Christoph Kerschbaumer

dblp:41/8026 · DBLP profile ↗
← Back
5ranked-venue papers
3as first author
1since 2021 · last 2022
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Systems and software security · 87% Web and mobile security · 13%
Software engineering, system software, and programming languages
1 paper
Runtime systems and virtual machines · 100%

Topics — the 4 heaviest of 4, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security
information flow tracking
0.212013
Information flow tracking meets just-in-time compilation · ACM Trans. Archit. Code Optim. 2013
Systems and software security
javascript engine
0.212013
Information flow tracking meets just-in-time compilation · ACM Trans. Archit. Code Optim. 2013
Runtime systems and virtual machines › dynamic compilation
just-in-time compilation
0.212013
Information flow tracking meets just-in-time compilation · ACM Trans. Archit. Code Optim. 2013
Web and mobile security › web security
cross-site scripting
0.012013
Information flow tracking meets just-in-time compilation · ACM Trans. Archit. Code Optim. 2013

Methods — techniques the papers use, named apart from their topics

just-in-time compilation · 0.3information flow tracking · 0.3
YearPublicationVenuePosition
2022 SoK: All or Nothing - A Postmortem of Solutions to the Third-Party Script Inclusion Permission Model and a Path Forward
abstract
The web execution model allows third-party JavaScript to be leveraged in a single execution context. Access control for these scripts is currently all or nothing. It has been this way for over a decade despite the knowledge that this model allows for privacy violations and even user data exfiltration. Consequently, users have little to no control over which third-parties operate on their Personally Identifying Information (PII) when interacting with a web application. In this work we aim to explain the lack of solutions to this problem, and to suggest more promising future directions. We first survey past proposed solutions and their trade-offs. We then create a monitoring system in the Firefox browser which captures third-party script access to user supplied PII in HTML Form Elements. We proceed to inspect 100,000 websites with our Monitor and custom web crawler to highlight the complexity of use cases of third-party scripts operating on user PII. Our findings inform the creation of a grading rubric and systematization for solutions in this space, which we then apply to many previous works. The complexity exposed through this effort allows us to start a discussion around why current technological and policy solutions fail adoption. Ultimately we propose a research direction that allows web applications to take advantage of the interoperability of the web execution model while also respecting an end user's privacy and security.
Steven Sprecher, Christoph Kerschbaumer, Engin Kirda
EuroS&P2
2017 Extending the Same Origin Policy with Origin Attributes
Tanvi Vyas, Andrea Marchesini, Christoph Kerschbaumer
ICISSP3
2016 Injecting CSP for Fun and Security
Christoph Kerschbaumer, Sid Stamm, Stefan Brunthaler 0001
ICISSP1
2013 CrowdFlow: Efficient Information Flow Security
Christoph Kerschbaumer, Eric Hennigan, Per Larsen, Stefan Brunthaler 0001, Michael Franz
ISC1
2013 Information flow tracking meets just-in-time compilation
abstract
Web applications are vulnerable to cross-site scripting attacks that enable data thefts. Information flow tracking in web browsers can prevent communication of sensitive data to unintended recipients and thereby stop such data thefts. Unfortunately, existing solutions have focused on incorporating information flow into browsers’ JavaScript interpreters, rather than just-in-time compilers, rendering the resulting performance noncompetitive. Few users will switch to a safer browser if it comes at the cost of significantly degrading web application performance. We present the first information flow tracking JavaScript engine that is based on a true just-in-time compiler, and that thereby outperforms all previous interpreter-based information flow tracking JavaScript engines by more than a factor of two. Our JIT-based engine (i) has the same coverage as previous interpreter- based solutions, (ii) requires reasonable implementation effort, and (iii) introduces new optimizations to achieve acceptable performance. When evaluated against three industry-standard JavaScript benchmark suites, there is still an average slowdown of 73% over engines that do not support information flow, but this is now well within the range that many users will find an acceptable price for obtaining substantially increased security.
Christoph Kerschbaumer, Eric Hennigan, Per Larsen, Stefan Brunthaler 0001, Michael Franz
ACM Trans. Archit. Code Optim.1