{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T21:15:18Z","timestamp":1760044518428,"version":"3.41.0"},"reference-count":48,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2013,12,1]],"date-time":"2013-12-01T00:00:00Z","timestamp":1385856000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Archit. Code Optim."],"published-print":{"date-parts":[[2013,12]]},"abstract":"<jats:p>Web applications are vulnerable to cross-site scripting attacks that enable data thefts. Information flow tracking in web browsers can prevent communication of sensitive data to unintended recipients and thereby stop such data thefts. Unfortunately, existing solutions have focused on incorporating information flow into browsers\u2019 JavaScript interpreters, rather than just-in-time compilers, rendering the resulting performance noncompetitive. Few users will switch to a safer browser if it comes at the cost of significantly degrading web application performance.<\/jats:p>\n          <jats:p>We present the first information flow tracking JavaScript engine that is based on a true just-in-time compiler, and that thereby outperforms all previous interpreter-based information flow tracking JavaScript engines by more than a factor of two. Our JIT-based engine (i) has the same coverage as previous interpreter- based solutions, (ii) requires reasonable implementation effort, and (iii) introduces new optimizations to achieve acceptable performance. When evaluated against three industry-standard JavaScript benchmark suites, there is still an average slowdown of 73% over engines that do not support information flow, but this is now well within the range that many users will find an acceptable price for obtaining substantially increased security.<\/jats:p>","DOI":"10.1145\/2541228.2555295","type":"journal-article","created":{"date-parts":[[2014,1,14]],"date-time":"2014-01-14T13:39:57Z","timestamp":1389706797000},"page":"1-25","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["Information flow tracking meets just-in-time compilation"],"prefix":"10.1145","volume":"10","author":[{"given":"Christoph","family":"Kerschbaumer","sequence":"first","affiliation":[{"name":"University of California, Irvine, California, United States"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Eric","family":"Hennigan","sequence":"additional","affiliation":[{"name":"University of California, Irvine, California, United States"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Per","family":"Larsen","sequence":"additional","affiliation":[{"name":"University of California, Irvine, California, United States"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stefan","family":"Brunthaler","sequence":"additional","affiliation":[{"name":"University of California, Irvine, California, United States"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michael","family":"Franz","sequence":"additional","affiliation":[{"name":"University of California, Irvine, California, United States"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2013,12]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"Retrieved","author":"Alexa","year":"2013","unstructured":"Alexa . 2013 . Alexa Global Top Sites . Retrieved November 20, 2013 from http:\/\/www.alexa.com\/topsites. Alexa. 2013. Alexa Global Top Sites. Retrieved November 20, 2013 from http:\/\/www.alexa.com\/topsites."},{"doi-asserted-by":"publisher","key":"e_1_2_1_2_1","DOI":"10.1145\/1554339.1554353"},{"doi-asserted-by":"publisher","key":"e_1_2_1_3_1","DOI":"10.1145\/1814217.1814220"},{"doi-asserted-by":"publisher","key":"e_1_2_1_4_1","DOI":"10.1145\/2103656.2103677"},{"doi-asserted-by":"publisher","key":"e_1_2_1_5_1","DOI":"10.1145\/857076.857077"},{"doi-asserted-by":"publisher","key":"e_1_2_1_6_1","DOI":"10.1109\/ACSAC.2008.50"},{"volume-title":"Proceedings of the 23rd Annual Computer Security Applications Conference (ACSAC\u201907)","author":"Chandra D.","unstructured":"Chandra , D. and Franz , M . 