返回
Securing Frame Communication in Browsers
DOI:10.1145/1516046.1516066.png)
摘要
En 中文
Many Web sites embed third-party content in frames, relying on the browser's security policy to protect against malicious content. However, frames provide insufficient isolation in browsers that let framed content navigate other frames. We evaluate existing frame navigation policies and advocate a stricter policy, which we deploy in the open-source browsers. In addition to preventing undesirable interactions, the browser's strict isolation policy also affects communication between cooperating frames. We therefore analyze two techniques for interframe communication between isolated frames. The first method, fragment identifier messaging, initially provides confidentiality without authentication, which we repair using concepts from a well-known network protocol. The second method, post-Message, initially provides authentication, but we discover an attack that breaches confidentiality. We propose improvements in the post-Message API to provide confidentiality; our proposal has been standardized and adopted in browser implementations.
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
12.2
论文数:
1.2W
被引数:
3.7W
机构
引用论文
A highly sensitive diaphragm pressure sensor based on fiber Bragg grating with multiprobe configuration基于多探针结构的光纤布拉格光栅高灵敏度薄膜压力传感器
没有更多内容

