arrow
返回

Securing Frame Communication in Browsers

delete2009-06-01
delete50
delete
OA
AI
A
Adam Barth *
C
Collin Jackson
J
John C. Mitchell
DOI:10.1145/1516046.1516066delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
Many Web sites embed third-party content in frames, relying on the browser's security policy to protect against malicious content. However, frames provide insufficient isolation in browsers that let framed content navigate other frames. We evaluate existing frame navigation policies and advocate a stricter policy, which we deploy in the open-source browsers. In addition to preventing undesirable interactions, the browser's strict isolation policy also affects communication between cooperating frames. We therefore analyze two techniques for interframe communication between isolated frames. The first method, fragment identifier messaging, initially provides confidentiality without authentication, which we repair using concepts from a well-known network protocol. The second method, post-Message, initially provides authentication, but we discover an attack that breaches confidentiality. We propose improvements in the post-Message API to provide confidentiality; our proposal has been standardized and adopted in browser implementations.
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

Communications of the ACM 封面图
Communications of the ACM
IF:
12.2
论文数:
1.2W
被引数:
3.7W

机构

U
University of California Berkeley
学者数:
3.5W
论文数: 2.8W
被引数: 11.3W
University of California System 封面图
University of California System
学者数:
37.7W
论文数: 33.8W
被引数: 6.6K
引用论文

引用论文

err分享
err收藏
err分享
err收藏
Review on data-driven approaches for improving the selectivity of MOX-sensors
err2024-04-13
err0
PREAI
errMohand Djeziri; Samir Benmoussa; Marc Bendahan; Jean-Luc Seguin
err分享
err收藏
没有更多内容