exercise greater care in selecting Web server implementations and demand better security from external embedded
Web server developers and their own engineering staff.
Second, complex embedded application logic and state
need to be more visible, which would enable vulnerability
scans either from the same host (in the case of LOM) or over
the network (for appliances not running a general-purpose
OS). Third, the Web community needs to recognize that
embedded Web sites can have fundamentally different use
models from those usually seen on the Internet: we have to
enable these two paradigms to coexist securely.
7. concLuSion
Networked appliances are not as secure and harmless as
they are often assumed to be. The advent of browser-centric
Web 2.0 computing has amplified the scope of attacks possible via embedded devices, giving rise to XCS. There is much
work to be done before hardware vendors start to routinely
design and test for security, Web browsers are capable of
dealing securely with different classes of Web applications,
and users are enabled to make and execute decisions about
managing their networked private data. We hope that we
have at least made the first step toward that goal.
1. balzarotti, d., Cova, M., Felmetsger,
V., Jovanovic, n., Kirda, e., Kruegel,
C., Vigna, G. saner: Composing static
and dynamic analysis to validate
sanitization in Web applications. In
IEEE Symposium on Security and
Privacy (2008).
hristo Bojinov ( hristo@cs.stanford.edu),
stanford university, stanford, Ca.
Elie Bursztein ( elie@cs.stanford.edu),
stanford university, stanford, Ca.
Dan Boneh ( dabo@cs.stanford.edu),
stanford university, stanford, Ca.
this work is supported by the nsF, dHs, and the Packard Foundation.
© 2010 aCM 0001-0782/10/0800 $10.00
Announcing ACM’s Newly Improved
Career & Job Center!
Are you looking for your next IT job? Do you need Career Advice?
Visit ACM’s newly enhanced career resource at:
http://www.acm.org/careercenter
◆ ◆ ◆ ◆ ◆
The ACM Career & Job Center offers ACM members a host of benefits including:
➜ A highly targeted focus on job opportunities in the computing industry
➜ Access to hundreds of corporate job postings
➜ Resume posting keeping you connected to the employment market while letting you maintain full
control over your confidential information
➜ An advanced Job Alert system that notifies you of new opportunities matching your criteria
➜ Career coaching and guidance from trained experts dedicated to your success
➜ A content library of the best career articles complied from hundreds of sources, and much more!
The ACM Career & Job Center is the perfect place to
begin searching for your next employment opportunity!
Visit today at http://www.acm.org/careercenter