Constructing robust and secure web applications
Road description: Visit www.lindholmen.se
The web connects a wide range of computing units from browser-enabled mobile devices to enterprise computers. These units might be protected from communication with the environment by network-based mechanisms such as fi rewalls.
However, allowing the mere possibility of fetching a web page opens up opportunities for delivering potentially malicious executable content past firewalls.
This talk summarizes some highlights from a recent Dagstuhl seminar on web application security. The seminar’s focus is on principles for construction of robust and secure web applications. We present a selection of proposals by the others and outline some of our own, related to tracking information fl ow in web applications. We discuss static and dynamic information security enforcement techniques and synergies between them.