메뉴 건너뛰기




Volumn , Issue , 2008, Pages 89-98

SOMA: Mutual approval for included content in web pages

Author keywords

Cross site request forgery (XSRF); Cross site scripting (XSS); JavaScript; Same origin policy; Web security

Indexed keywords

CROSS-SITE REQUEST FORGERY (XSRF); CROSS-SITE SCRIPTING (XSS); JAVASCRIPT; SAME ORIGIN POLICY; WEB SECURITY;

EID: 70349292390     PISSN: 15437221     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1145/1455770.1455783     Document Type: Conference Paper
Times cited : (46)

References (41)
  • 1
    • 70349271936 scopus 로고    scopus 로고
    • External data not accessible outside a Macromedia Flash movie's domain. Technical Report tn-14213, Adobe Systems Incorporated
    • Adobe Systems Incorporated, Feb
    • Adobe Systems Incorporated. External data not accessible outside a Macromedia Flash movie's domain. Technical Report tn-14213, Adobe Systems Incorporated, Feb 2006.
    • (2006)
  • 2
    • 70349273485 scopus 로고    scopus 로고
    • Alexa top 500 sites. Web page (viewed 14 Apr 2008). http://www.alexa.com/ site/ds/top-sites? ts-mode=global&lang=none.
    • Alexa top 500 sites. Web page (viewed 14 Apr 2008). http://www.alexa.com/ site/ds/top-sites? ts-mode=global&lang=none.
  • 4
    • 70349268850 scopus 로고    scopus 로고
    • Web page, Apr
    • R. Berends. Bandwidth stealing. Web page, Apr 2001. http://www.website- awards.net/articles/ article39.htm.
    • (2001) Bandwidth stealing
    • Berends, R.1
  • 5
    • 70349267293 scopus 로고    scopus 로고
    • CERT advisory CA-2000-02 malicious HTML tags embedded in client web requests. Web page, Feb 2000. http://www.cert.org/advisories/ CA-2000-02.html.
    • CERT advisory CA-2000-02 malicious HTML tags embedded in client web requests. Web page, Feb 2000. http://www.cert.org/advisories/ CA-2000-02.html.
  • 6
    • 70349273484 scopus 로고    scopus 로고
    • The cross site scripting (XSS) FAQ. Web page, Aug 2003. http : //www. cgi security . com/art ides/ xss-faq.shtml.
    • The cross site scripting (XSS) FAQ. Web page, Aug 2003. http : //www. cgi security . com/art ides/ xss-faq.shtml.
  • 9
    • 70349296555 scopus 로고    scopus 로고
    • Web page, May
    • S. DeDeo. Pagestats extension. Web page, May 2006. http://www.cs.wpi.edu/ ̃cew/pagestats/.
    • (2006) Pagestats extension
    • DeDeo, S.1
  • 10
    • 0016949746 scopus 로고
    • A lattice model of secure information flow
    • D. E. Denning. A lattice model of secure information flow. Communications of the ACM, 19(2):236-243, 1976.
    • (1976) Communications of the ACM , vol.19 , Issue.2 , pp. 236-243
    • Denning, D.E.1
  • 13
    • 34547256115 scopus 로고    scopus 로고
    • Hacking intranet websites from the outside - JavaScript malware just got a lot more dangerous
    • Aug
    • J. Grossman and T. Niedzialkowski. Hacking intranet websites from the outside - JavaScript malware just got a lot more dangerous. In Blackhat USA, Aug 2006.
    • (2006) Blackhat USA
    • Grossman, J.1    Niedzialkowski, T.2
  • 20
    • 70349299621 scopus 로고    scopus 로고
    • J. Kyrnin. Are you invading your customers' privacy? Web page (viewed 14 Apr 2008). http ://webdesign . about.com/od/privacy/a/aal12601a.htm.
    • J. Kyrnin. Are you invading your customers' privacy? Web page (viewed 14 Apr 2008). http ://webdesign . about.com/od/privacy/a/aal12601a.htm.
  • 21
    • 34547381072 scopus 로고    scopus 로고
    • Puppetnets: Misusing web browsers as a distributed attack infrastructure
    • V. T. Lam, S. Antonatos, P. Akritidis, and K. G. Anagnostakis. Puppetnets: misusing web browsers as a distributed attack infrastructure. In Proc. 13th ACM CCS, pages 221-234, 2006.
    • (2006) Proc. 13th ACM CCS , pp. 221-234
    • Lam, V.T.1    Antonatos, S.2    Akritidis, P.3    Anagnostakis, K.G.4
  • 22
    • 70349271937 scopus 로고    scopus 로고
