Title
Content-based security for the web.
Abstract
The World Wide Web has become the most common platform for building applications and delivering content. Yet despite years of research, the web continues to face severe security challenges related to data integrity and confidentiality. Rather than continuing the exploit-and-patch cycle, we propose addressing these challenges at an architectural level, by supplementing the web's existing connection-based and server-based security models with a new approach: content-based security. With this approach, content is directly signed and encrypted at rest, enabling it to be delivered via any path and then validated by the browser. We explore how this new architectural approach can be applied to the web and analyze its security benefits. We then discuss a broad research agenda to realize this vision and the challenges that must be overcome.
Year
DOI
Venue
2016
10.1145/3011883.3011890
NSPW
Keywords
Field
DocType
content-based security, web security, end-to-end encryption
Web development,World Wide Web,Internet privacy,Computer security,Computer science,Web engineering,Security service,Web modeling,Web application security,Web navigation,Web service,Content Security Policy
Conference
Citations 
PageRank 
References 
1
0.35
16
Authors
7
Name
Order
Citations
PageRank
Alexander Afanasyev1107361.37
J. Alex Halderman22301149.67
Scott Ruoti39214.30
Kent E. Seamons41161150.55
Yingdi Yu510.35
Daniel Zappala6517.92
Lixia Zhang7117292506.06