Anticipating and hardening the Web against socio-technical security attacks
by Stamm, Sidney L., Ph.D., INDIANA UNIVERSITY, 2009, 219 pages; 3344603

Abstract:

The Internet, and the World Wide Web in particular, is becoming an increasingly important resource to people in modern society. Mostly, people are browsing the web for news, shopping, blogging, researching, or simply surfing; the vast majority of Internet use is browsing the Web with one of many browsers. To appease users' demand for robust and novel web applications, programmers are discovering new tricks to add unique or novel behavior to their web sites (through asynchronous data fetching, or animations). Though these features are based on mature languages and standards, new security problems are often uncovered with each new trick. Many of these are socio-technical problems: the result of technological nuances in the use of scripting or other web technologies coupled with the way people interact with the web sites. This sociological spin on technical security problems, introducing an element of deception, makes the security of the web more complex and not easily patched with simple software fixes.

The web was not designed with security in mind, only utility. In its evolution from simple html, it has inflated to have a colossal number of technologies and features supported by browsers that have increased the web's potential for misuse. It is time to re-consider fundamental control of web content, and this dissertation shows how to begin. Most security problems with web applications stem from loose control of data; there are no strictly enforced policies that dictate how information can flow between technologies in the web browser or out from a web application's domain. This dissertation investigates the underlying problems in the way data is transfered in and out of browsers and their components by analyzing a variety of security problems and their corresponding solutions. Through presentation and analysis of some cases, underlying themes are exposed that can eventually be used to address web security on a more fundamental level.

 
AdviserMarkus Jakobsson
SchoolINDIANA UNIVERSITY
SourceDAI/B 70-02, p. , Apr 2009
Source TypeDissertation
SubjectsComputer science
Publication Number3344603
Adobe PDF Access the complete dissertation:
 

» Find an electronic copy at your library.
  Use the link below to access a full citation record of this graduate work:
  http://gateway.proquest.com/openurl%3furl_ver=Z39.88-2004%26res_dat=xri:pqdiss%26rft_val_fmt=info:ofi/fmt:kev:mtx:dissertation%26rft_dat=xri:pqdiss:3344603
  If your library subscribes to the ProQuest Dissertations & Theses (PQDT) database, you may be entitled to a free electronic version of this graduate work. If not, you will have the option to purchase one, and access a 24 page preview for free (if available).

About ProQuest Dissertations & Theses
With over 2.3 million records, the ProQuest Dissertations & Theses (PQDT) database is the most comprehensive collection of dissertations and theses in the world. It is the database of record for graduate research.

The database includes citations of graduate works ranging from the first U.S. dissertation, accepted in 1861, to those accepted as recently as last semester. Of the 2.3 million graduate works included in the database, ProQuest offers more than 1.9 million in full text formats. Of those, over 860,000 are available in PDF format. More than 60,000 dissertations and theses are added to the database each year.

If you have questions, please feel free to visit the ProQuest Web site - http://www.proquest.com - or call ProQuest Hotline Customer Support at 1-800-521-3042.