-
2
-
-
84874550218
-
-
Alexa top sites. http://www.alexa.com/topsites.
-
Alexa Top Sites
-
-
-
4
-
-
77954475874
-
-
Myspace. http://www.myspace.com.
-
Myspace
-
-
-
5
-
-
77954523221
-
-
Nikto. http://www.cirt.net/nikto2.
-
Nikto
-
-
-
9
-
-
77954512863
-
-
xdotool. http://www.semicomplete.com/projects/xdotool/.
-
Xdotool
-
-
-
10
-
-
77954501673
-
-
http://www.blogger.com, 2009.
-
(2009)
-
-
-
11
-
-
77954461257
-
-
Alexa Internet, Inc. Alexa - top sites by category. http://www.alexa.com/ topsites/category/Top/, 2009.
-
(2009)
Alexa - Top Sites by Category
-
-
-
12
-
-
50249115131
-
Saner: Composing static and dynamic analysis to validate sanitization in web applications
-
D. Balzarotti, M. Cova, V. Felmetsger, N. Jovanovic, E. Kirda, C. Kruegel, and G. Vigna. Saner: Composing static and dynamic analysis to validate sanitization in web applications. In IEEE Symposium on Security and Privacy, pages 387-401, 2008.
-
(2008)
IEEE Symposium on Security and Privacy
, pp. 387-401
-
-
Balzarotti, D.1
Cova, M.2
Felmetsger, V.3
Jovanovic, N.4
Kirda, E.5
Kruegel, C.6
Vigna, G.7
-
13
-
-
33746440296
-
Using static program analysis to aid intrusion detection
-
M. Egele, M. Szydlowski, E. Kirda, and C. Kruegel. Using static program analysis to aid intrusion detection. In Detection of Intrusions and Malware & Vulnerability Assessment, Third International Conference, DIMVA 2006, Berlin, Germany, July 13-14, 2006, Proceedings, pages 17-36, 2006.
-
(2006)
Detection of Intrusions and Malware & Vulnerability Assessment, Third International Conference, DIMVA 2006, Berlin, Germany, July 13-14, 2006, Proceedings
, pp. 17-36
-
-
Egele, M.1
Szydlowski, M.2
Kirda, E.3
Kruegel, C.4
-
14
-
-
85080362568
-
A virtual machine introspection based architecture for intrusion detection
-
T. Garfinkel and M. Rosenblum. A virtual machine introspection based architecture for intrusion detection. In Proceedings of the Network and Distributed System Security Symposium, NDSS 2003, San Diego, California, USA, 2003.
-
Proceedings of the Network and Distributed System Security Symposium, NDSS 2003, San Diego, California, USA, 2003
-
-
Garfinkel, T.1
Rosenblum, M.2
-
17
-
-
84880450431
-
Web application security assessment by fault injection and behavior monitoring
-
New York, NY, USA, ACM
-
Y.-W. Huang, S.-K. Huang, T.-P. Lin, and C.-H. Tsai. Web application security assessment by fault injection and behavior monitoring. In WWW '03: Proceedings of the 12th international conference on World Wide Web, pages 148-159, New York, NY, USA, 2003. ACM.
-
(2003)
WWW '03: Proceedings of the 12th International Conference on World Wide Web
, pp. 148-159
-
-
Huang, Y.-W.1
Huang, S.-K.2
Lin, T.-P.3
Tsai, C.-H.4
-
18
-
-
19944365247
-
Securing web application code by static analysis and runtime protection
-
New York, NY, USA, ACM
-
Y.-W. Huang, F. Yu, C. Hang, C.-H. Tsai, D.-T. Lee, and S.-Y. Kuo. Securing web application code by static analysis and runtime protection. In WWW '04: Proceedings of the 13th international conference on World Wide Web, pages 40-52, New York, NY, USA, 2004. ACM.
-
(2004)
WWW '04: Proceedings of the 13th International Conference on World Wide Web
, pp. 40-52
-
-
Huang, Y.-W.1
Yu, F.2
Hang, C.3
Tsai, C.-H.4
Lee, D.-T.5
Kuo, S.-Y.6
-
19
-
-
77954478139
-
-
International Secure Systems Lab. http://anubis.iseclab.org, 2009.
-
(2009)
-
-
-
21
-
-
77954467581
-
-
June
-
Jeremiah Grossman. Clickjacking 2017. http://jeremiahgrossman.blogspot. com/2009/06/clickjacking-2017.html, June 2009.
-
(2009)
Clickjacking 2017
-
-
Grossman, J.1
-
22
-
-
33751027156
-
Pixy: A static analysis tool for detecting web application vulnerabilities
-
(short paper)
-
N. Jovanovic, C. Kruegel, and E. Kirda. Pixy: A static analysis tool for detecting web application vulnerabilities (short paper). In IEEE Symposium on Security and Privacy, pages 258-263, 2006.
-
(2006)
IEEE Symposium on Security and Privacy
, pp. 258-263
-
-
Jovanovic, N.1
Kruegel, C.2
Kirda, E.3
-
23
-
-
34250673645
-
Secubat: A web vulnerability scanner
-
New York, NY, USA, ACM
-
S. Kals, E. Kirda, C. Kruegel, and N. Jovanovic. Secubat: a web vulnerability scanner. In WWW '06: Proceedings of the 15th international conference on World Wide Web, pages 247-256, New York, NY, USA, 2006. ACM.
