Repository logo
  • English
  • العربية
  • বাংলা
  • Català
  • Čeština
  • Deutsch
  • Ελληνικά
  • Español
  • Suomi
  • Français
  • Gàidhlig
  • हिंदी
  • Magyar
  • Italiano
  • Қазақ
  • Latviešu
  • Nederlands
  • Polski
  • Português
  • Português do Brasil
  • Srpski (lat)
  • Српски
  • Svenska
  • Türkçe
  • Yкраї́нська
  • Tiếng Việt
Log In
New user? Click here to register.Have you forgotten your password?
  1. Home
  2. IIT Gandhinagar
  3. Computer Science and Engineering
  4. CSE Publications
  5. Student research abstract: least privilege persistent-storage access in web browsers
 
  • Details

Student research abstract: least privilege persistent-storage access in web browsers

Date Issued
2024-08-04
Author(s)
Priyadarsini, Gayatri
DOI
10.1145/3605098.3635173
Abstract
Web applications often include third-party content and scripts to personalize a user's online experience. These scripts have unrestricted access to a user's private data stored in the browser's persistent storage like cookies and localstorage associated with the host page. However these third-party scripts can be compromised or may act maliciously and easily access and modify private user information like session-id, user consent, etc., that are stored in the browser.



We propose an approach to enforce least privilege access for third-party scripts on the web storage(cookies and localstorage) objects to ensure their security. We attach labels with the storage objects that specify which domains are allowed to read from and write to these objects on the page. We implement our approach on the Nightly Firefox build and show that it effectively blocks scripts from other domains, which are not allowed access based on these labels, from accessing the storage objects.
Unpaywall
URI
https://d8.irins.org/handle/IITG2025/29951
Subjects
Web Storage
Third-party scripts
Least privilege access control
Web browsers
IITGN Knowledge Repository Developed and Managed by Library

Built with DSpace-CRIS software - Extension maintained and optimized by 4Science

  • Privacy policy
  • End User Agreement
  • Send Feedback
Repository logo COAR Notify