Collected research
Web Platform Threats: Automated Detection of Web Security Issues With WPT
Proposes a framework that formalises intended security properties of client-side browser mechanisms such as cookie attributes and the Mixed Content policy as first-order-logic Web invariants, then checks browser execution traces collected from the Web Platform Tests suite against them. Validating 9 invariants uncovered violations with clear security implications in 104 tests across Firefox, Chromium and Safari, yielding 8 vendor reports and one Safari CVE.
Record
- Researcher
- Pedro Bernardo, Lorenzo Veronese, Valentino Dalla Valle, Stefano Calzavara, Marco Squarcina, Pedro Adão and Matteo Maffei
- Published by
- usenix.org
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Pedro Bernardo, Lorenzo Veronese, Valentino Dalla Valle, Stefano Calzavara, Marco Squarcina, Pedro Adão and Matteo Maffei, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .