WebSpec: Towards Machine-Checked Analysis of Browser Security Mechanisms

01/05/2022
by   Lorenzo Veronese, et al.
0

The complexity of browsers has steadily increased over the years, driven by the continuous introduction and update of Web platform components, such as novel Web APIs and security mechanisms. Their specifications are manually reviewed by experts to identify potential security issues. However, this process has proved to be error-prone due to the extensiveness of modern browser specifications and the interplay between new and existing Web platform components. To tackle this problem, we developed WebSpec, the first formal security framework for the analysis of browser security mechanisms, which enables both the automatic discovery of logical flaws and the development of machine-checked security proofs. WebSpec, in particular, includes a comprehensive semantic model of the browser in the Coq proof assistant, a formalization in this model of ten Web security invariants, and a compiler turning the Coq model and the Web invariants into SMT-lib formulas. We showcase the effectiveness of WebSpec by discovering two new logical flaws caused by the interaction of different browser mechanisms and by identifying three previously discovered logical flaws in the current Web platform, as well as five in old versions. Finally, we show how WebSpec can aid the verification of our proposed changes to amend the reported inconsistencies affecting the current Web platform.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
10/28/2014

A First Look at Firefox OS Security

With Firefox OS, Mozilla is making a serious push for an HTML5-based mob...
research
01/28/2020

Language-Based Web Session Integrity

Session management is a fundamental component of web applications: despi...
research
01/28/2020

Automated Proof of Bell-LaPadula Security Properties

Almost fifty years ago, D.E. Bell and L. LaPadula published the first fo...
research
01/29/2022

Logical Pseudocode: Connecting Algorithms with Proofs

Proofs (sequent calculus, natural deduction) and imperative algorithms (...
research
09/12/2017

A certified reference validation mechanism for the permission model of Android

Android embodies security mechanisms at both OS and application level. I...
research
09/04/2022

PhishClone: Measuring the Efficacy of Cloning Evasion Attacks

Web-based phishing accounts for over 90 web-browsers and security vendor...
research
11/10/2020

Computational Design and Fabrication of Corrugated Mechanisms from Behavioral Specifications

Orthogonally assembled double-layered corrugated (OADLC) mechanisms are ...

Please sign up or login with your details

Forgot password? Click here to reset