Web Hack List

Collected research

Web Platform Threats: Automated Detection of Web Security Issues With WPT

Proposes a framework that formalises intended security properties of client-side browser mechanisms such as cookie attributes and the Mixed Content policy as first-order-logic Web invariants, then checks browser execution traces collected from the Web Platform Tests suite against them. Validating 9 invariants uncovered violations with clear security implications in 104 tests across Firefox, Chromium and Safari, yielding 8 vendor reports and one Safari CVE.

Record

Researcher
Pedro Bernardo, Lorenzo Veronese, Valentino Dalla Valle, Stefano Calzavara, Marco Squarcina, Pedro Adão and Matteo Maffei
Published by
usenix.org
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Pedro Bernardo, Lorenzo Veronese, Valentino Dalla Valle, Stefano Calzavara, Marco Squarcina, Pedro Adão and Matteo Maffei, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .