-
2
-
-
58849150637
-
Beware of finer-grained origins
-
Oakland, CA, May
-
C. Jackson and A. Barth, "Beware of Finer-Grained Origins," in Web 2.0 Security and Privacy (W2SP), Oakland, CA, May 2008. [Online]. Available: http://seclab.stanford.edu/websec/ origins/fgo.pdf
-
(2008)
Web 2.0 Security and Privacy (W2SP)
-
-
Jackson, C.1
Barth, A.2
-
3
-
-
77954608267
-
The multi-principal OS construction of the gazelle web browser
-
Montreal, Canada, Aug.
-
th USENIX Security Symposium, Montreal, Canada, Aug. 2009.
-
(2009)
th USENIX Security Symposium
-
-
Wang, H.J.1
Grier, C.2
Moshchuk, A.3
King, S.T.4
Choudhury, P.5
Venter, H.6
-
4
-
-
79952338164
-
-
Accessed on Nov. 14
-
J. Ruderman, "Same Origin Policy for JavaScript," http://www.mozilla.org/projects/security/components/ same-origin.html. Accessed on Nov. 14, 2009.
-
(2009)
Same Origin Policy for JavaScript
-
-
Ruderman, J.1
-
5
-
-
77955182541
-
-
"Alexa," http://www.alexa.com/.
-
Alexa
-
-
-
6
-
-
77955216221
-
-
Accessed on Nov. 14
-
"Document Object Model," http://www.w3.org/DOM/. Accessed on Nov. 14, 2009.
-
(2009)
-
-
-
7
-
-
0009517422
-
HTTP state management mechanism
-
Oct.
-
D. Kristol and L. Montulli, "HTTP State Management Mechanism," in IETF RFC 2965, Oct. 2000.
-
(2000)
IETF RFC
, vol.2965
-
-
Kristol, D.1
Montulli, L.2
-
9
-
-
77949669849
-
-
Accessed on Nov. 14, 2009.
-
M. Zalewski, "Browser Security Handbook," 2008, http:// code.google.com/p/browsersec/wiki/Main. Accessed on Nov. 14, 2009.
-
(2008)
Browser Security Handbook
-
-
Zalewski, M.1
-
10
-
-
77955220132
-
HTTP state management mechanism
-
Feb
-
A. Barth, "HTTP State Management Mechanism," IETF Draft 2109, Feb 2010, http://tools.ietf.org/html/ draft-ietf-httpstate-cookie-03.
-
(2010)
IETF Draft 2109
-
-
Barth, A.1
-
11
-
-
57349089194
-
Force HTTPS: Protecting highsecurity web sites from network attacks
-
C. Jackson and A. