Vetting Browser Extensions for Security Vulnerabilities with VEX.

Saved in:
Bibliographic Details
Title: Vetting Browser Extensions for Security Vulnerabilities with VEX.
Authors: Bandhakavi, Sruthi1 sbandha2@illinois.edu, Tiku, Nandit1 tiku1@illinois.edu, Pittman, Wyatt1 wpittma2@illinois.edu, King, Samuel T.1 kingst@illinois.edu, Madhusudan, P.1 madhu@illinois.edu, Winslett, Marianne1 winslett@illinois.edu
Source: Communications of the ACM. Sep2011, Vol. 54 Issue 9, p91-99. 9p. 3 Diagrams, 5 Charts.
Subjects: Web browser security, Anti-malware (Computer software), Malware, Computer security, JavaScript programming language, World Wide Web
Abstract: The browser has become the de facto platform for everyday computation and a popular target for attackers of computer systems. Among the many potential attacks that target or exploit browsers, vulnerabilities in browser extensions have received relatively little attention. Currently, extensions are vetted by manual inspection, which is time consuming and subject to human error. In this paper, we present Vex, a framework for applying static information flow analysis to JavaScript code to identify security vulnerabilities in browser extensions. We describe several patterns of flows that can lead to privilege escalations in Firefox extensions. Vex analyzes Firefox extensions for such flow patterns using high-precision, context-sensitive, flow-sensitive static analysis. We subject 2460 browser extensions to the analysis, and Vex finds 5 of the 18 previously known vulnerabilities and 7 previously unknown vulnerabilities. [ABSTRACT FROM AUTHOR]
Copyright of Communications of the ACM is the property of Association for Computing Machinery and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
FullText Links:
  – Type: pdflink
Text:
  Availability: 0
Header DbId: egs
DbLabel: Engineering Source
An: 67134753
AccessLevel: 6
PubType: Periodical
PubTypeId: serialPeriodical
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Vetting Browser Extensions for Security Vulnerabilities with VEX.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Bandhakavi%2C+Sruthi%22">Bandhakavi, Sruthi</searchLink><relatesTo>1</relatesTo><i> sbandha2@illinois.edu</i><br /><searchLink fieldCode="AR" term="%22Tiku%2C+Nandit%22">Tiku, Nandit</searchLink><relatesTo>1</relatesTo><i> tiku1@illinois.edu</i><br /><searchLink fieldCode="AR" term="%22Pittman%2C+Wyatt%22">Pittman, Wyatt</searchLink><relatesTo>1</relatesTo><i> wpittma2@illinois.edu</i><br /><searchLink fieldCode="AR" term="%22King%2C+Samuel+T%2E%22">King, Samuel T.</searchLink><relatesTo>1</relatesTo><i> kingst@illinois.edu</i><br /><searchLink fieldCode="AR" term="%22Madhusudan%2C+P%2E%22">Madhusudan, P.</searchLink><relatesTo>1</relatesTo><i> madhu@illinois.edu</i><br /><searchLink fieldCode="AR" term="%22Winslett%2C+Marianne%22">Winslett, Marianne</searchLink><relatesTo>1</relatesTo><i> winslett@illinois.edu</i>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Communications+of+the+ACM%22">Communications of the ACM</searchLink>. Sep2011, Vol. 54 Issue 9, p91-99. 9p. 3 Diagrams, 5 Charts.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Web+browser+security%22">Web browser security</searchLink><br /><searchLink fieldCode="DE" term="%22Anti-malware+%28Computer+software%29%22">Anti-malware (Computer software)</searchLink><br /><searchLink fieldCode="DE" term="%22Malware%22">Malware</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+security%22">Computer security</searchLink><br /><searchLink fieldCode="DE" term="%22JavaScript+programming+language%22">JavaScript programming language</searchLink><br /><searchLink fieldCode="DE" term="%22World+Wide+Web%22">World Wide Web</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: The browser has become the de facto platform for everyday computation and a popular target for attackers of computer systems. Among the many potential attacks that target or exploit browsers, vulnerabilities in browser extensions have received relatively little attention. Currently, extensions are vetted by manual inspection, which is time consuming and subject to human error. In this paper, we present Vex, a framework for applying static information flow analysis to JavaScript code to identify security vulnerabilities in browser extensions. We describe several patterns of flows that can lead to privilege escalations in Firefox extensions. Vex analyzes Firefox extensions for such flow patterns using high-precision, context-sensitive, flow-sensitive static analysis. We subject 2460 browser extensions to the analysis, and Vex finds 5 of the 18 previously known vulnerabilities and 7 previously unknown vulnerabilities. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Communications of the ACM is the property of Association for Computing Machinery and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=67134753
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1145/1995376.1995398
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 9
        StartPage: 91
    Subjects:
      – SubjectFull: Web browser security
        Type: general
      – SubjectFull: Anti-malware (Computer software)
        Type: general
      – SubjectFull: Malware
        Type: general
      – SubjectFull: Computer security
        Type: general
      – SubjectFull: JavaScript programming language
        Type: general
      – SubjectFull: World Wide Web
        Type: general
    Titles:
      – TitleFull: Vetting Browser Extensions for Security Vulnerabilities with VEX.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Bandhakavi, Sruthi
      – PersonEntity:
          Name:
            NameFull: Tiku, Nandit
      – PersonEntity:
          Name:
            NameFull: Pittman, Wyatt
      – PersonEntity:
          Name:
            NameFull: King, Samuel T.
      – PersonEntity:
          Name:
            NameFull: Madhusudan, P.
      – PersonEntity:
          Name:
            NameFull: Winslett, Marianne
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 09
              Text: Sep2011
              Type: published
              Y: 2011
          Identifiers:
            – Type: issn-print
              Value: 00010782
          Numbering:
            – Type: volume
              Value: 54
            – Type: issue
              Value: 9
          Titles:
            – TitleFull: Communications of the ACM
              Type: main
ResultId 1