Oblique: Accelerating Page Loads Using Symbolic Execution
Ronny Ko, James Mickens, Blake Loring, Ravi Netravali
摘要
Mobile devices are often stuck behind high-latency links. Unfortunately for mobile browsers, latency (not bandwidth) is often the key influence on page load time. Proxy-based web accelerators hide last-mile latency by analyzing a page's content, and informing clients about useful objects to prefetch. However, most accelerators require content providers to divulge cleartext HTTPS data to third-party analysis servers. Acceleration systems can be installed on first-party web servers, avoiding the violation of end-to-end TLS security; however, due to the administrative overhead (and additional VM costs) associated with running an accelerator, many first-party content providers would prefer to outsource the acceleration work-if outsourcing could be secure.
In this paper, we introduce Oblique, a third-party web accelerator which enables secure outsourcing of page analysis.
Oblique symbolically executes the client-side of a page load, generating a prefetch list of symbolic URLs. Each symbolic URL describes a URL that a client browser should fetch, given user-specific values for cookies, the User-Agent string, and other sensitive variables. Those sensitive values are never revealed to Oblique's analysis server. Instead, during a real page load, the user's browser concretizes URLs by reading sensitive local state; the browser can then prefetch the associated objects. Experiments involving real sites demonstrate that Oblique preserves TLS integrity while providing faster page loads than state-of-the-art accelerators. For popular sites, Oblique is also financially cheaper in terms of VM costs.
=="Chrome Mobile"
First-party web servers Client browser 4 5 https_req::UserAgent Other browser types dark-mode.css gui.js https_req::cookie["uid"].html light-mode.css gui.js default.html https_req::cookie["darkMode"] =="yes" ==("no" || "")
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Eunomia: Enabling User-Specified Fine-Grained Search in Symbolically Executing WebAssembly BinariesNingyu He, Zhehao Zhao, Jikai Wang, Yubin Hu 等ISSTA 2023 · 被引用 10 次
- Horcrux: Automatic JavaScript Parallelism for Resource-Efficient Web ComputationShaghayegh Mardani, Ayush Goel, Ronny Ko, Harsha V. Madhyastha 等OSDI 2021 · 被引用 9 次
- Sprinter: Speeding Up High-Fidelity Crawling of the Modern WebAyush Goel, Jingyuan Zhu, Ravi Netravali, Harsha V. MadhyasthaNSDI 2024 · 被引用 5 次
- Visual-Aware Testing and Debugging for Web Performance OptimizationXinlei Yang, Wei Liu, Hao Lin, Zhenhua Li 等WWW 2023 · 被引用 4 次
- Jawa: Web Archival in the Era of JavaScriptAyush Goel, Jingyuan Zhu, Ravi Netravali, Harsha V. MadhyasthaOSDI 2022
相关 Paper
- Fawkes: Faster Mobile Page Loads via App-Inspired Static TemplatingShaghayegh Mardani, Mayank Singh, Ravi NetravaliNSDI 2020 · 被引用 13 次
- Deconstructing Google's Web Light ServiceAmmar Tahir, Muhammad Tahir Munir, Shaiq Munir Malik, Zafar Ayyub Qazi 等WWW 2020 · 被引用 7 次
- Protecting Insecure Communications with Topology-aware Network TunnelsGeorgios Kontaxis, Angelos D. KeromytisCCS 2016 · 被引用 1 次
- Who's Hosting the Block Party? Studying Third-Party Blockage of CSP and SRIMarius Steffens, Marius Musch, Martin Johns, Ben StockNDSS 2021
- A Large-Scale Measurement Study of the PROXY Protocol and its Security ImplicationsStijn Pletinckx, Christopher Kruegel, Giovanni VignaNDSS 2025