    • G. Maone. NoScript - JavaScript/Java/Flash blocker for a safer Firefox experience! Web page (viewed 14 Apr 2008). http://noscript.net/.
    • G. Maone. NoScript - JavaScript/Java/Flash blocker for a safer Firefox experience! Web page (viewed 14 Apr 2008). http://noscript.net/.
  • 23
    • 70349281195 scopus 로고    scopus 로고
    • Microsoft. Mitigating cross-site scripting with HTTP-only cookies. Web page (viewed 18 Jul 2008). http://msdn.microsoft.com/en-us/library/ ms533046.aspx.
    • Microsoft. Mitigating cross-site scripting with HTTP-only cookies. Web page (viewed 18 Jul 2008). http://msdn.microsoft.com/en-us/library/ ms533046.aspx.
  • 24
    • 70349271934 scopus 로고    scopus 로고
    • field used in the battle against online fraud. Web page, Jan
    • A. D. Miglio. "Referer" field used in the battle against online fraud. Web page, Jan 2008. http://www.Symantec.com/enterprise/ security-response/weblog/2008/01/ referer-field-used-in-the-batt.html.
    • (2008) Referer
    • Miglio, A.D.1
  • 25
    • 78650227796 scopus 로고    scopus 로고
    • SOMA: Mutual approval for included content in web
    • Technical Report TR-08-07, School of Computer Science, Carleton University, Apr
    • T. Oda, G. Wurster, P. van Oorsehot, and A. Somayaji. SOMA: Mutual approval for included content in web pages. Technical Report TR-08-07, School of Computer Science, Carleton University, Apr 2008.
    • (2008)
    • Oda, T.1    Wurster, G.2    van Oorsehot, P.3    Somayaji, A.4
  • 28
    • 70349288881 scopus 로고    scopus 로고
    • Microsoft apologizes for serving malware
    • Feb
    • J. Reimer. Microsoft apologizes for serving malware. Ars Technica, Feb 2007.
    • (2007) Ars Technica
    • Reimer, J.1
  • 31
    • 41149151731 scopus 로고    scopus 로고
    • Web page, Aug
    • J. Ruderman. The same origin policy. Web page, Aug 2001. http://www.mozilia.org/projects/ security/components/same-origin.html.
    • (2001) The same origin policy
    • Ruderman, J.1
  • 32
    • 70349273482 scopus 로고    scopus 로고
    • Rogue anti-virus slimeballs hide malware in ads
    • Nov
    • B. Schiffman. Rogue anti-virus slimeballs hide malware in ads. Wired, Nov 2007.
    • (2007) Wired
    • Schiffman, B.1
  • 34
    • 70349285761 scopus 로고    scopus 로고
    • Smarter image hotlinking prevention
    • Apr
    • T. Scott. Smarter image hotlinking prevention. A List Apart, Apr 2004.
    • (2004) A List Apart
    • Scott, T.1
  • 36
    • 70349271935 scopus 로고    scopus 로고
    • B. Sterne. Site security policy draft version 0.2, Web Page, Jul 2008
    • B. Sterne. Site security policy draft (version 0.2). Web Page, Jul 2008. http://people.mozilla.org/̃bsterne/ site-security-policy/details.html.
  • 37
    • 0031187547 scopus 로고    scopus 로고
    • How people revisit web pages: Empirical findings and implications for the design of history systems
    • L. Tauscher and S. Greenberg. How people revisit web pages: empirical findings and implications for the design of history systems. In International Journal of Human Computer Studies, 1997.
    • (1997) International Journal of Human Computer Studies
    • Tauscher, L.1    Greenberg, S.2
  • 40
    • 41149109640 scopus 로고    scopus 로고
    • Protection and communication abstractions for web browsers in MashupOS
    • Oct
    • H. J. Wang, X. Fan, C. Jackson, and J. Howell. Protection and communication abstractions for web browsers in MashupOS. In 21st ACM SOSP, Oct 2007.
    • (2007) 21st ACM SOSP
    • Wang, H.J.1    Fan, X.2    Jackson, C.3    Howell, J.4
  • 41
    • 70349265740 scopus 로고    scopus 로고
    • WordPress.org. Enable sending referrers. Web page (viewed 14 Apr 2008). http : //codex .wordpress.org/Enable-Sending-Referrers.
    • WordPress.org. Enable sending referrers. Web page (viewed 14 Apr 2008). http : //codex .wordpress.org/Enable-Sending-Referrers.


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.