A Blueprint to Stop Browser Attacks
Technology Review (05/14/09) Naone, Erica
University of Illinois at Chicago (UIC) researchers will present a new way of defending against cross-site scripting attacks at the upcoming IEEE Symposium on Security and Privacy. The new defense enables a Web site to control how user-generated content is transmitted to a Web browser, neutralizing cross-site scripting attacks before they reach the end user. White Hat Security founder Jeremiah Grossman says cross-site scripting is the most prevalent threat on the Internet, and although newer Web sites are better equipped to defend against these attacks, there are still millions of vulnerabilities on the Internet. The UIC solution involves a layer of software called Blueprint that can be inserted between user-generated pages and the browser. Blueprint is stored on a Web site's servers, reads user-generated HTML, and checks it against a white list of trusted code, removing any potentially harmful scripts and deciding how content should appear in a browser. The software then reformats the information and transmits it to the browser. For example, Blueprint eliminates characters and symbols that are sometimes used to send unauthorized scripting signals to a user's browser. The solution was tested against 94 types of cross-site scripting attacks and successfully prevented every attack. "What we want to do is to take away the ability for the browser's parser to make any script-identification decisions on the untrusted content that is supplied by the Web application," says UIC professor V. N. Venkatakrishnan.
Thursday, May 14, 2009
Blog: A Blueprint to Stop Browser Attacks; defending against cross-site scripting attacks
Subscribe to:
Post Comments (Atom)
Blog Archive
-
►
2012
(35)
- ► April 2012 (13)
- ► March 2012 (16)
- ► February 2012 (3)
- ► January 2012 (3)
-
►
2011
(118)
- ► December 2011 (9)
- ► November 2011 (11)
- ► October 2011 (7)
- ► September 2011 (13)
- ► August 2011 (7)
- ► April 2011 (8)
- ► March 2011 (11)
- ► February 2011 (12)
- ► January 2011 (15)
-
►
2010
(183)
- ► December 2010 (16)
- ► November 2010 (15)
- ► October 2010 (15)
- ► September 2010 (25)
- ► August 2010 (19)
- ► April 2010 (21)
- ► March 2010 (7)
- ► February 2010 (6)
- ► January 2010 (6)
-
▼
2009
(120)
- ► December 2009 (5)
- ► November 2009 (12)
- ► October 2009 (2)
- ► September 2009 (3)
- ► August 2009 (16)
-
▼
May 2009
(8)
- Blog: Researchers to Create Next Gen Discs; record...
- Blog: Mozilla launches Jetpack; Will add-ons be Fi...
- Blog: ACM Group Honors Researchers Who Discovered ...
- Blog: Are Your 'Secret Questions' Too Easily Answe...
- Blog: Robert Kahn: A Different Kind of Internet; u...
- Blog: A Blueprint to Stop Browser Attacks; defendi...
- Blog: Constantinos Daskalakis Wins ACM Award for A...
- Blog: The A-Z of Programming Languages: Tcl; a pow...
- ► April 2009 (4)
- ► March 2009 (20)
- ► February 2009 (9)
- ► January 2009 (19)
-
►
2008
(139)
- ► December 2008 (15)
- ► November 2008 (16)
- ► October 2008 (17)
- ► September 2008 (2)
- ► August 2008 (2)
- ► April 2008 (12)
- ► March 2008 (25)
- ► February 2008 (16)
- ► January 2008 (6)
-
►
2007
(17)
- ► December 2007 (4)
- ► November 2007 (4)
- ► October 2007 (7)
Blog Labels
- research
- CSE
- security
- software
- web
- AI
- development
- hardware
- algorithm
- hackers
- medical
- machine learning
- robotics
- data-mining
- semantic web
- quantum computing
- Cloud computing
- cryptography
- network
- EMR
- search
- NP-complete
- linguistics
- complexity
- data clustering
- optimization
- parallel
- performance
- social network
- HIPAA
- accessibility
- biometrics
- connectionist
- cyber security
- passwords
- voting
- XML
- biological computing
- neural network
- user interface
- DNS
- access control
- firewall
- graph theory
- grid computing
- identity theft
- project management
- role-based
- HTML5
- NLP
- NoSQL
- Python
- cell phone
- database
- java
- open-source
- spam
- GENI
- Javascript
- SQL-Injection
- Wikipedia
- agile
- analog computing
- archives
- biological
- bots
- cellular automata
- computer tips
- crowdsourcing
- e-book
- equilibrium
- game theory
- genetic algorithm
- green tech
- mobile
- nonlinear
- p
- phone
- prediction
- privacy
- self-book publishing
- simulation
- testing
- virtual server
- visualization
- wireless
No comments:
Post a Comment