JSISOLATE: lightweight in-browser JavaScript isolation
Mingxue Zhang, Wei Meng
Abstract
Modern web applications commonly include third-party scripts from external hosts. While enabling code reuse and enhancing the functionalities, the reliability of client-side JavaScript code can be impaired by the inclusion of other scripts. Since all scripts run in the same execution environment in the browser, executing them all together may cause unexpected effects. For example, global variables with the same name might be defined by multiple scripts, causing the actual value to be unpredictable.
In this paper, we design a lightweight browser-based framework, JSIsolate, that provides an isolated and reliable JavaScript execution environment. JSIsolate injects scripts into different isolated environments based on their dependency relationship. In this way, it executes scripts with independent functionalities in different contexts, effectively preventing them from interfering with each other. We further evaluated the compatibility and performance overhead of JSIsolate on Alexa top 1K websites, and showed that it can efficiently isolate scripts while preserving the functionalities.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 34894d02-648f-42f2-82e3-79bac43ead84Cited by top-tier papers9
- Undefined-oriented Programming: Detecting and Chaining Prototype Pollution Gadgets in Node.js Template Engines for Malicious ConsequencesZhengyu Liu, Kecheng An, Yinzhi CaoS&P 2024 · 17 citations
- CoCo: Efficient Browser Extension Vulnerability Detection via Coverage-guided, Concurrent Abstract InterpretationJianjia Yu, Song Li, Junmin Zhu, Yinzhi CaoCCS 2023 · 6 citations
- RogueOne: Detecting Rogue Updates via Differential Data-flow Analysis Using Trust DomainsRaphael J. Sofaer, Yaniv David, Mingqing Kang, Jianjia Yu et al.ICSE 2024 · 3 citations
- ReactAppScan: Mining React Application Vulnerabilities via Component GraphZhiyong Guo, Mingqing Kang, V. N. Venkatakrishnan, Rigel Gjomemo et al.CCS 2024 · 3 citations
- Fine-Grained Data-Centric Content Protection Policy for Web ApplicationsZilun Wang, Wei Meng, Michael R. LyuCCS 2023 · 2 citations
Builds on7
- Thou Shalt Not Depend on Me: Analysing the Use of Outdated JavaScript Libraries on the WebTobias Lauinger, Abdelberi Chaabane, Sajjad Arshad, William Robertson et al.NDSS 2017 · 183 citations
- Site Isolation: Process Separation for Web Sites within the BrowserCharles Reis, Alexander Moshchuk, Nasko OskovUSENIX Security 2019 · 105 citations
- Most Websites Don't Need to Vibrate: A Cost-Benefit Approach to Improving Browser SecurityPeter Snyder, Cynthia Bagier Taylor, Chris KanichCCS 2017 · 75 citations
- Content Security Problems?: Evaluating the Effectiveness of Content Security Policy in the WildStefano Calzavara, Alvise Rabitti, Michele BugliesiCCS 2016 · 71 citations
- BreakApp: Automated, Flexible Application CompartmentalizationNikos Vasilakis, Ben Karel, Nick Roessler, Nathan Dautenhahn et al.NDSS 2018 · 66 citations
Related papers
- Detecting and understanding JavaScript global identifier conflicts on the webMingxue Zhang, Wei MengFSE 2020 · 10 citations
- ScriptChecker: To Tame Third-party Script Execution With Task CapabilitiesWu Luo, Xuhua Ding, Pengfei Wu, Xiaolei Zhang et al.NDSS 2022
- Timing-Based Browsing Privacy Vulnerabilities Via Site IsolationZihao Jin, Ziqiao Kong, Shuo Chen, Haixin DuanS&P 2022 · 2 citations
- Are your Sites Truly Isolated? Automatically Detecting Logic Bugs in Site Isolation ImplementationsJan Drescher, David Klein, Martin JohnsNDSS 2026
- SandDriller: A Fully-Automated Approach for Testing Language-Based JavaScript SandboxesAbdullah AlHamdan, Cristian-Alexandru StaicuUSENIX Security 2023
