WebSpec: Towards Machine-Checked Analysis of Browser Security Mechanisms
Lorenzo Veronese, Benjamin Farinier, Pedro Bernardo, Mauro Tempesta, Marco Squarcina, Matteo Maffei
Abstract
The complexity of browsers has steadily increased over the years, driven by the continuous introduction and update of Web platform components, such as novel Web APIs and security mechanisms. Their specifications are manually reviewed by experts to identify potential security issues. However, this process has proved to be error-prone due to the extensiveness of modern browser specifications and the interplay between new and existing Web platform components. To tackle this problem, we developed WebSpec, the first formal security framework for the analysis of browser security mechanisms, which enables both the automatic discovery of logical flaws and the development of machine-checked security proofs. WebSpec, in particular, includes a comprehensive semantic model of the browser in the Coq proof assistant, a formalization in this model of ten Web security invariants, and a toolchain turning the Coq model and the Web invariants into SMT-lib formulas to enable model checking with the Z3 theorem prover. If a violation is found, the toolchain automatically generates executable tests corresponding to the discovered attack trace, which is validated across major browsers.We showcase the effectiveness of WebSpec by discovering two new logical flaws caused by the interaction of different browser mechanisms and by identifying three previously discovered logical flaws in the current Web platform, as well as five in old versions. Finally, we show how WebSpec can aid the verification of our proposed changes to amend the reported inconsistencies affecting the current Web platform.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 81b0d0d8-cfb0-4af6-8f90-b3616c4ff404Cited by top-tier papers4
- Web Platform Threats: Automated Detection of Web Security Issues With WPTPedro Bernardo, Lorenzo Veronese, Valentino Dalla Valle, Stefano Calzavara et al.USENIX Security 2024 · 6 citations
- Trust Me If You Can - How Usable Is Trusted Types In Practice?Sebastian Roth, Lea Gröber, Philipp Baus, Katharina Krombholz et al.USENIX Security 2024 · 3 citations
- React-tRace: A Semantics for Understanding React Hooks: An Operational Semantics and a Visualizer for Clarifying React HooksJay Lee, Joongwon Ahn, Kwangkeun YiOOPSLA 2025 · 1 citation
- Are your Sites Truly Isolated? Automatically Detecting Logic Bugs in Site Isolation ImplementationsJan Drescher, David Klein, Martin JohnsNDSS 2026
Builds on4
- Can I Take Your Subdomain? Exploring Same-Site Attacks in the Modern WebMarco Squarcina, Mauro Tempesta, Lorenzo Veronese, Stefano Calzavara et al.USENIX Security 2021 · 30 citations
- An Extensive Formal Security Analysis of the OpenID Financial-Grade APIDaniel Fett, Pedram Hosseyni, Ralf KüstersS&P 2019 · 29 citations
- PMForce: Systematically Analyzing postMessage Handlers at ScaleMarius Steffens, Ben StockCCS 2020 · 23 citations
- A Formal Security Analysis of the W3C Web Payment APIs: Attacks and VerificationQuoc Huy Do, Pedram Hosseyni, Ralf Küsters, Guido Schmitz et al.S&P 2022 · 6 citations
Related papers
- WPSE: Fortifying Web Protocols via Browser-Side Security MonitoringStefano Calzavara, Riccardo Focardi, Matteo Maffei, Clara Schneidewind et al.USENIX Security 2018 · 29 citations
- Who Left Open the Cookie Jar? A Comprehensive Evaluation of Third-Party Cookie PoliciesGertjan Franken, Tom van Goethem, Wouter JoosenUSENIX Security 2018 · 39 citations
- Model-based testing of networked applicationsYishuai Li, Benjamin C. Pierce, Steve ZdancewicISSTA 2021 · 9 citations
- A Bug's Life: Analyzing the Lifecycle and Mitigation Process of Content Security Policy BugsGertjan Franken, Tom van Goethem, Lieven Desmet, Wouter JoosenUSENIX Security 2023
- Tacoma: Enhanced Browser Fuzzing with Fine-Grained Semantic AlignmentJiashui Wang, Peng Qian, Xilin Huang, Xinlei Ying et al.ISSTA 2024 · 3 citations
