Web Platform Threats: Automated Detection of Web Security Issues With WPT
Pedro Bernardo, Lorenzo Veronese, Valentino Dalla Valle, Stefano Calzavara, Marco Squarcina, Pedro Adão, Matteo Maffei
摘要
Client-side security mechanisms implemented by Web browsers, such as cookie security attributes and the Mixed Content policy, are of paramount importance to protect Web applications. Unfortunately, the design and implementation of such mechanisms are complicated and error-prone, potentially exposing Web applications to security vulnerabilities. In this paper, we present a practical framework to formally and automatically detect security flaws in client-side security mechanisms. In particular, we leverage Web Platform Tests (WPT), a popular cross-browser test suite, to automatically collect browser execution traces and match them against Web invariants, i.e., intended security properties of Web mechanisms expressed in first-order logic. We demonstrate the effectiveness of our approach by validating 9 invariants against the WPT test suite, discovering violations with clear security implications in 104 tests for Firefox, Chromium and Safari. We disclosed the root causes of these violations to browser vendors and standard bodies, which resulted in 8 individual reports and one CVE on Safari.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- RulePilot: An LLM-Powered Agent for Security Rule GenerationHongtai Wang, Ming Xu, Yanpei Guo, Weili Han 等ICSE 2026 · 被引用 1 次
- BUIzz: Finding Policy Enforcement Bugs via Interaction Simulation on the Browser User InterfaceMingi Jung, Donggyu Kim, Mijung Kim, Seongil WiUSENIX Security 2026
- Are your Sites Truly Isolated? Automatically Detecting Logic Bugs in Site Isolation ImplementationsJan Drescher, David Klein, Martin JohnsNDSS 2026
- Plain Text, Plain Risks: Measuring HTTP Inclusion in Android WebViews at ScalePhilipp Beer, Sebastian Roth, Martina Lindorfer, Marco SquarcinaUSENIX Security 2026
- Head(er)s Up! Detecting Security Header Inconsistencies in BrowsersJannis Rautenstrauch, Trung Tin Nguyen, Karthik Ramakrishnan, Ben StockCCS 2025
它引用的顶会 Paper9
- A Comprehensive Formal Security Analysis of OAuth 2.0Daniel Fett, Ralf Küsters, Guido SchmitzCCS 2016 · 被引用 228 次
- JSgraph: Enabling Reconstruction of Web Attacks via Efficient Tracking of Live In-Browser JavaScript ExecutionsBo Li, Phani Vadrevu, Kyu Hyung Lee, Roberto PerdisciNDSS 2018 · 被引用 61 次
- Same-Origin Policy: Evaluation in Modern BrowsersJörg Schwenk, Marcus Niemietz, Christian MainkaUSENIX Security 2017 · 被引用 52 次
- Time Does Not Heal All Wounds: A Longitudinal Analysis of Security-Mechanism Support in Mobile BrowsersMeng Luo, Pierre Laperdrix, Nima Honarmand, Nick NikiforakisNDSS 2019 · 被引用 35 次
- Cookie Crumbles: Breaking and Fixing Web Session IntegrityMarco Squarcina, Pedro Adão, Lorenzo Veronese, Matteo MaffeiUSENIX Security 2023
相关 Paper
- WebSpec: Towards Machine-Checked Analysis of Browser Security MechanismsLorenzo Veronese, Benjamin Farinier, Pedro Bernardo, Mauro Tempesta 等S&P 2023
- Who Left Open the Cookie Jar? A Comprehensive Evaluation of Third-Party Cookie PoliciesGertjan Franken, Tom van Goethem, Wouter JoosenUSENIX Security 2018 · 被引用 39 次
- DiffCSP: Finding Browser Bugs in Content Security Policy Enforcement through Differential TestingSeongil Wi, Trung Tin Nguyen, Jihwan Kim, Ben Stock 等NDSS 2023
- A Tale of Two Headers: A Formal Analysis of Inconsistent Click-Jacking Protection on the WebStefano Calzavara, Sebastian Roth, Alvise Rabitti, Michael Backes 等USENIX Security 2020
- Finding All Cross-Site Needles in the DOM Stack: A Comprehensive Methodology for the Automatic XS-Leak Detection in Web BrowsersDominik Trevor Noß, Lukas Knittel, Christian Mainka, Marcus Niemietz 等CCS 2023
