Dissertation/Thesis Abstract

From FLOWCORE to JITFLOW: Improving the speed of Information Flow in JavaScript
by Hennigan, Eric, Ph.D., University of California, Irvine, 2015, 193; 3688532
Abstract (Summary)

Today's web applications remain vulnerable to cross-site scripting attacks that enable data theft. Information flow tracking in the JavaScript VM of a web engine can track data flows through the web application and prevent the communication of sensitive data to unintended recipients, thereby stopping data theft. Existing solutions have focused on the incorporating information flow into the JS interpreter, rather than the just-in-time compiler, rendering the resulting performance non-competitive.

This thesis presents an implementation of information flow tracking that works with the just-in-time compiler, outperforming all previous interpreter-based information flow tracking engines by more than a factor of two. The JIT-based engine (i) has the same coverage as previous implementations, (ii) requires comparatively light implementation effort, and (iii) introduces new optimizations to remain performant. When evaluated against three industry standard benchmark suites, the tracking engine retains an average slowdown of 73% over engines that do not support information flow, remaining will within the range that many users will find an acceptable price for obtaining substantially increased security against data theft.

Indexing (document details)
Advisor: Franz, Michael
Commitee: Harris, Ian, Markopoulou, Athina
School: University of California, Irvine
Department: Computer Science
School Location: United States -- California
Source: DAI-B 76/08(E), Dissertation Abstracts International
Source Type: DISSERTATION
Subjects: Computer science
Keywords: Information flow, Javascript, Just-in-time compilation, Web security
Publication Number: 3688532
ISBN: 9781321672084
Copyright © 2019 ProQuest LLC. All rights reserved. Terms and Conditions Privacy Policy Cookie Policy
ProQuest