Dartmouth logo Dartmouth College Computer Science
Technical Report series
CS home
TR home
TR search TR listserv
By author: A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
By number: 2017, 2016, 2015, 2014, 2013, 2012, 2011, 2010, 2009, 2008, 2007, 2006, 2005, 2004, 2003, 2002, 2001, 2000, 1999, 1998, 1997, 1996, 1995, 1994, 1993, 1992, 1991, 1990, 1989, 1988, 1987, 1986

A Data Flow Tracker and Reference Monitor for WebKit and JavaScriptCore
Andrew Bloomgarden
Dartmouth TR2014-750

Abstract: Browser security revolves around the same-origin policy, but it

does not defend against all attacks as evidenced by the prevalence of

cross-site scripting attacks. Rather than solve that attack in

particular, I have opted for a more general solution. I have modified

WebKit to allow data flow tracking via labels and to allow

security-sensitive operations to be allowed or denied from JavaScript.

Note: Senior Honors Thesis. Advisors: Sergey Bratus, Sean W. Smith.

Code available at https://github.com/aughr/webkit_with_reference_monitor


PDF PDF (636KB)

Bibliographic citation for this report: [plain text] [BIB] [BibTeX] [Refer]

Or copy and paste:
   Andrew Bloomgarden, "A Data Flow Tracker and Reference Monitor for WebKit and JavaScriptCore." Dartmouth Computer Science Technical Report TR2014-750, May 2012.


Notify me about new tech reports.

Search the technical reports.

To receive paper copy of a report, by mail, send your address and the TR number to reports AT cs.dartmouth.edu


Copyright notice: The documents contained in this server are included by the contributing authors as a means to ensure timely dissemination of scholarly and technical work on a non-commercial basis. Copyright and all rights therein are maintained by the authors or by other copyright holders, notwithstanding that they have offered their works here electronically. It is understood that all persons copying this information will adhere to the terms and constraints invoked by each author's copyright. These works may not be reposted without the explicit permission of the copyright holder.

Technical reports collection maintained by David Kotz.