-
1
-
-
33846012075
-
-
A. V. Aho, R. Sethi, and J. D. Ullman. Compilers, Addison-Wesley
-
A. V. Aho, R. Sethi, and J. D. Ullman. Compilers, Principles, Techniques, and Tools. Addison-Wesley, 1986.
-
(1986)
Principles, Techniques, and Tools
-
-
-
2
-
-
84976844361
-
Control Flow Analysis
-
F. E. Allen. Control Flow Analysis. SIGPLAN Notices, 5, 1970.
-
(1970)
SIGPLAN Notices
, vol.5
-
-
Allen, F.E.1
-
3
-
-
50249115131
-
Saner: Composing Static and Dynamic Analysis to Validate Sanitization in Web Applications
-
Oakland, CA, May
-
D. Balzarotti, M. Cova, V. Felmetsger, N. Jovanovic, E. Kirda, C. Kruegel, and G. Vigna. Saner: Composing Static and Dynamic Analysis to Validate Sanitization in Web Applications. In Proceedings of the IEEE Symposium on Security and Privacy, Oakland, CA, May 2008.
-
(2008)
Proceedings of the IEEE Symposium on Security and Privacy
-
-
Balzarotti, D.1
Cova, M.2
Felmetsger, V.3
Jovanovic, N.4
Kirda, E.5
Kruegel, C.6
Vigna, G.7
-
5
-
-
51849162672
-
Vulnerability Analysis of Web Applications
-
L. Baresi and E. Di Nitto, editors, Springer
-
M. Cova, V. Felmetsger, and G. Vigna. Vulnerability Analysis of Web Applications. In L. Baresi and E. Di Nitto, editors, Testing and Analysis of Web Services. Springer, 2007.
-
(2007)
Testing and Analysis of Web Services
-
-
Cova, M.1
Felmetsger, V.2
Vigna, G.3
-
6
-
-
1542595877
-
Static and Dynamic Analysis: Synergy and Duality
-
Portland, OR, May 9
-
M. D. Ernst. Static and Dynamic Analysis: Synergy and Duality. In WODA 2003: ICSE Workshop on Dynamic Analysis, Portland, OR, May 9, 2003.
-
(2003)
WODA 2003: ICSE Workshop on Dynamic Analysis
-
-
Ernst, M.D.1
-
7
-
-
57449112285
-
A dynamic technique for enhancing the security and privacy of web applications
-
A. Futoransky, E. Gutesman, and A. Waissbein. A dynamic technique for enhancing the security and privacy of web applications. In Black Hat USA, 2007.
-
(2007)
Black Hat USA
-
-
Futoransky, A.1
Gutesman, E.2
Waissbein, A.3
-
8
-
-
40449116802
-
A Classification of SQL-Injection Attacks and Countermeasures
-
Arlington, VA, USA, March
-
W. G. Halfond, J. Viegas, and A. Orso. A Classification of SQL-Injection Attacks and Countermeasures. In Proceedings of the IEEE International Symposium on Secure Software Engineering, Arlington, VA, USA, March 2006.
-
(2006)
Proceedings of the IEEE International Symposium on Secure Software Engineering
-
-
Halfond, W.G.1
Viegas, J.2
Orso, A.3
-
9
-
-
84956630483
-
Interprocedural Slicing Using Dependence Graphs
-
New York, NY, USA, ACM Press
-
S. Horwitz, T. Reps, and D. Binkley. Interprocedural Slicing Using Dependence Graphs. In PLDI '88: Proceedings of the ACM SIGPLAN 1988 conference on Programming Language design and Implementation, New York, NY, USA, 1988. ACM Press.
-
(1988)
PLDI '88: Proceedings of the ACM SIGPLAN 1988 conference on Programming Language design and Implementation
-
-
Horwitz, S.1
Reps, T.2
Binkley, D.3
-
10
-
-
19944365247
-
Securing web application code by static analysis and runtime protection
-
ACM
-
Y.-W. Huang, F. Yu, C. Hang, C.-H. Tsai, D.-T. Lee, and S.-Y. Kuo. Securing web application code by static analysis and runtime protection. In Proceedings of the 13th international conference on World Wide Web. ACM, 2004.
-
(2004)
Proceedings of the 13th international conference on World Wide Web
-
-
Huang, Y.-W.1
Yu, F.2
Hang, C.3
Tsai, C.-H.4
Lee, D.-T.5
Kuo, S.-Y.6
-
11
-
-
33745934031
-
Precise alias analysis for static detection of web application vulnerabilities
-
New York, NY, USA, ACM
-
N. Jovanovic, C. Kruegel, and E. Kirda. Precise alias analysis for static detection of web application vulnerabilities. In Proceedings of the 2006 workshop on Programming languages and analysis for security, New York, NY, USA, 2006. ACM.
-
(2006)
Proceedings of the 2006 workshop on Programming languages and analysis for security
-
-
Jovanovic, N.1
Kruegel, C.2
Kirda, E.3
-
12
-
-
33751027156
-
Pixy: A static analysis tool for detecting web application vulnerabilities (short paper)
-
IEEE Computer Society
-
N. Jovanovic, C. Krügel, and E. Kirda. Pixy: A static analysis tool for detecting web application vulnerabilities (short paper). In IEEE Symposium on Security and Privacy. IEEE Computer Society, 2006.
-
(2006)
IEEE Symposium on Security and Privacy
-
-
Jovanovic, N.1
Krügel, C.2
Kirda, E.3
-
13
-
-
84871349041
-
-
A. Nguyen-tuong, S. Guarnieri, D. Greene, J. Shirley, and D. Evans. Automatically hardening web applications using precise tainting. In In 20th IFIP International Information Security Conference, 2005.
-
A. Nguyen-tuong, S. Guarnieri, D. Greene, J. Shirley, and D. Evans. Automatically hardening web applications using precise tainting. In In 20th IFIP International Information Security Conference, 2005.
-
-
-
-
20
-
-
84910681237
-
Static detection of security vulnerabilities in scripting languages
-
Berkeley, CA, USA, USENIX Association
-
Y. Xie and A. Aiken. Static detection of security vulnerabilities in scripting languages. In Proceedings of the 15th conference on USENIX Security Symposium, Berkeley, CA, USA, 2006. USENIX Association.
-
(2006)
Proceedings of the 15th conference on USENIX Security Symposium
-
-
Xie, Y.1
Aiken, A.2
|