Skip to main content

Showing 1–1 of 1 results for author: Karel, B

Searching in archive cs. Search in all archives.
.
  1. arXiv:2011.00253  [pdf, other

    cs.CR

    Mir: Automated Quantifiable Privilege Reduction Against Dynamic Library Compromise in JavaScript

    Authors: Nikos Vasilakis, Cristian-Alexandru Staicu, Grigoris Ntousakis, Konstantinos Kallas, Ben Karel, André DeHon, Michael Pradel

    Abstract: Third-party libraries ease the development of large-scale software systems. However, they often execute with significantly more privilege than needed to complete their task. This additional privilege is often exploited at runtime via dynamic compromise, even when these libraries are not actively malicious. Mir addresses this problem by introducing a fine-grained read-write-execute (RWX) permission… ▽ More

    Submitted 1 January, 2021; v1 submitted 31 October, 2020; originally announced November 2020.