A security architecture for server-side JavaScript: Extended abstract

user-5f8411ab4c775e9685ff56d3(2014)

引用 0|浏览2
暂无评分
摘要
Node.js is a popular JavaScript server-side framework with an efficient runtime for cloud-based eventdriven architectures. Its strength is the presence of thousands of third party libraries which allow developers to quickly build and deploy applications. These very libraries are a source of security threats as a vulnerability in one library can (and in some cases did) compromise one’s entire server. In order to support the least-privilege integration of libraries we develop NodeSentry, the first security architecture for server-side JavaScript. Our policy enforcement infrastructure supports an easy deployment of web-hardening techniques and access control policies on interactions between libraries and their environment, including any dependent library.
更多
查看译文
关键词
Unobtrusive JavaScript,JavaScript,Enterprise information security architecture,Access control,Server-side,Cloud computing,Software deployment,World Wide Web,Vulnerability,Computer science
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要