+ All Categories
Home > Documents > Empowering Browser Security for Mobile Devices Using Smart CDNs Ben Livshits and David Molnar...

Empowering Browser Security for Mobile Devices Using Smart CDNs Ben Livshits and David Molnar...

Date post: 15-Jan-2016
Category:
Upload: regan-symonds
View: 214 times
Download: 0 times
Share this document with a friend
Popular Tags:
14
Empowering Browser Security for Mobile Devices Using Smart CDNs Ben Livshits and David Molnar Microsoft Research 1
Transcript
Page 1: Empowering Browser Security for Mobile Devices Using Smart CDNs Ben Livshits and David Molnar Microsoft Research 1.

1

Empowering Browser Security for Mobile Devices Using Smart CDNs

Ben Livshits and David MolnarMicrosoft Research

Page 2: Empowering Browser Security for Mobile Devices Using Smart CDNs Ben Livshits and David Molnar Microsoft Research 1.

2

Mobile Web Growth

Page 3: Empowering Browser Security for Mobile Devices Using Smart CDNs Ben Livshits and David Molnar Microsoft Research 1.

4

Opera Mobile Study

http://www.opera.com/media/smw/2009/pdf/smw032009.pdf

Page 4: Empowering Browser Security for Mobile Devices Using Smart CDNs Ben Livshits and David Molnar Microsoft Research 1.

5

Research in Desktop Browser Security

Page 5: Empowering Browser Security for Mobile Devices Using Smart CDNs Ben Livshits and David Molnar Microsoft Research 1.

6

Mobile: Difficulties of Adoption

http://developer.android.com/resources/dashboard/platform-versions.html

Page 6: Empowering Browser Security for Mobile Devices Using Smart CDNs Ben Livshits and David Molnar Microsoft Research 1.

7

CDNs are Growing

Page 7: Empowering Browser Security for Mobile Devices Using Smart CDNs Ben Livshits and David Molnar Microsoft Research 1.

8

Consequence: Fat Middle Tier

Rise of “smart CDN” (sCDN)What does this mean for security?

Page 8: Empowering Browser Security for Mobile Devices Using Smart CDNs Ben Livshits and David Molnar Microsoft Research 1.

9

Two Research Directions

• What if the middle tier is not trustworthy?

• What new security services can we provide?

Page 9: Empowering Browser Security for Mobile Devices Using Smart CDNs Ben Livshits and David Molnar Microsoft Research 1.

10

Two Research Directions

• What if the middle tier is not trustworthy?

• What new security services can we provide?

Let’s do the easiest one first…

Page 10: Empowering Browser Security for Mobile Devices Using Smart CDNs Ben Livshits and David Molnar Microsoft Research 1.

11

Example Service: Nozzle in Mobile

• Nozzle is a heap spraying prevention system that protects desktop browsers [UsenixSec’09]

• How to deploy Nozzle on mobile browsers?• Software updates on all handsets..?• Same problem for any browser based

mitigation – StackGuard, RandomHeap, your paper at W2SP20XX…

Page 11: Empowering Browser Security for Mobile Devices Using Smart CDNs Ben Livshits and David Molnar Microsoft Research 1.

12

Example Service: Nozzle in Mobile

Run Nozzle in sCDN!Catch heap sprays,pre-render benign pages,ship renders to mobile.

Page 12: Empowering Browser Security for Mobile Devices Using Smart CDNs Ben Livshits and David Molnar Microsoft Research 1.

13

More sCDN Security Services

• Real Time phish tracking– “Why is everyone suddenly going to whuffo.com?”

• URL reputation– “15 other people were owned by this URL”

• XSS filters• Fuzz testing seeded with real traces

Page 13: Empowering Browser Security for Mobile Devices Using Smart CDNs Ben Livshits and David Molnar Microsoft Research 1.

14

Untrustworthy Infrastructure?

• Multiple vendors– Linksys, Cisco, Akamai, Limelight, …

• Multiple operators– Comcast, Sprint, AT&T, T-Mobile, Joe Sixpack, …

• Multiple web applications• How do these parties work together?• What about privacy?

Page 14: Empowering Browser Security for Mobile Devices Using Smart CDNs Ben Livshits and David Molnar Microsoft Research 1.

15

Two Research Directions

• What if the middle tier is not trustworthy?

• What new security services can we provide?


Recommended