Reference. Fission: Secure Dynamic Code-Splitting for JavaScript

Traditional web programming involves the creation of two distinct programs: a client-side front-end, a server-side back-end, and a lot of communications boilerplate. An alternative approach is to use a tierless programming model, where a single program describes the behavior of both the client and the server, and the runtime system takes care of communication. Unfortunately, this usually entails adopting a new language and thus abandoning well-worn libraries and web programming tools.

In this paper, we present our ongoing work on Fission, a platform that uses dynamic tier-splitting and dynamic information flow control to transparently run a single JavaScript program across the client and server. Although static tier-splitting has been studied before, our focus on dynamic approaches presents several new challenges and opportunities. For example, Fission supports characteristic JavaScript features such as eval and sophisticated JavaScript libraries like React. Therefore, programmers can reason about the integrity and confidentiality of information while continuing to use common libraries and programming patterns. Moreover, by unifying the client and server into a single program, Fission allows language-based tools, like type systems and IDEs, to manipulate complete web applications. To illustrate, we use TypeScript to ensure that client-server communication does not go wrong.

Cite

Cite as @guha-2017-fission (helia, typst) · \cite{guha-2017-fission} (LaTeX)
BibTeX
bibtex · 14 lines
@inproceedings{guha-2017-fission,
  doi = {10.4230/LIPICS.SNAPL.2017.5},
  url = {https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.SNAPL.2017.5},
  author = {Guha, Arjun and Jeannin, Jean-Baptiste and Nigam, Rachit and Tangen, Jane and Shambaugh, Rian},
  keywords = {JavaScript, information flow control},
  language = {en},
  title = {Fission: Secure Dynamic Code-Splitting for JavaScript},
  volume = {71},
  pages = {5:1-5:13},
  publisher = {Schloss Dagstuhl – Leibniz-Zentrum für Informatik},
  year = {2017},
  copyright = {Creative Commons Attribution 3.0 Unported license},
  booktitle = {2nd Summit on Advances in Programming Languages (SNAPL 2017)}
}
hayagriva YAML (typst)
yaml · 19 lines
guha-2017-fission:
  type: article
  title: 'Fission: Secure Dynamic Code-Splitting for JavaScript'
  author:
  - Guha, Arjun
  - Jeannin, Jean-Baptiste
  - Nigam, Rachit
  - Tangen, Jane
  - Shambaugh, Rian
  date: 2017
  page-range: 5:1-5:13
  url: https://drops.dagstuhl.de/entities/document/10.4230/LIPIcs.SNAPL.2017.5
  serial-number:
    doi: 10.4230/LIPICS.SNAPL.2017.5
  parent:
    type: proceedings
    title: 2nd Summit on Advances in Programming Languages (SNAPL 2017)
    publisher: Schloss Dagstuhl – Leibniz-Zentrum für Informatik
    volume: 71
Cites 56 works (0 here)
External (56)
  • Bounty hunters: The honor roll (2017)
  • XSS vulnerability in Action View in Ruby on Rails (2017)
  • Facebook bug bounty: $5 million paid in 5 years (2017)
  • Google security rewards–2015 year in review (2017)
  • U.S. election agency breached by hackers after November vote (2017)
  • WordPress 4.6.1 security and maintenance release (2017)
  • Type inference for static compilation of JavaScript (2016)
  • Java information flow (2016)
  • Let’s face it: Faceted values for taint tracking (2016)
  • A glimpse of Hopjs (2016)
  • Verified compilers for a multi-language world (2015)
  • Ur/Web: A simple model for programming the web (2015)
  • Static analysis of event-driven Node.js JavaScript applications (2015)
  • KJS: A complete formal semantics of JavaScript (2015)
  • Concrete types for TypeScript (2015)
  • Trust, but verify: Two-phase typing for dynamic languages (2015)
  • Determinacy in static analysis for jQuery (2014)
  • A trusted mechanised JavaScript specification (2014)
  • JSAI: A static analysis platform for JavaScript (2014)
  • Practical fine-grained information flow control using Laminar (2014)
  • Asynchronous functional reactive programming for GUIs (2013)
  • Fully abstract compilation to JavaScript (2013)
  • Combining form and function: Static types for JQuery programs (2013)
  • TeJaS: Retrofitting type systems for JavaScript (2013)
  • Multiple facets for dynamic information flow control (2012)
  • Dependent types for JavaScript (2012)
  • Nested refinements for dynamic languages (2012)
  • A tested semantics for getters, setters, and eval in JavaScript (2012)
  • Semantics and types for objects with first-class member names (2012)
  • Remote batch invocation for SQL databases (2011)
  • Typing local control and state using flow analysis (2011)
  • Adsafety: Type-based verification of javascript sandboxing (2011)
  • Automated analysis of security-critical JavaScript APIs (2011)
  • Towards a formal foundation of Web security (2010)
  • The essence of JavaScript (2010)
  • An analysis of the dynamic behavior of JavaScript programs (2010)
  • Static typing for Ruby on Rails (2009)
  • Staged information flow for JavaScript (2009)
  • Cross-tier, label-based security enforcement for web applications (2009)
  • Profile-guilding static typing for dynamic scripting languages (2009)
  • GateKeeper: Mostly static enforcement of security and reliability policies for JavaScript code (2009)
  • Using static analysis for Ajax intrusion detection (2009)
  • Recency types for dynamically-typed, object-based languages: Strong updates for JavaScript (2009)
  • Remote batch invocation for compositional object services (2009)
  • Isolating JavaScript with filters, rewriting, and wrappers (2009)
  • An operational semantics for JavaScript (2008)
  • Secure web applications via automatic partitioning (2007)
  • Operational semantics for multi-language programs (2007)
  • Links: Web programming without tiers (2006)
  • LINQ: Reconciling object, relations and XML in the .NET Framework (2006)
  • Hop, a language for programming the Web 2.0 (2006)
  • Towards type inference for JavaScript (2005)
  • Towards a type system for analyzing JavaScript programs (2005)
  • A type safe DOM API (2005)
  • TreadMarks: Shared memory computing on networks of workstations (1996)
  • Implementing remote procedure calls (1984)
guha-2017-fission reference entries/refs/guha-2017-fission/guha-2017-fission.hel