| Nome: | Descrição: | Tamanho: | Formato: | |
|---|---|---|---|---|
| 4.52 MB | Adobe PDF |
Autores
Orientador(es)
Resumo(s)
O desenvolvimento de software moderno possui uma forte dependência de bibliotecas de
terceiros, estimando-se que uma grande parte do código em aplicações atuais provém de
fontes externas, com destaque para o ecossistema JavaScript/npm . Esta dependência,
embora bené ca para a produtividade, introduz riscos de segurança, nomeadamente através
de ataques à cadeia de abastecimento. O problema central reside no modelo de execu-
ção permissivo dos ambientes JavaScript, onde o código de terceiros herda implicitamente
os privilégios da aplicação hospedeira, operando sem o isolamento necessário para conter
dependências comprometidas.
Neste contexto, esta dissertação concebeu e concretizou um protótipo de isolamento granular
para bibliotecas JavaScript executadas no browser. A solução integra-se no processo
de construção através de um plugin Webpack, gera proxies para preservar a forma habitual
de importação e executa cada biblioteca selecionada num contexto QuickJS alojado
em WebAssembly. O runtime aplica uma política de negação por omissão, expondo apenas
capacidades explicitamente autorizadas e mediando a comunicação entre a aplicação e a
biblioteca isolada através de membranas e marshallers extensíveis.
A avaliação analisou compatibilidade, desempenho e segurança. Foram reutilizadas suites de
teste de dez bibliotecas, das quais sete preservaram mais de 80% da respetiva execução de
referência nativa. No browser, dez cargas de trabalho executadas em Chromium mostraram
que o isolamento introduz custos relevantes, dependentes do volume e da frequência das
travessias entre contextos. Em cenários com maior comunicação, os adaptadores de carga
de trabalho reduziram o sobrecusto de execução da biblioteca Lodash de 1350;59 para
78;41 e da Zod de 623;19 para 16;21 . Em três cenários de segurança, envolvendo
poluição de protótipos, interceção de Application Programming Interfaces (APIs) sensíveis e
acesso a uma capacidade não autorizada, a sandbox preservou o comportamento legítimo e
mitigou os efeitos observados na execução nativa. Os resultados demonstram a viabilidade
técnica da abordagem, embora evidenciem que a sua aplicação prática depende do per l da
biblioteca, das permissões concedidas e do padrão de comunicação com a aplicação.
Modern software development relies heavily on third-party libraries, with an estimated large portion of the code in current applications coming from external sources, particularly the JavaScript/npm ecosystem. This dependency, while bene cial to productivity, introduces security risks, notably through supply chain attacks. The central problem lies in the permissive execution model of JavaScript environments, where third-party code implicitly inherits the privileges of the host application, operating without the necessary isolation to contain compromised dependencies. In this context, this dissertation designed and implemented a prototype for granular isolation of JavaScript libraries executed in the browser. The solution integrates with the build process through a Webpack plugin, generates proxies to preserve the usual import style, and executes each selected library in a QuickJS context hosted in WebAssembly. At runtime, it applies a default-deny policy, exposes only explicitly authorised capabilities, and mediates communication between the host application and the isolated library through membranes and extensible marshallers. The evaluation analysed compatibility, performance, and security. Test suites from ten libraries were reused, with seven preserving more than 80% of their native baseline. In the browser, ten workloads executed in Chromium showed that isolation introduces relevant costs, depending on the volume and frequency of crossings between contexts. In communication-heavy scenarios, workload adapters reduced the overhead of Lodash from 1350:59 to 78:41 and of Zod from 623:19 to 16:21 . In three security scenarios, covering prototype pollution, interception of sensitive APIs, and access to an unauthorised capability, the sandbox preserved legitimate behaviour and mitigated the e ects observed in native execution. The results demonstrate the technical feasibility of the approach, while showing that its practical use depends on the library pro le, the granted permissions, and the communication pattern with the application.
Modern software development relies heavily on third-party libraries, with an estimated large portion of the code in current applications coming from external sources, particularly the JavaScript/npm ecosystem. This dependency, while bene cial to productivity, introduces security risks, notably through supply chain attacks. The central problem lies in the permissive execution model of JavaScript environments, where third-party code implicitly inherits the privileges of the host application, operating without the necessary isolation to contain compromised dependencies. In this context, this dissertation designed and implemented a prototype for granular isolation of JavaScript libraries executed in the browser. The solution integrates with the build process through a Webpack plugin, generates proxies to preserve the usual import style, and executes each selected library in a QuickJS context hosted in WebAssembly. At runtime, it applies a default-deny policy, exposes only explicitly authorised capabilities, and mediates communication between the host application and the isolated library through membranes and extensible marshallers. The evaluation analysed compatibility, performance, and security. Test suites from ten libraries were reused, with seven preserving more than 80% of their native baseline. In the browser, ten workloads executed in Chromium showed that isolation introduces relevant costs, depending on the volume and frequency of crossings between contexts. In communication-heavy scenarios, workload adapters reduced the overhead of Lodash from 1350:59 to 78:41 and of Zod from 623:19 to 16:21 . In three security scenarios, covering prototype pollution, interception of sensitive APIs, and access to an unauthorised capability, the sandbox preserved legitimate behaviour and mitigated the e ects observed in native execution. The results demonstrate the technical feasibility of the approach, while showing that its practical use depends on the library pro le, the granted permissions, and the communication pattern with the application.
Descrição
Palavras-chave
WebAssembly JavaScript Software Supply Chain Security Granular Isolation npm Sandboxing
