DocumentCode :
1807221
Title :
A safety-oriented platform for Web applications
Author :
Cox, Richard S. ; Hansen, Jacob Gorm ; Gribble, Steven D. ; Levy, Henry M.
Author_Institution :
Dept. of Comput. Sci. & Eng., Washington Univ.
fYear :
2006
fDate :
21-24 May 2006
Lastpage :
364
Abstract :
This paper describes the architecture and implementation of the Tahoma Web browsing system. Key to Tahoma is the browser operating system (BOS), a new trusted software layer on which Web browsers execute. The benefits of this architecture are threefold. First, the BOS runs the client-side component of each Web application (e.g., on-line banking, Web mail) in its own virtual machine. This provides strong isolation between Web services and the user´s local resources. Second, Tahoma lets Web publishers limit the scope of their Web applications by specifying which URLs and other resources their browsers are allowed to access. This limits the harm that can be caused by a compromised browser. Third, Tahoma treats Web applications as first-class objects that users explicitly install and manage, giving them explicit knowledge about and control over downloaded content and code. We have implemented a prototype of Tahoma using Linux and the Xen virtual machine monitor. Our security evaluation shows that Tahoma can prevent or contain 87% of the vulnerabilities that have been identified in the widely used Mozilla browser. In addition, our measurements of latency, throughput, and responsiveness demonstrate that users need not sacrifice performance for the benefits of stronger isolation and safety
Keywords :
Internet; network operating systems; online front-ends; security of data; virtual machines; Linux; Mozilla browser; Tahoma Web browsing system; Web applications; Web browser; Web services; Xen virtual machine monitor; browser operating system; safety-oriented platform; security evaluation; trusted software layer; Application software; Banking; Computer architecture; Delay; Operating systems; Postal services; Service oriented architecture; Uniform resource locators; Virtual machining; Web services;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Security and Privacy, 2006 IEEE Symposium on
Conference_Location :
Berkeley/Oakland, CA
ISSN :
1081-6011
Print_ISBN :
0-7695-2574-1
Type :
conf
DOI :
10.1109/SP.2006.4
Filename :
1624025
Link To Document :
بازگشت