-
(2006)
WWW '06: Proceedings of the 15th International Conference on World Wide Web
, pp. 247-256
-
-
Kals, S.1
Kirda, E.2
Kruegel, C.3
Jovanovic, N.4
-
27
-
-
77954465167
-
-
01
-
Microsoft. IE8 Clickjacking Defense. http://blogs.msdn.com/ie/archive/ 2009/01/27/ie8-security-part-vii-clickjacking-defenses. aspx, 01 2009.
-
(2009)
IE8 Clickjacking Defense
-
-
-
29
-
-
85077681170
-
A crawler-based study of spyware in the web
-
A. Moshchuk, T. Bragin, S. D. Gribble, and H. M. Levy. A crawler-based study of spyware in the web. In Proceedings of the Network and Distributed System Security Symposium, NDSS 2006, San Diego, California, USA, 2006.
-
Proceedings of the Network and Distributed System Security Symposium, NDSS 2006, San Diego, California, USA, 2006
-
-
Moshchuk, A.1
Bragin, T.2
Gribble, S.D.3
Levy, H.M.4
-
30
-
-
77954505906
-
-
Mozilla Foundation. https://bugzilla.mozilla.org/show-bug.cgi?id=154957, 2002.
-
(2002)
-
-
-
32
-
-
85080711655
-
The ghost in the browser analysis of web-based malware
-
Berkeley, CA, USA, USENIX Association
-
N. Provos, D. McNamee, P. Mavrommatis, K. Wang, and N. Modadugu. The ghost in the browser analysis of web-based malware. In HotBots'07: Proceedings of the first conference on First Workshop on Hot Topics in Understanding Botnets, pages 4-4, Berkeley, CA, USA, 2007. USENIX Association.
-
(2007)
HotBots'07: Proceedings of the First Conference on First Workshop on Hot Topics in Understanding Botnets
, pp. 4-4
-
-
Provos, N.1
McNamee, D.2
Mavrommatis, P.3
Wang, K.4
Modadugu, N.5
-
33
-
-
0035009417
-
Analysis and testing of web applications
-
Washington, DC, USA, IEEE Computer Society
-
F. Ricca and P. Tonella. Analysis and testing of web applications. In ICSE '01: Proceedings of the 23rd International Conference on Software Engineering, pages 25-34, Washington, DC, USA, 2001. IEEE Computer Society.
-
(2001)
ICSE '01: Proceedings of the 23rd International Conference on Software Engineering
, pp. 25-34
-
-
Ricca, F.1
Tonella, P.2
-
35
-
-
84887309913
-
Cross site scripting prevention with dynamic data tainting and static analysis
-
P. Vogt, F. Nentwich, N. Jovanovic, E. Kirda, C. Kruegel, and G. Vigna. Cross site scripting prevention with dynamic data tainting and static analysis. In Proceedings of the Network and Distributed System Security Symposium, NDSS 2007, San Diego, California, USA, 28th February - 2nd March 2007, 2007.
-
(2007)
Proceedings of the Network and Distributed System Security Symposium, NDSS 2007, San Diego, California, USA, 28th February - 2nd March 2007
-
-
Vogt, P.1
Nentwich, F.2
Jovanovic, N.3
Kirda, E.4
Kruegel, C.5
Vigna, G.6
-
36
-
-
33750356750
-
Automated web patrol with strider honeymonkeys: Finding web sites that exploit browser vulnerabilities
-
Y.-M. Wang, D. Beck, X. Jiang, and R. Roussev. Automated web patrol with strider honeymonkeys: Finding web sites that exploit browser vulnerabilities. In IN NDSS, 2006.
-
(2006)
IN NDSS
-
-
Wang, Y.-M.1
Beck, D.2
Jiang, X.3
Roussev, R.4
-
37
-
-
35449004893
-
Sound and precise analysis of web applications for injection vulnerabilities
-
G. Wassermann and Z. Su. Sound and precise analysis of web applications for injection vulnerabilities. SIGPLAN Not., 42(6):32-41, 2007.
-
(2007)
SIGPLAN Not.
, vol.42
, Issue.6
, pp. 32-41
-
-
Wassermann, G.1
Su, Z.2
-
38
-
-
57449103850
-
Dynamic test input generation for web applications
-
New York, NY, USA, ACM
-
G. Wassermann, D. Yu, A. Chander, D. Dhurjati, H. Inamura, and Z. Su. Dynamic test input generation for web applications. In ISSTA '08: Proceedings of the 2008 international symposium on Software testing and analysis, pages 249-260, New York, NY, USA, 2008. ACM.
-
(2008)
ISSTA '08: Proceedings of the 2008 International Symposium on Software Testing and Analysis
, pp. 249-260
-
-
Wassermann, G.1
Yu, D.2
Chander, A.3
Dhurjati, D.4
Inamura, H.5
Su, Z.6
-
39
-
-
84910681237
-
Static detection of security vulnerabilities in scripting languages
-
USENIX Association
-
Y. Xie and A. Aiken. Static detection of security vulnerabilities in scripting languages. In USENIX-SS'06: Proceedings of the 15th conference on USENIX Security Symposium, Berkeley, CA, USA, 2006. USENIX Association.
-
USENIX-SS'06: Proceedings of the 15th Conference on USENIX Security Symposium, Berkeley, CA, USA, 2006
-
-
Xie, Y.1
Aiken, A.2
|