Lune

CCS2023Top-tier venue

Tainted Secure Multi-Execution to Restrict Attacker Influence

McKenna McCall, Abhishek Bichhawat, Limin Jia

2023Year
1Citations

Abstract

Attackers can steal sensitive user information from web pages via third-party scripts. Prior work shows that secure multi-execution (SME) with declassification is useful for mitigating such attacks, but that attackers can leverage dynamic web features to declassify more than intended. The proposed solution of disallowing events from dynamic web elements to be declassified is too restrictive to be practical; websites that declassify events from dynamic elements cannot function correctly. In this paper, we present SME 𝑇 , a new information flow monitor based on SME which uses taint tracking within each execution to remember what has been influenced by an attacker. The resulting monitor is more permissive than what was proposed by prior work and satisfies both knowledge-and influence-based definitions of security for confidentiality and integrity policies (respectively). We also show that robust declassification follows from our influence-based security condition, for free. Finally, we examine the performance impact of monitoring attacker influence with SME by implementing SME 𝑇 on top of Featherweight Firefox.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext fe866c2a-efe4-4696-be8a-97be3dc8800a

Builds on2

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines