Securing Web Inputs Using Parallel Session Attachments

  • Ziqi Yang*
  • , Ruite Xu
  • , Qixiao Lin
  • , Shikun Wu
  • , Jian Mao
  • , Zhenkai Liang
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Web applications have become a cornerstone of the critical cyber infrastructure powering our daily life. Untrusted browser environments, such as public computers and browsers with untrusted extensions, may expose sensitive data in web applications to attackers. One way to protect sensitive data in web sessions is to isolate it using a trusted environment, such as a trusted mobile phone. However, existing solutions either require modifications of web applications to incorporate the trusted environment, or require developers to manually pre-label sensitive data. To address these issues, we propose, WebTeleporter, a lightweight framework to protect users’ sensitive input through a trusted mobile environment. It attaches to the original web session an independent secure parallel session that isolates sensitive input without any change to web applications. WebTeleporter is highly flexible, such that users can choose to opt in to the secure environment at any time, and choose sensitive input to protect on demand. Our evaluation demonstrates that WebTeleporter is compatible with 11 popular web applications and frameworks. It can protect 99% of pages that contain sensitive input. It takes low overhead to deploy WebTeleporter, which is a one-time effort for various applications. WebTeleporter introduces negligible performance overhead, i.e., 13.9% increase in loading time, and 0.37% decrease in throughput.

Original languageEnglish
Title of host publicationSecurity and Privacy in Communication Networks - 19th EAI International Conference, SecureComm 2023, Proceedings
EditorsHaixin Duan, Mourad Debbabi, Xavier de Carné de Carnavalet, Xiapu Luo, Man Ho Allen Au, Xiaojiang Du
PublisherSpringer Science and Business Media Deutschland GmbH
Pages189-208
Number of pages20
ISBN (Print)9783031649530
DOIs
StatePublished - 2025
Event19th EAI International Conference on Security and Privacy in Communication Networks, SecureComm 2023 - Hong Kong, China
Duration: 19 Oct 202321 Oct 2023

Publication series

NameLecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering, LNICST
Volume568 LNICST
ISSN (Print)1867-8211
ISSN (Electronic)1867-822X

Conference

Conference19th EAI International Conference on Security and Privacy in Communication Networks, SecureComm 2023
Country/TerritoryChina
CityHong Kong
Period19/10/2321/10/23

Fingerprint

Dive into the research topics of 'Securing Web Inputs Using Parallel Session Attachments'. Together they form a unique fingerprint.

Cite this