WEBAPPSEC · Web Application Security Policies and Enforcement
FP7 — People (Marie Curie Actions)
- Duration
- 2008-05-01 → 2012-04-30
- EU contribution
- €100,000
- Participants
- 1
- Scheme
- MC-IRG
Lines connect the coordinator with its partners.
Results in brief
Periodic Report Summary - WEBAPPSEC (Web Application Security Policies and Enforcement)
The focus of the project was to develop the theoretical knowledge and practical mechanisms needed to address security concerns in web applications. Web applications entail software, scripts and other executable components running on the user's computer, without the user having specifically installed the software. This has many benefits in terms of providing users access to interactive content and even full software functionality through the web, but it also creates new security issues. This project was addressing core issues involved in modeling security threats and security mechanisms in that context. Three specific elements were off to a good start within the project. The analysis of programming languages as an element in providing security is a notion different from the traditional emphasis on the operating system. Another was the development of control-flow integrity principles to prevent the possibility of malicious subversion of application machine code. The third was the development of secure distributed aggregation functionality, which addresses some of the issues that arise in collaboration between applications in different systems.
Data: CORDIS, © European Union
Project objective
We are all increasingly dependent on information systems and thus affected by how those systems are implemented in terms of their security, reliability, and protection of our privacy. In the future, interactive, high-functionality Web applications are likely to be one of the foundations on which services are provisioned and accessed in society at large. There is a great, current opportunity for the principled consideration of the security of these Web applications, and a re-thinking of previous assumptions. This grant project will perform such a reconsideration of the fundamentals of Web application security, giving special considerations to the three current developments known as Web 2.0. These are a new generation of richer Web content, such as interactive video, the aggregation of Web functionality from many services, and, finally, the migration of Web application functionality to the client Web browsers, in the form of scripts and other executable content. Concretely, the project will develop a new model of threats and attacks and security policies that apply to Web applications, including policies for service availability, data integrity, information secrecy and end-user privacy. In particular, the project will consider application-specific security policies, including commercial security policies, such those that apply to pricing in Web commerce, and take a new view of Web client responsibilities. A project goal is to enable the automatic derivation of such policies through static or dynamic analysis of the Web application and its manner of composition. The project will also develop flexible enforcement mechanisms for Web application security policies, including mechanisms based on inlined reference monitors and dynamic tracking of information flow. These mechanisms will rely on the inherently dynamic and fluid software distribution of Web Applications, which allows security-related changes such as monitoring code to be pushed to the end user.
Original text from CORDIS.
Participants
- HASKOLINN I REYKJAVIK EHF · REYKJAVIKCoordinatorIceland
Links
Data: CORDIS, © European Union