2007. Fine-grained information flow analysis and enforcement in a Java virtual machine . In Proceedings of the 23rd Annual Computer Security Applications Conference (ACSAC\u201907) . IEEE, 463--475. Chandra, D. and Franz, M. 2007. Fine-grained information flow analysis and enforcement in a Java virtual machine. In Proceedings of the 23rd Annual Computer Security Applications Conference (ACSAC\u201907). IEEE, 463--475.","key":"e_1_2_1_7_1"},{"doi-asserted-by":"publisher","key":"e_1_2_1_8_1","DOI":"10.1145\/1542476.1542483"},{"key":"e_1_2_1_9_1","volume-title":"Retrieved","author":"Crockford D.","year":"2009","unstructured":"Crockford , D. 2009 . ADsafe . Retrieved November 20, 2013 from http:\/\/www.adsafe.org. Crockford, D. 2009. ADsafe. Retrieved November 20, 2013 from http:\/\/www.adsafe.org."},{"doi-asserted-by":"publisher","key":"e_1_2_1_10_1","DOI":"10.1145\/359636.359712"},{"doi-asserted-by":"publisher","key":"e_1_2_1_11_1","DOI":"10.1145\/800017.800542"},{"doi-asserted-by":"publisher","key":"e_1_2_1_12_1","DOI":"10.1109\/SP.2010.15"},{"doi-asserted-by":"publisher","key":"e_1_2_1_13_1","DOI":"10.1109\/ACSAC.2009.43"},{"unstructured":"ECMA International. 2009. Standard ECMA-262. The ECMAScript language specification. http:\/\/www.ecma-international.org\/publications\/standards\/Ecma-262.htm.  ECMA International. 2009. Standard ECMA-262. The ECMAScript language specification. http:\/\/www.ecma-international.org\/publications\/standards\/Ecma-262.htm.","key":"e_1_2_1_14_1"},{"volume-title":"Proceedings of the 9th USENIX Symposium on Operating Systems Design and Implementation (OSDI\u201910)","author":"Enck W.","unstructured":"Enck , W. , Gilbert , P. , Chun , B.-G. , Cox , L. P. , Jung , J. , McDaniel , P. , and Sheth , A. N . 2010. TaintDroid: An information-flow tracking system for realtime privacy monitoring on smartphones . In Proceedings of the 9th USENIX Symposium on Operating Systems Design and Implementation (OSDI\u201910) . USENIX Association, 393--407. Enck, W., Gilbert, P., Chun, B.-G., Cox, L. P., Jung, J., McDaniel, P., and Sheth, A. N. 2010. TaintDroid: An information-flow tracking system for realtime privacy monitoring on smartphones. In Proceedings of the 9th USENIX Symposium on Operating Systems Design and Implementation (OSDI\u201910). USENIX Association, 393--407.","key":"e_1_2_1_15_1"},{"key":"e_1_2_1_16_1","volume-title":"Retrieved","author":"Facebook","year":"2011","unstructured":"Facebook . 2011 . FBJS (Facebook JavaScript) . Retrieved November 20, 2013 from http:\/\/developers.facebook.com\/docs\/fbjs\/. Facebook. 2011. FBJS (Facebook JavaScript). Retrieved November 20, 2013 from http:\/\/developers.facebook.com\/docs\/fbjs\/."},{"doi-asserted-by":"publisher","key":"e_1_2_1_17_1","DOI":"10.1145\/1542476.1542528"},{"key":"e_1_2_1_18_1","volume-title":"Retrieved","author":"Google","year":"2012","unstructured":"Google . 2012 . V8 Benchmark Suite . Retrieved November 20, 2013 from https:\/\/developers.google.com\/v8\/benchmarks. Google. 2012. V8 Benchmark Suite. Retrieved November 20, 2013 from https:\/\/developers.google.com\/v8\/benchmarks."},{"doi-asserted-by":"publisher","key":"e_1_2_1_19_1","DOI":"10.1109\/SP.2008.19"},{"doi-asserted-by":"publisher","key":"e_1_2_1_20_1","DOI":"10.1145\/2382196.2382275"},{"volume-title":"Proceedings of the 24th European Conference on Object-Oriented Programming (ECOOP\u201910)","author":"Guha A.","unstructured":"Guha , A. , Saftoiu , C. , and Krishnamurthi , S . 2010. The essence of JavaScript . In Proceedings of the 24th European Conference on Object-Oriented Programming (ECOOP\u201910) . ACM, 126--150. Guha, A., Saftoiu, C., and Krishnamurthi, S. 2010. The essence of JavaScript. In Proceedings of the 24th European Conference on Object-Oriented Programming (ECOOP\u201910). ACM, 126--150.","key":"e_1_2_1_21_1"},{"doi-asserted-by":"publisher","key":"e_1_2_1_22_1","DOI":"10.1145\/2254064.2254094"},{"doi-asserted-by":"publisher","key":"e_1_2_1_23_1","DOI":"10.1109\/CSF.2012.19"},{"volume-title":"Proceedings of the 6th International Conference on Trust and Trustworthy Computing (TRUST\u201913)","author":"Hennigan E.","unstructured":"Hennigan , E. , Kerschbaumer , C. , Larsen , P. , Brunthaler , S. , and Franz , M . 