题名 | Poster: Finding Javascript name conflicts on the web |
作者 | |
DOI | |
发表日期 | 2019
|
ISSN | 1543-7221
|
会议录名称 | |
页码 | 2609-2611
|
会议地点 | London, United kingdom
|
出版地 | 1515 BROADWAY, NEW YORK, NY 10036-9998 USA
|
出版者 | |
摘要 | Including JavaScript code from many different hosts is a popular practice in developing web applications. For example, to include a social plugin like the Facebook Like button, a web developer needs to only include a script from facebook.net in her/his web page. However, in a web browser, all the identifiers (i.e., variable names and function names) in scripts loaded in the same frame share a single global namespace. Therefore, a script can overwrite any of the global variables and/or global functions defined in another script, causing unexpected behavior. In this work, we develop a browser-based dynamic analysis framework, that monitors and records any writes to JavaScript global variables and global functions. Our tool is able to cover all the code executed in the run time. We detected 778 conflicts across the Alexa top 1K websites. Our results show that global name conflicts can indeed expose web applications to security risks. © 2019 Association for Computing Machinery. |
关键词 | |
学校署名 | 其他
|
语种 | 英语
|
相关链接 | [来源记录] |
收录类别 | |
资助项目 | Research Grants Council, University Grants Committee[CUHK 24209418]
|
WOS研究方向 | Computer Science
; Telecommunications
|
WOS类目 | Computer Science, Information Systems
; Computer Science, Theory & Methods
; Telecommunications
|
WOS记录号 | WOS:000509760700173
|
EI入藏号 | 20195007799424
|
EI主题词 | Codes (symbols)
; Websites
|
EI分类号 | Computer Programming Languages:723.1.1
; Data Processing and Image Processing:723.2
|
来源库 | EV Compendex
|
引用统计 |
被引频次[WOS]:2
|
成果类型 | 会议论文 |
条目标识符 | http://sustech.caswiz.com/handle/2SGJ60CL/50838 |
专题 | 南方科技大学 |
作者单位 | 1.Chinese University of Hong Kong, Hong Kong 2.Southern University of Science and Technology, China |
推荐引用方式 GB/T 7714 |
Zhang, Mingxue,Meng, Wei,Wang, Yi. Poster: Finding Javascript name conflicts on the web[C]. 1515 BROADWAY, NEW YORK, NY 10036-9998 USA:Association for Computing Machinery,2019:2609-2611.
|
条目包含的文件 | 条目无相关文件。 |
|
除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。
修改评论