• Home
  • Search
  • CorbFuzz: Checking Browser Security Policies with Fuzzing
  • Open Access IconOpen Access
  • Cite Icon5
  • https://doi.org/10.1109/ase51524.2021.9678636Copy DOI Icon

CorbFuzz: Checking Browser Security Policies with Fuzzing

  • Nov 1, 2021
  • Chaofan Shou +3 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Browsers use security policies to block malicious behaviors. Cross-Origin Read Blocking (CORB) is a browser security policy for preventing side-channel attacks such as Spectre. We propose a web browser security policy fuzzer called CorbFuzz for checking CORB and similar policies. In implementing a security policy, the browser only has access to HTTP requests and responses, and takes policy actions based solely on those interactions. In checking the browser security policies, CorbFuzz uses a policy oracle that tracks the web application behavior and infers the desired policy action based on the web application state. By comparing the policy oracle with the browser behavior, CorbFuzz detects weaknesses in browser security policies. CorbFuzz checks the web browser policy by fuzzing a set of web applications where the state-related queries are symbolically evaluated for increased coverage and automation. CorbFuzz collects type information from database queries and branch conditions in order to prevent the generation of inconsistent data values during fuzzing. We evaluated CorbFuzz on CORB implementations of Chromium and Webkit, and Opaque Response Blocking (ORB) policy implementation of Firefox using web applications collected from GitHub. We found three classes of weaknesses in Chromium’s implementation of CORB.

Similar Papers
  • Research Article
  • Citations131

Securing frame communication in browsers

  • Jun 01, 2009
  • Communications of the ACM
  • Adam Barth +2
  • Book Chapter

Interface Module for Emulator-Based Web Application Execution Engine

  • Oct 12, 2018
  • Hyunwoo Nam +1
  • Book Chapter

Resource-Based Web Applications

  • Jun 01, 2005
  • Sebastian Fischer
  • Book Chapter

More Server Controls

  • Jan 01, 2020
  • Robert E Beasley
  • Research Article
  • Citations137

The essence of command injection attacks in web applications

  • Jan 11, 2006
  • ACM SIGPLAN Notices
  • Zhendong Su +1
  • Conference Article
  • Citations555

The essence of command injection attacks in web applications

  • Jan 11, 2006
  • Zhendong Su +1
  • PDF
  • Research Article
  • Citations1

Improving Web Application Security Using Penetration Testing

  • Aug 05, 2014
  • Research Journal of Applied Sciences, Engineering and Technology
  • D Srinithi +3
  • Conference Article
  • Citations29

FlowWatcher

  • Oct 12, 2015
  • Divya Muthukumaran +5
  • Conference Article
  • Citations7

An adaptive programming framework for Web applications

  • Aug 24, 2004
  • Po-Hao Chang +2
  • Research Article

Automated Server-Side Regression Testing for Web Applications

  • Jan 01, 2012
  • International Journal of Computers and Applications
  • Takao Shimomura
  • Conference Article
  • Citations161

Some Trends in Web Application Development

  • May 01, 2007
  • Mehdi Jazayeri
  • Conference Article
  • Citations16

The Web Browser as Distributed Application Server

  • Mar 25, 2019
  • Kristof Jannes +2
  • PDF
  • Research Article
  • Citations16

CITYJSON + WEB = NINJA

  • Sep 03, 2020
  • ISPRS Annals of the Photogrammetry, Remote Sensing and Spatial Information Sciences
  • S Vitalis +7
  • Book Chapter
  • Citations1

Event-Driven Implementation of Layer-7 Load Balancer

  • Jan 01, 2013
  • Takayuki Sasajima +1
  • Conference Article
  • Citations1

Parallel implementation of public key cryptosystems using Web workers

  • Jan 01, 2014
  • Takuya Sumi +5
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.