2013. First-class labels: Using information flow to debug security holes . In Proceedings of the 6th International Conference on Trust and Trustworthy Computing (TRUST\u201913) . Springer. Hennigan, E., Kerschbaumer, C., Larsen, P., Brunthaler, S., and Franz, M. 2013. First-class labels: Using information flow to debug security holes. In Proceedings of the 6th International Conference on Trust and Trustworthy Computing (TRUST\u201913). Springer.","key":"e_1_2_1_24_1"},{"volume-title":"IEEE standard for floating-point arithmetic","year":"2008","unstructured":"IEEE. 2008. IEEE standard for floating-point arithmetic . IEEE Std 754-- 2008 , 1--58. IEEE. 2008. IEEE standard for floating-point arithmetic. IEEE Std 754--2008, 1--58.","key":"e_1_2_1_25_1"},{"doi-asserted-by":"publisher","key":"e_1_2_1_26_1","DOI":"10.1145\/1866307.1866339"},{"doi-asserted-by":"publisher","key":"e_1_2_1_27_1","DOI":"10.1145\/2093328.2093331"},{"volume-title":"Proceedings of the 6th International Conference on Trust and Trustworthy Computing (TRUST\u201913)","author":"Kerschbaumer C.","unstructured":"Kerschbaumer , C. , Hennigan , E. , Larsen , P. , Brunthaler , S. , and Franz , M . 2013. Towards precise and efficient information flow control in web browsers . In Proceedings of the 6th International Conference on Trust and Trustworthy Computing (TRUST\u201913) . Springer. Kerschbaumer, C., Hennigan, E., Larsen, P., Brunthaler, S., and Franz, M. 2013. Towards precise and efficient information flow control in web browsers. In Proceedings of the 6th International Conference on Trust and Trustworthy Computing (TRUST\u201913). Springer.","key":"e_1_2_1_28_1"},{"doi-asserted-by":"publisher","key":"e_1_2_1_29_1","DOI":"10.1109\/ACSAC.2006.6"},{"key":"e_1_2_1_30_1","volume-title":"Retrieved","author":"Microsoft","year":"2012","unstructured":"Microsoft . 2012 . Microsoft Security Intelligence Report, Volume 13: January - June 2012 . Retrieved November 20, 2013 http:\/\/www.microsoft.com\/security\/sir\/default.aspx. Microsoft. 2012. Microsoft Security Intelligence Report, Volume 13: January - June 2012. Retrieved November 20, 2013 http:\/\/www.microsoft.com\/security\/sir\/default.aspx."},{"key":"e_1_2_1_31_1","volume-title":"Retrieved","author":"Miller M. S.","year":"2013","unstructured":"Miller , M. S. , Samuel , M. , Laurie , B. , Awad , I. , and Stay , M . 2008. Caja: Safe active content in sanitized JavaScript . Retrieved November 20, 2013 http:\/\/google-caja.googlecode.com\/files\/caja-spec-2008-01-15.pdf. Miller, M. S., Samuel, M., Laurie, B., Awad, I., and Stay, M. 2008. Caja: Safe active content in sanitized JavaScript. Retrieved November 20, 2013 http:\/\/google-caja.googlecode.com\/files\/caja-spec-2008-01-15.pdf."},{"unstructured":"MITRE Corporation. 2012. Common weakness enumeration: A community-developed dictionary of software weakness types. http:\/\/cwe.mitre.org\/top25\/.  MITRE Corporation. 2012. Common weakness enumeration: A community-developed dictionary of software weakness types. http:\/\/cwe.mitre.org\/top25\/.","key":"e_1_2_1_32_1"},{"key":"e_1_2_1_33_1","volume-title":"Retrieved","author":"Mozilla","year":"2011","unstructured":"Mozilla . 2011 . Kraken JavaScript benchmark . Retrieved November 20, 2013 from http:\/\/krakenbenchmark.mozilla.org\/. (checked: February, 2013). Mozilla. 2011. Kraken JavaScript benchmark. Retrieved November 20, 2013 from http:\/\/krakenbenchmark.mozilla.org\/. (checked: February, 2013)."},{"key":"e_1_2_1_34_1","volume-title":"Retrieved","author":"Mozilla Foundation","year":"2008","unstructured":"Mozilla Foundation . 2008 . Same origin policy for JavaScript . Retrieved November 20, 2013 from https:\/\/developer.mozilla.org\/En\/Same_origin_policy_for_JavaScript. Mozilla Foundation. 2008. Same origin policy for JavaScript. Retrieved November 20, 2013 from https:\/\/developer.mozilla.org\/En\/Same_origin_policy_for_JavaScript."},{"doi-asserted-by":"publisher","key":"e_1_2_1_35_1","DOI":"10.1145\/292540.292561"},{"doi-asserted-by":"publisher","key":"e_1_2_1_36_1","DOI":"10.1145\/363516.363526"},{"key":"e_1_2_1_37_1","volume-title":"Retrieved","author":"Myers A. C.","year":"2013","unstructured":"Myers , A. C. , Zheng , L. , Zdancewic , S. , Chong , S. , and Nystrom , N . 2001. Jif: Java information flow . Retrieved November 20, 2013 from http:\/\/www.cs.cornell.edu\/jif. Myers, A. C., Zheng, L., Zdancewic, S., Chong, S., and Nystrom, N. 2001. Jif: Java information flow. Retrieved November 20, 2013 from http:\/\/www.cs.cornell.edu\/jif."},{"volume-title":"Proceedings of the 16th Annual Network and Distributed System Security Symposium (NDSS\u201909)","author":"Nadji Y.","unstructured":"Nadji , Y. , Saxena , P. , and Song , D . 