-
1
-
-
51449085610
-
Vulnerability Type Distributions in CVE
-
May
-
Christey, S., Martin, R., "Vulnerability Type Distributions in CVE", Mitre report, May, 2007
-
(2007)
Mitre report
-
-
Christey, S.1
Martin, R.2
-
2
-
-
53349152890
-
Automatic Detection of Web Application Security Flaws
-
Zanero, S., Carettoni, L., Zanchetta, M., "Automatic Detection of Web Application Security Flaws", Black Hat Briefings, 2005
-
(2005)
Black Hat Briefings
-
-
Zanero, S.1
Carettoni, L.2
Zanchetta, M.3
-
3
-
-
33745934031
-
Precise Alias Analysis for Static Detection of Web Application Vulnerabilities
-
Jovanovic, N., Kruegel, C., Kirda, E., "Precise Alias Analysis for Static Detection of Web Application Vulnerabilities", IEEE Symp. on Security and Privacy, 2006
-
(2006)
IEEE Symp. on Security and Privacy
-
-
Jovanovic, N.1
Kruegel, C.2
Kirda, E.3
-
4
-
-
70449783195
-
-
OWASP Foundation, July
-
Stock, A., Williams, J., Wichers, D., "OWASP top 10", OWASP Foundation, July, 2007
-
(2007)
OWASP top
, vol.10
-
-
Stock, A.1
Williams, J.2
Wichers, D.3
-
6
-
-
70449908122
-
-
August
-
Vnunet, August, 2007, http://www.vnunet.com/vnunet/news/2197408/ monsterkeptbreach-secret-five
-
(2007)
-
-
-
7
-
-
70449881385
-
-
NTA, May, 2007, http://www.ntamonitor.com/posts/2007/05/ annualsecurityreport.html
-
(2007)
-
-
May, N.T.A.1
-
8
-
-
39749151399
-
Conceptual Model and Architecture of MAFTIA
-
Powell, D., Stroud, R., "Conceptual Model and Architecture of MAFTIA", Project MAFTIA, deliverable D21, 2003
-
(2003)
Project MAFTIA, deliverable
-
-
Powell, D.1
Stroud, R.2
-
9
-
-
33845597598
-
Using Attack Injection to Discover New Vulnerabilities
-
Neves, N., Antunes, J., Correia, M., Veríssimo, P., Neves R., "Using Attack Injection to Discover New Vulnerabilities", IEEE/IFIP International Conference on Dependable Systems and Networks, 2006
-
(2006)
IEEE/IFIP International Conference on Dependable Systems and Networks
-
-
Neves, N.1
Antunes, J.2
Correia, M.3
Veríssimo, P.4
Neves, R.5
-
11
-
-
60349107378
-
Training Security Assurance Teams using Vulnerability Injection
-
December
-
Fonseca, J., Vieira, M., Madeira, H., "Training Security Assurance Teams using Vulnerability Injection", IEEE Pacific Rim Dependable Computing conference, December 2008
-
(2008)
IEEE Pacific Rim Dependable Computing conference
-
-
Fonseca, J.1
Vieira, M.2
Madeira, H.3
-
12
-
-
85008047801
-
Gauging Software Readiness with Defect Tracking
-
McConnell, S., "Gauging Software Readiness with Defect Tracking". Software, IEEE, 1997
-
(1997)
Software, IEEE
-
-
McConnell, S.1
-
13
-
-
0027646827
-
-
Arlat, J., Costes, A., Crouzet, Y., Laprie, J.-C., Powell, D., Fault injection and dependability evaluation of fault-tolerant systems, IEEE Trans. on Computers, 42(8):913.923, August, 1993
-
Arlat, J., Costes, A., Crouzet, Y., Laprie, J.-C., Powell, D., "Fault injection and dependability evaluation of fault-tolerant systems", IEEE Trans. on Computers, 42(8):913.923, August, 1993
-
-
-
-
14
-
-
0001822058
-
Experimental Evaluation, Special Issue FTCS-25 Silver Jubilee, IEEE Symp. on Fault Tolerant
-
Iyer, R., "Experimental Evaluation", Special Issue FTCS-25 Silver Jubilee, IEEE Symp. on Fault Tolerant Computing, pp. 115-132, 1995
-
(1995)
Computing
, pp. 115-132
-
-
Iyer, R.1
-
15
-
-
0032002385
-
Xception: Software Fault Injection and Monitoring in Processor Functional Units
-
February
-
Carreira, J., Madeira, H., Silva, J. G., "Xception: Software Fault Injection and Monitoring in Processor Functional Units", IEEE Trans. on Software Engineering, vol. 24, no. 2, February 1998
-
(1998)
IEEE Trans. on Software Engineering
, vol.24
, Issue.2
-
-
Carreira, J.1
Madeira, H.2
Silva, J.G.3
-
16
