Isolating JavaScript with filters, rewriting, and wrappers
File(s)DTR09-6.pdf (366.98 KB)
Published version
Author(s)
Maffeis, Sergio
Mitchell, John C
Taly, Ankur
Type
Report
Abstract
We study methods that allow web sites to safely combine JavaScript
from untrusted sources. If implemented properly, lters can prevent dangerous
code from loading into the execution environment, while rewriting allows greater
expressiveness by inserting run-time checks. Wrapping properties of the execu-
tion environment can prevent misuse without requiring changes to imported
JavaScript.
Using a formal semantics for the ECMA 262-3 standard language, we prove
security properties of a subset of JavaScript, comparable in expressiveness to
Facebook FBJS, obtained by combining three isolation mechanisms. The isola-
tion guarantees of the three mechanisms are interdependent, with rewriting and
wrapper functions relying on the absence of JavaScript constructs eliminated
by language lters.
from untrusted sources. If implemented properly, lters can prevent dangerous
code from loading into the execution environment, while rewriting allows greater
expressiveness by inserting run-time checks. Wrapping properties of the execu-
tion environment can prevent misuse without requiring changes to imported
JavaScript.
Using a formal semantics for the ECMA 262-3 standard language, we prove
security properties of a subset of JavaScript, comparable in expressiveness to
Facebook FBJS, obtained by combining three isolation mechanisms. The isola-
tion guarantees of the three mechanisms are interdependent, with rewriting and
wrapper functions relying on the absence of JavaScript constructs eliminated
by language lters.
Date Issued
2009-01-01
Citation
Departmental Technical Report: 09/6, 2009, pp.1-29
Publisher
Department of Computing, Imperial College London
Start Page
1
End Page
29
Journal / Book Title
Departmental Technical Report: 09/6
Copyright Statement
© 2009 The Author(s). This report is available open access under a CC-BY-NC-ND (https://creativecommons.org/licenses/by-nc-nd/4.0/)
Publication Status
Published
Article Number
09/6