About | Contact Us | Register | Login
ProceedingsSeriesJournalsSearchEAI
Security and Privacy in Communication Networks. 19th EAI International Conference, SecureComm 2023, Hong Kong, China, October 19-21, 2023, Proceedings, Part II

Research Article

Securing Web Inputs Using Parallel Session Attachments

Cite
BibTeX Plain Text
  • @INPROCEEDINGS{10.1007/978-3-031-64954-7_10,
        author={Ziqi Yang and Ruite Xu and Qixiao Lin and Shikun Wu and Jian Mao and Zhenkai Liang},
        title={Securing Web Inputs Using Parallel Session Attachments},
        proceedings={Security and Privacy in Communication Networks. 19th EAI International Conference, SecureComm 2023, Hong Kong, China, October 19-21, 2023, Proceedings, Part II},
        proceedings_a={SECURECOMM PART 2},
        year={2024},
        month={10},
        keywords={},
        doi={10.1007/978-3-031-64954-7_10}
    }
    
  • Ziqi Yang
    Ruite Xu
    Qixiao Lin
    Shikun Wu
    Jian Mao
    Zhenkai Liang
    Year: 2024
    Securing Web Inputs Using Parallel Session Attachments
    SECURECOMM PART 2
    Springer
    DOI: 10.1007/978-3-031-64954-7_10
Ziqi Yang,*, Ruite Xu, Qixiao Lin, Shikun Wu, Jian Mao, Zhenkai Liang
    *Contact email: yangziqi@zju.edu.cn

    Abstract

    Web applications have become a cornerstone of the critical cyber infrastructure powering our daily life. Untrusted browser environments, such as public computers and browsers with untrusted extensions, may expose sensitive data in web applications to attackers. One way to protect sensitive data in web sessions is to isolate it using a trusted environment, such as a trusted mobile phone. However, existing solutions either require modifications of web applications to incorporate the trusted environment, or require developers to manually pre-label sensitive data. To address these issues, we propose,WebTeleporter, a lightweight framework to protect users’ sensitive input through a trusted mobile environment. It attaches to the original web session an independent secure parallel session that isolates sensitive input without any change to web applications.WebTeleporteris highly flexible, such that users can choose to opt in to the secure environment at any time, and choose sensitive input to protect on demand. Our evaluation demonstrates thatWebTeleporteris compatible with 11 popular web applications and frameworks. It can protect 99% of pages that contain sensitive input. It takes low overhead to deployWebTeleporter, which is a one-time effort for various applications.WebTeleporterintroduces negligible performance overhead, i.e., 13.9% increase in loading time, and 0.37% decrease in throughput.

    Published
    2024-10-15
    Appears in
    SpringerLink
    http://dx.doi.org/10.1007/978-3-031-64954-7_10
    Copyright © 2023–2025 ICST
    EBSCOProQuestDBLPDOAJPortico
    EAI Logo

    About EAI

    • Who We Are
    • Leadership
    • Research Areas
    • Partners
    • Media Center

    Community

    • Membership
    • Conference
    • Recognition
    • Sponsor Us

    Publish with EAI

    • Publishing
    • Journals
    • Proceedings
    • Books
    • EUDL