Visible to the public Content-based Security for the Web

TitleContent-based Security for the Web
Publication TypeConference Paper
Year of Publication2016
AuthorsAfanasyev, Alexander, Halderman, J. Alex, Ruoti, Scott, Seamons, Kent, Yu, Yingdi, Zappala, Daniel, Zhang, Lixia
Conference NameProceedings of the 2016 New Security Paradigms Workshop
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-4813-3
Keywordscontent-based security, end-to-end encryption, Human Behavior, Key Management, Metrics, pubcrawl, Resiliency, Scalability, web security
Abstract

The World Wide Web has become the most common platform for building applications and delivering content. Yet despite years of research, the web continues to face severe security challenges related to data integrity and confidentiality. Rather than continuing the exploit-and-patch cycle, we propose addressing these challenges at an architectural level, by supplementing the web's existing connection-based and server-based security models with a new approach: content-based security. With this approach, content is directly signed and encrypted at rest, enabling it to be delivered via any path and then validated by the browser. We explore how this new architectural approach can be applied to the web and analyze its security benefits. We then discuss a broad research agenda to realize this vision and the challenges that must be overcome.

URLhttp://doi.acm.org/10.1145/3011883.3011890
DOI10.1145/3011883.3011890
Citation Keyafanasyev_content-based_2016