Show simple item record

dc.contributor.advisorKnapskog, Svein Johannb_NO
dc.contributor.advisorJ. Knapskog, Sveinnb_NO
dc.contributor.advisorSjödin, Peternb_NO
dc.contributor.advisorBolstad, Lars Eriknb_NO
dc.contributor.authorPrabhakara, Deepaknb_NO
dc.date.accessioned2014-12-19T14:12:25Z
dc.date.available2014-12-19T14:12:25Z
dc.date.created2010-09-03nb_NO
dc.date.issued2009nb_NO
dc.identifier347734nb_NO
dc.identifierntnudaim:4177nb_NO
dc.identifier.urihttp://hdl.handle.net/11250/261782
dc.description.abstractThe Web has evolved to support sophisticated web applications. These web applications are exposed to a number of attacks and vulnerabilities. The existing security model is unable to cope with these increasing attacks and there is a need for a new security model that not only provides the required security but also supports recent advances like AJAX and mashups. The attacks on client-side Web Applications can be attributed to four main reasons – 1) lack of a security context for Web Browsers to take decisions on the legitimacy of requests, 2) inadequate JavaScript security, 3) lack of a Network Access Control and 4) lack of security in Cross-Domain Web Applications. This work explores these four reasons and proposes a new security model that attempts to improve overall security for Web Applications. The proposed security model allows developers of Web Applications to define fine-grained security policies and Web Browsers enforce these rules; analogous to a configurable firewall for each Web Application. The Browser has disallows all unauthorized requests, thus preventing most common attacks like Cross-Site Script Injections, Cross-Frame Scripting and Cross-Site Tracing. In addition the security model defines a framework for secure Cross-Domain Communication, thus allowing secure mashups of Web Services. The security model is backward compatible, does not affect the current usability of the Web Applications and has cross-platform applicability. The proposed security model was proven to protect against most common attacks, by a proof-of-concept implementation that was tested against a comprehensive list of known attacks.nb_NO
dc.languageengnb_NO
dc.publisherInstitutt for telematikknb_NO
dc.subjectntnudaimno_NO
dc.subjectSIE7 kommunikasjonsteknologino_NO
dc.subjectTelematikkno_NO
dc.titleWeb Applications Security: A security model for client-side web applicationsnb_NO
dc.typeMaster thesisnb_NO
dc.source.pagenumber72nb_NO
dc.contributor.departmentNorges teknisk-naturvitenskapelige universitet, Fakultet for informasjonsteknologi, matematikk og elektroteknikk, Institutt for telematikknb_NO


Files in this item

Thumbnail
Thumbnail
Thumbnail

This item appears in the following Collection(s)

Show simple item record