Student research abstract: least privilege persistent-storage access in web browsers

Show simple item record

dc.contributor.author Priyadarsini, Gayatri
dc.contributor.other 39th ACM/SIGAPP Symposium on Applied Computing (SAC 2024)
dc.coverage.spatial Spain
dc.date.accessioned 2024-05-30T11:50:02Z
dc.date.available 2024-05-30T11:50:02Z
dc.date.issued 4/8/2024
dc.identifier.citation Priyadarsini, Gayatri, "Student research abstract: least privilege persistent-storage access in web browsers", in the 39th ACM/SIGAPP Symposium on Applied Computing (SAC 2024), �vila, ES, Apr. 08-12, 2024.
dc.identifier.uri https://doi.org/10.1145/3605098.3635173
dc.identifier.uri https://repository.iitgn.ac.in/handle/123456789/10110
dc.description.abstract Web applications often include third-party content and scripts to personalize a user's online experience. These scripts have unrestricted access to a user's private data stored in the browser's persistent storage like cookies and localstorage associated with the host page. However these third-party scripts can be compromised or may act maliciously and easily access and modify private user information like session-id, user consent, etc., that are stored in the browser. We propose an approach to enforce least privilege access for third-party scripts on the web storage(cookies and localstorage) objects to ensure their security. We attach labels with the storage objects that specify which domains are allowed to read from and write to these objects on the page. We implement our approach on the Nightly Firefox build and show that it effectively blocks scripts from other domains, which are not allowed access based on these labels, from accessing the storage objects.
dc.description.statementofresponsibility by Gayatri Priyadarsini
dc.language.iso en_US
dc.publisher Association for Computing Machinery (ACM)
dc.subject Web Storage
dc.subject Third-party scripts
dc.subject Least privilege access control
dc.subject Web browsers
dc.title Student research abstract: least privilege persistent-storage access in web browsers
dc.type Poster Presented


Files in this item

Files Size Format View

There are no files associated with this item.

This item appears in the following Collection(s)

Show simple item record

Search Digital Repository


Browse

My Account