2009. Document structure integrity: A robust basis for cross-site scripting defense . In Proceedings of the 16th Annual Network and Distributed System Security Symposium (NDSS\u201909) . The Internet Society. Nadji, Y., Saxena, P., and Song, D. 2009. Document structure integrity: A robust basis for cross-site scripting defense. In Proceedings of the 16th Annual Network and Distributed System Security Symposium (NDSS\u201909). The Internet Society.","key":"e_1_2_1_38_1"},{"doi-asserted-by":"publisher","key":"e_1_2_1_39_1","DOI":"10.1145\/1377943.1377956"},{"key":"e_1_2_1_40_1","volume-title":"Retrieved","author":"Nava E. V.","year":"2013","unstructured":"Nava , E. V. and Lindsay , D . 2009. Our favorite XSS filters and how to attack them . Retrieved November 20, 2013 http:\/\/www.blackhat.com\/presentations\/bh-usa-09\/VELANAVA\/BHUSA09-VelaNava-FavoriteXSS-SLIDES.pdf. Nava, E. V. and Lindsay, D. 2009. Our favorite XSS filters and how to attack them. Retrieved November 20, 2013 http:\/\/www.blackhat.com\/presentations\/bh-usa-09\/VELANAVA\/BHUSA09-VelaNava-FavoriteXSS-SLIDES.pdf."},{"doi-asserted-by":"publisher","key":"e_1_2_1_41_1","DOI":"10.1145\/2382196.2382274"},{"key":"e_1_2_1_42_1","volume-title":"Retrieved","author":"OWASP.","year":"2012","unstructured":"OWASP. 2012 . The Open Web Application Security Project . Retrieved November 20, 2013 from https:\/\/www.owasp.org\/. OWASP. 2012. The Open Web Application Security Project. Retrieved November 20, 2013 from https:\/\/www.owasp.org\/."},{"key":"e_1_2_1_43_1","volume-title":"Retrieved","author":"OWASP.","year":"2013","unstructured":"OWASP. 2013 . XSS Filter Evasion Cheat Sheet . Retrieved November 20, 2013 from https:\/\/www.owasp.org\/index.php\/XSS_Filter_Evasion_Cheat_Sheet. OWASP. 2013. XSS Filter Evasion Cheat Sheet. Retrieved November 20, 2013 from https:\/\/www.owasp.org\/index.php\/XSS_Filter_Evasion_Cheat_Sheet."},{"doi-asserted-by":"publisher","key":"e_1_2_1_44_1","DOI":"10.1109\/JSAC.2002.806121"},{"key":"e_1_2_1_45_1","volume-title":"Retrieved","author":"SunSpider","year":"2012","unstructured":"SunSpider . 2012 . SunSpider JavaScript benchmark . Retrieved November 20, 2013 from http:\/\/www2.webkit.org\/perf\/sunspider-0.9\/sunspider.html. SunSpider. 2012. SunSpider JavaScript benchmark. Retrieved November 20, 2013 from http:\/\/www2.webkit.org\/perf\/sunspider-0.9\/sunspider.html."},{"doi-asserted-by":"publisher","key":"e_1_2_1_46_1","DOI":"10.1007\/978-3-642-31284-7_25"},{"volume-title":"Proceedings of the 14th Annual Network and Distributed System Security Symposium (NDSS\u201907)","author":"Vogt P.","unstructured":"Vogt , P. , Nentwich , F. , Jovanovic , N. , Kruegel , C. , Kirda , E. , and Vigna , G . 2007. Cross site scripting prevention with dynamic data tainting and static analysis . In Proceedings of the 14th Annual Network and Distributed System Security Symposium (NDSS\u201907) . The Internet Society. Vogt, P., Nentwich, F., Jovanovic, N., Kruegel, C., Kirda, E., and Vigna, G. 2007. Cross site scripting prevention with dynamic data tainting and static analysis. In Proceedings of the 14th Annual Network and Distributed System Security Symposium (NDSS\u201907). The Internet Society.","key":"e_1_2_1_47_1"},{"doi-asserted-by":"publisher","key":"e_1_2_1_48_1","DOI":"10.1145\/1315245.1315261"}],"container-title":["ACM Transactions on Architecture and Code Optimization"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2541228.2555295","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2541228.2555295","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T07:35:01Z","timestamp":1750232101000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2541228.2555295"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013,12]]},"references-count":48,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2013,12]]}},"alternative-id":["10.1145\/2541228.2555295"],"URL":"https:\/\/doi.org\/10.1145\/2541228.2555295","relation":{},"ISSN":["1544-3566","1544-3973"],"issn-type":[{"type":"print","value":"1544-3566"},{"type":"electronic","value":"1544-3973"}],"subject":[],"published":{"date-parts":[[2013,12]]},"assertion":[{"value":"2013-09-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2013-10-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2013-12-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}