A Syracuse University (SU) professor will use a three-year, $472,000 grant from the National Science Foundation (NSF) to study ways to improve the security of Web browsers.
The ultimate goal is for industry to adopt researchers’ findings, says Wenliang Du, the grant recipient and a professor of computer science in SU’s L.C. Smith College of Engineering and Computer Science. Du says he and his fellow researchers have already been in touch with companies like Google and Mozilla about their work.
He adds that some of his students are in the running for jobs at some of the major browser players.
“That could certainly help us,” he says.
Much of the current work done on browser security focuses on fixing problems after they emerge, Du says. Someone finds a hole potential security threats could exploit and programmers then race to close it.
Those approaches don’t address the fundamental, underlying security problem that browsers share, Du explains. The security model they use was designed 10 or 15 years ago, even though the Web has changed dramatically since then.
“That security model was adequate for earlier days,” Du says. “Now, with Web 2.0 and so much dynamic content, this model is not adequate.”
If the basic design of the model is flawed, Du says, it doesn’t matter what you do. The system will eventually run into problems.
He compares it to bridge design: someone could look at a bridge and see the weak points that need to be strengthened. But the flaws could be even more evident if the basic design and blueprint are examined.
Du wants to change that blueprint — the security engine at the heart of a Web browser’s ability to protect itself.
“The ultimate goal is to get Microsoft and Google and Mozilla to adopt this engine,” he says.
Of course, actually getting a new engine adopted as a standard…