收稿日期: 2011-12-09
修回日期: 2012-03-22
网络出版日期: 2013-01-15
基金资助
国家自然科学基金(60970140)资助
Secure cross-document messaging scheme based on HTML5
Received date: 2011-12-09
Revised date: 2012-03-22
Online published: 2013-01-15
李潇宇 , 张玉清 , 刘奇旭 , 郑晨 . 一种基于HTML5的安全跨文档消息传递方案[J]. 中国科学院大学学报, 2013 , 30(1) : 124 -130 . DOI: 10.7523/j.issn.1002-1175.2013.01.019
We analyze security risk of the current cross-document messaging methods based on HTML5 and propose a secure cross-document messaging scheme SafePM. In SafePM, white list, two-way detection, and auto-detecting are developed to limit maliciously messaging. Moreover, with the detection of the message content, SafePM eliminates information leakage and tampering and reduce the risk for executing of cross-site scripts, which makes cross-document messaging more secure.
Key words: HTML5; cross-document messaging; white list; two-way detection; SafePM
[1] Barth A, Jackson C, Mitchell J C. Securing frame communication in browsers[C]//Proceedings of the 17th USENIX Security Symposium. San Jose, CA, USA,2008:17-30.
[2] The World Wide Web Consortium (W3C).W3C editor's draft[EB/OL]. (2011-11-20)[2011-11-25]. http://dev.w3.org/html5 /postmsg/#dom-messageevent-source.
[3] Alman B. jQuery postMessage: Cross-domain scripting goodness[EB/OL]. (2009-08-23)[2011-11-20]. http://benalman. com/projects/jquery-postmessage-plugin/.
[4] Kinsey Φ S. Easy cross-site scripting using the easyXDM library[EB/OL].(2009-08-17)[2011-11-25]. http://www.codeproject.com/Articles/37622/Easy-Cross-site-Scripting-using-the-easyXDM-Library.
[5] Matono A, Nakamura A, Kojima I. A mashup tool for cross-domain Web applications using HTML5[J]. Lecture Notes in Computer Science, 2011, 6612:382-385.
[6] Ryck P D, Desmet L, Philippaerts P, et al. A security analysis of next generation Web standards[R/OL].Greece: European Network and Information Security Agency (ENISA), (2011-07-31)[2011-11-25]. http://www.enisa.europa.eu/activities/application-security/web-security/.
[7] Hickson I. HTML living standard . USA:The Web Hypertext Application Technology Working Group, (2009-10-23)[2011-11-25]http://www.whatwg.org/specs/web-apps/current-work/multipage/web-messaging.html#crossDocumentMess ages.
[8] Hanna S, Shin E C R, Akhawe D, et al. The emperor’s new APIs: on the (in)secure usage of new client-side primitives[C]//Proceedings of the 4th Web 2.0 Security and Privacy. Oakland, California, USA, 2010.
[9] Saxena P, Hanna S, Poosankam P, et al. FLAX:systematic discovery of client-side validation vulnerabilities in rich Web applications[C]//Proceedings of the 17th Annual Network & Distributed System Security Symposium. San Diego, Califonia, USA, 2010.
[10] Edwards D. Packer version 3.0[CP/OL]. (2007-04-01)[2011-11-20]. http://dean.edwards.name/weblog/2007/04/packer3/.
[11] Heiderich M. HTML5 security cheatsheet[EB/OL].(2011-01-22)[2011-11-20].http://html5sec.org/.
/
| 〈 |
|
〉 |