Skip to main content

Showing 1–4 of 4 results for author: Tempesta, M

.
  1. arXiv:2201.01649  [pdf, other

    cs.CR

    WebSpec: Towards Machine-Checked Analysis of Browser Security Mechanisms

    Authors: Lorenzo Veronese, Benjamin Farinier, Pedro Bernardo, Mauro Tempesta, Marco Squarcina, Matteo Maffei

    Abstract: The complexity of browsers has steadily increased over the years, driven by the continuous introduction and update of Web platform components, such as novel Web APIs and security mechanisms. Their specifications are manually reviewed by experts to identify potential security issues. However, this process has proved to be error-prone due to the extensiveness of modern browser specifications and the… ▽ More

    Submitted 1 September, 2022; v1 submitted 5 January, 2022; originally announced January 2022.

    Comments: Submitted to IEEE S&P '23 on 19 Aug 2022

  2. arXiv:2012.01946  [pdf, other

    cs.CR

    Can I Take Your Subdomain? Exploring Related-Domain Attacks in the Modern Web

    Authors: Marco Squarcina, Mauro Tempesta, Lorenzo Veronese, Stefano Calzavara, Matteo Maffei

    Abstract: Related-domain attackers control a sibling domain of their target web application, e.g., as the result of a subdomain takeover. Despite their additional power over traditional web attackers, related-domain attackers received only limited attention by the research community. In this paper we define and quantify for the first time the threats that related-domain attackers pose to web application sec… ▽ More

    Submitted 3 December, 2020; originally announced December 2020.

    Comments: Submitted to USENIX Security '21 on 16 Oct 2020

  3. arXiv:2001.10405  [pdf, ps, other

    cs.CR

    Language-Based Web Session Integrity

    Authors: Stefano Calzavara, Riccardo Focardi, Niklas Grimm, Matteo Maffei, Mauro Tempesta

    Abstract: Session management is a fundamental component of web applications: despite the apparent simplicity, correctly implementing web sessions is extremely tricky, as witnessed by the large number of existing attacks. This motivated the design of formal methods to rigorously reason about web session security which, however, are not supported at present by suitable automated verification techniques. In th… ▽ More

    Submitted 2 June, 2020; v1 submitted 28 January, 2020; originally announced January 2020.

  4. arXiv:1806.09111  [pdf, other

    cs.CR

    WPSE: Fortifying Web Protocols via Browser-Side Security Monitoring

    Authors: Stefano Calzavara, Riccardo Focardi, Matteo Maffei, Clara Schneidewind, Marco Squarcina, Mauro Tempesta

    Abstract: We present WPSE, a browser-side security monitor for web protocols designed to ensure compliance with the intended protocol flow, as well as confidentiality and integrity properties of messages. We formally prove that WPSE is expressive enough to protect web applications from a wide range of protocol implementation bugs and web attacks. We discuss concrete examples of attacks which can be prevente… ▽ More

    Submitted 24 June, 2018; originally announced June 2018.