A Lattice-Based Approach to Mashup Security
Source: Association for Computing Machinery
A web mashup is a web application that integrates content from different providers to create a new service, not offered by the content providers. As mashups grow in popularity, the problem of securing information flow between mashup components become increasingly important. This paper presents a security lattice-based approach to mashup security, where the origins of the different components of the mashup are used as levels in the security lattice. Declassification allows controlled information release between the components. The authors formalize a notion of composite delimited release policy and provide considerations for practical (static as well as run-time) enforcement of mashup information-flow security policies in a web browser.
| Format: | Size: | 508.10 | |
| Date: | Apr 2010 |



