PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
October 27, 200857 citations

Soma

View Full Paper
TOTerri OdaGWGlenn WursterPOPaul C. van Oorschot

Key Points

Key points are not available for this paper at this time.

Abstract

Unrestricted information flows are a key security weakness of current web design. Cross-site scripting, cross-site request forgery, and other attacks typically require that information be sent or retrieved from arbitrary, often malicious, web servers. In this paper we propose Same Origin Mutual Approval (SOMA), a new policy for controlling information flows that prevents common web vulnerabilities. By requiring site operators to specify approved external domains for sending or receiving information, and by requiring those external domains to also approve interactions, we prevent page content from being retrieved from malicious servers and sensitive information from being communicated to an attacker. SOMA is compatible with current web applications and is incrementally deployable, providing immediate benefits for clients and servers that implement it. SOMA has an overhead of one additional HTTP request per domain accessed and can be implemented with minimal effort by application and web browser developers. To evaluate our proposal, we have developed a Firefox SOMA add-on.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Oda et al. (2008) studied this question.

synapsesocial.com/papers/6a193530dec6c1694ed93cd0https://doi.org/10.1145/1455770.1455783
Ask AI
Helpful
Bookmark
Share
View Full Paper