-
-
0033875633
-
NFTAPE: A framework for assessing dependability in distributed systems with lightweight fault injectors
-
Stott, D.T., Floering, B., Burke, D., Kalbarczpk, Z., Iyer, R.K., "NFTAPE: a framework for assessing dependability in distributed systems with lightweight fault injectors", Computer Performance and Dependability Symp., 2000
-
(2000)
Computer Performance and Dependability Symp
-
-
Stott, D.T.1
Floering, B.2
Burke, D.3
Kalbarczpk, Z.4
Iyer, R.K.5
-
19
-
-
33947314499
-
Emulation of Software Faults: A Field Data Study and a Practical Approach
-
November
-
Durães, J., Madeira, H., "Emulation of Software Faults: A Field Data Study and a Practical Approach", IEEE Trans. on Software Engineering, Vol. 32, No. 11, November 2006
-
(2006)
IEEE Trans. on Software Engineering
, vol.32
, Issue.11
-
-
Durães, J.1
Madeira, H.2
-
20
-
-
50049110333
-
Testing and comparing web vulnerability scanning tools for SQL injection and XSS attacks
-
December
-
Fonseca, J., Vieira, M., Madeira, H., "Testing and comparing web vulnerability scanning tools for SQL injection and XSS attacks", IEEE Pacific Rim International Symposium on Dependable Computing, December 2007
-
(2007)
IEEE Pacific Rim International Symposium on Dependable Computing
-
-
Fonseca, J.1
Vieira, M.2
Madeira, H.3
-
21
-
-
70449764428
-
-
Sam NG. CISA, CISSP. SQLBlock.com, www.owasp.org/images/7/7d/Advanced- Topics-on-SQL-Injection-Protection.ppt, 2006
-
(2006)
CISSP. SQLBlock.com
-
-
Sam, N.C.1
-
22
-
-
70449799206
-
-
December 2008
-
Cgisecurity.net, December 2008, http://www.cgisecurity.com/articles/csrf- faq.shtml#whatis
-
Cgisecurity.net
-
-
-
23
-
-
70449908118
-
-
SANS Institute, January, 2008
-
SANS Institute, January, 2008, http://isc.sans.org/diary.html?storyid= 3823
-
-
-
-
24
-
-
70449881384
-
-
Web Application Security Consortium, August
-
Web Application Security Consortium, August, 2008, http://www.webappsec. org/lists/websecurity/archive/2008-08/msg00084.html
-
(2008)
-
-
-
25
-
-
70449743083
-
-
The PHP Group, December
-
The PHP Group, December, 2007, http://pt.php.net/
-
(2007)
-
-
-
26
-
-
34547241372
-
A Classification of SQL Injection Attacks and Countermeasures
-
Halfond, W., Viegas, J., Orso, A., "A Classification of SQL Injection Attacks and Countermeasures", Int. Symp. on Secure Software Engineering, 2006
-
(2006)
Int. Symp. on Secure Software Engineering
-
-
Halfond, W.1
Viegas, J.2
Orso, A.3
-
27
-
-
77953855187
-
Using Parse Tree Validation to Prevent SQL Injection Attacks
-
Buehrer, G., Weide, B., Sivilotti, P., "Using Parse Tree Validation to Prevent SQL Injection Attacks", International Workshop on Software Egineering and Middleware, 2005
-
(2005)
International Workshop on Software Egineering and Middleware
-
-
Buehrer, G.1
Weide, B.2
Sivilotti, P.3
-
28
-
-
70449829585
-
-
December
-
TikiWiki, December, 2008, http://tikiwiki.org/
-
(2008)
-
-
-
29
-
-
70449759904
-
-
December
-
phpBB, December, 2008, http://www.phpbb.com/
-
(2008)
-
-
-
30
-
-
70449871679
-
-
Java-source.net, 2008, http://java-source.net/opensource/crawlers
-
(2008)
Java-source.net
-
-
-
31
-
-
79952023768
-
Detecting Malicious SQL
-
September
-
Fonseca, J., Vieira, M., Madeira, H., "Detecting Malicious SQL", Int. Conference on Trust, Privacy & Security in Digital Business, September, 2007
-
(2007)
Int. Conference on Trust, Privacy & Security in Digital Business
-
-
Fonseca, J.1
Vieira, M.2
Madeira, H.3
-
32
-
-
70449743073
-
-
SPI Dynamics Inc, May
-
SPI Dynamics Inc., May, 2008, http://www.spydynamics.com/products/ webinspect/
-
(2008)
-
-
-
33
-
-
70449783185
-
-
Watchfire Corporation
-
Watchfire Corporation, 2008, http://www.watchfire.com
-
(2008)
-
-
|