WAIT: Protecting the Integrity of Web Applications with Binary-Equivalent Transparency

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Meißner, Echo, Kargl, Frank, Erb, Benjamin
Format: Preprint
Veröffentlicht: 2021
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866910658363129856
author Meißner, Echo
Kargl, Frank
Erb, Benjamin
author_facet Meißner, Echo
Kargl, Frank
Erb, Benjamin
contents Modern single page web applications require client-side executions of application logic, including critical functionality such as client-side cryptography. Existing mechanisms such as TLS and Subresource Integrity secure the communication and provide external resource integrity. However, the browser is unaware of modifications to the client-side application as provided by the server and the user remains vulnerable against malicious modifications carried out on the server side. Our solution makes such modifications transparent and empowers the browser to validate the integrity of a web application based on a publicly verifiable log. Our Web Application Integrity Transparency (WAIT) approach requires (1) an extension for browsers for local integrity validations, (2) a custom HTTP header for web servers that host the application, and (3) public log servers that serve the verifiable logs. With WAIT, the browser can disallow the execution of undisclosed application changes. Also, web application providers cannot dispute their authorship for published modifications anymore. Although our approach cannot prevent every conceivable attack on client-side web application integrity, it introduces a novel sense of transparency for users and an increased level of accountability for application providers particularly effective against targeted insider attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2104_06136
institution arXiv
publishDate 2021
record_format arxiv
spellingShingle WAIT: Protecting the Integrity of Web Applications with Binary-Equivalent Transparency
Meißner, Echo
Kargl, Frank
Erb, Benjamin
Cryptography and Security
Modern single page web applications require client-side executions of application logic, including critical functionality such as client-side cryptography. Existing mechanisms such as TLS and Subresource Integrity secure the communication and provide external resource integrity. However, the browser is unaware of modifications to the client-side application as provided by the server and the user remains vulnerable against malicious modifications carried out on the server side. Our solution makes such modifications transparent and empowers the browser to validate the integrity of a web application based on a publicly verifiable log. Our Web Application Integrity Transparency (WAIT) approach requires (1) an extension for browsers for local integrity validations, (2) a custom HTTP header for web servers that host the application, and (3) public log servers that serve the verifiable logs. With WAIT, the browser can disallow the execution of undisclosed application changes. Also, web application providers cannot dispute their authorship for published modifications anymore. Although our approach cannot prevent every conceivable attack on client-side web application integrity, it introduces a novel sense of transparency for users and an increased level of accountability for application providers particularly effective against targeted insider attacks.
title WAIT: Protecting the Integrity of Web Applications with Binary-Equivalent Transparency
topic Cryptography and Security
url https://arxiv.org/abs/2104.06136