Most Websites Don't Need to Vibrate: A Cost-Benefit Approach to Improving Browser Security
Peter Snyder, Cynthia Bagier Taylor, Chris Kanich
Abstract
Modern web browsers have accrued an incredibly broad set of features since being invented for hypermedia dissemination in 1990. Many of these features benefit users by enabling new types of web applications. However, some features also bring risk to users' privacy and security, whether through implementation error, unexpected composition, or unintended use. Currently there is no general methodology for weighing these costs and benefits. Restricting access to only the features which are necessary for delivering desired functionality on a given website would allow users to enforce the principle of lease privilege on use of the myriad APIs present in the modern web browser. However, security benefits gained by increasing restrictions must be balanced against the risk of breaking existing websites. This work addresses this problem with a methodology for weighing the costs and benefits of giving websites default access to each browser feature. We model the benefit as the number of websites that require the feature for some user-visible benefit, and the cost as the number of CVEs, lines of code, and academic attacks related to the functionality. We then apply this methodology to 74 Web API standards implemented in modern browsers. We find that allowing websites default access to large parts of the Web API poses significant security and privacy risks, with little corresponding benefit. We also introduce a configurable browser extension that allows users to selectively restrict access to low-benefit, high-risk features on a per site basis. We evaluated our extension with two hardened browser configurations, and found that blocking 15 of the 74 standards avoids 52.0% of code paths related to previous CVEs, and 50.0% of implementation code identified by our metric, without affecting the functionality of 94.7% of measured websites.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers32
- Fingerprinting the Fingerprinters: Learning to Detect Browser Fingerprinting BehaviorsUmar Iqbal, Steven Englehardt, Zubair ShafiqS&P 2021 · 143 citations
- RAZOR: A Framework for Post-deployment Software DebloatingChenxiong Qian, Hong Hu, Mansour Alharthi, Simon Pak Ho Chung et al.USENIX Security 2019 · 132 citations
- AdGraph: A Graph-Based Approach to Ad and Tracker BlockingUmar Iqbal, Peter Snyder, Shitong Zhu, Benjamin Livshits et al.S&P 2020 · 112 citations
- Site Isolation: Process Separation for Web Sites within the BrowserCharles Reis, Alexander Moshchuk, Nasko OskovUSENIX Security 2019 · 105 citations
- Less is More: Quantifying the Security Benefits of Debloating Web ApplicationsBabak Amin Azad, Pierre Laperdrix, Nick NikiforakisUSENIX Security 2019 · 100 citations
Builds on6
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 798 citations
- Beauty and the Beast: Diverting Modern Web Browsers to Build Unique Browser FingerprintsPierre Laperdrix, Walter Rudametkin, Benoit BaudryS&P 2016 · 279 citations
- ASLR on the Line: Practical Cache Attacks on the MMUBen Gras, Kaveh Razavi, Erik Bosman, Herbert Bos et al.NDSS 2017 · 276 citations
- (Cross-)Browser Fingerprinting via OS and Hardware Level FeaturesYinzhi Cao, Song Li, Erik WijmansNDSS 2017 · 199 citations
- Tracking Mobile Web Users Through Motion Sensors: Attacks and DefensesAnupam Das, Nikita Borisov, Matthew CaesarNDSS 2016 · 145 citations
Related papers
- Who Left Open the Cookie Jar? A Comprehensive Evaluation of Third-Party Cookie PoliciesGertjan Franken, Tom van Goethem, Wouter JoosenUSENIX Security 2018 · 39 citations
- JavaScript Zero: Real JavaScript and Zero Side-Channel AttacksMichael Schwarz, Moritz Lipp, Daniel GrussNDSS 2018 · 67 citations
- Mystique: Uncovering Information Leakage from Browser ExtensionsQuan Chen, Alexandros KapravelosCCS 2018 · 88 citations
- Extending a Hand to Attackers: Browser Privilege Escalation Attacks via ExtensionsYoung Min Kim, Byoungyoung LeeUSENIX Security 2023
- If It's Not Secure, It Should Not Compile: Preventing DOM-Based XSS in Large-Scale Web Development with API HardeningPei Wang, Julian Bangert, Christoph KernICSE 2021 · 9 citations
