dc.contributor.author |
Priyadarsini, Gayatri |
|
dc.contributor.other |
39th ACM/SIGAPP Symposium on Applied Computing (SAC 2024) |
|
dc.coverage.spatial |
Spain |
|
dc.date.accessioned |
2024-05-30T11:50:02Z |
|
dc.date.available |
2024-05-30T11:50:02Z |
|
dc.date.issued |
4/8/2024 |
|
dc.identifier.citation |
Priyadarsini, Gayatri, "Student research abstract: least privilege persistent-storage access in web browsers", in the 39th ACM/SIGAPP Symposium on Applied Computing (SAC 2024), �vila, ES, Apr. 08-12, 2024. |
|
dc.identifier.uri |
https://doi.org/10.1145/3605098.3635173 |
|
dc.identifier.uri |
https://repository.iitgn.ac.in/handle/123456789/10110 |
|
dc.description.abstract |
Web applications often include third-party content and scripts to personalize a user's online experience. These scripts have unrestricted access to a user's private data stored in the browser's persistent storage like cookies and localstorage associated with the host page. However these third-party scripts can be compromised or may act maliciously and easily access and modify private user information like session-id, user consent, etc., that are stored in the browser.
We propose an approach to enforce least privilege access for third-party scripts on the web storage(cookies and localstorage) objects to ensure their security. We attach labels with the storage objects that specify which domains are allowed to read from and write to these objects on the page. We implement our approach on the Nightly Firefox build and show that it effectively blocks scripts from other domains, which are not allowed access based on these labels, from accessing the storage objects. |
|
dc.description.statementofresponsibility |
by Gayatri Priyadarsini |
|
dc.language.iso |
en_US |
|
dc.publisher |
Association for Computing Machinery (ACM) |
|
dc.subject |
Web Storage |
|
dc.subject |
Third-party scripts |
|
dc.subject |
Least privilege access control |
|
dc.subject |
Web browsers |
|
dc.title |
Student research abstract: least privilege persistent-storage access in web browsers |
|
dc.type |
Poster Presented |
|