Automated Analysis of Security-Critical JavaScript APIs

JavaScript is widely used to provide client-side functionality in Web applications. To provide services ranging from maps to advertisements, Web applications may incorporate untrusted JavaScript code from third parties. The trusted portion of each application may then expose an API to untrusted code, interposing a reference monitor that mediates access to security-critical resources. However, a JavaScript reference monitor can only be effective if it cannot be circumvented through programming tricks or programming language idiosyncracies.

Provided by: Stanford University Topic: Software Date Added: Mar 2011 Format: PDF

Find By Topic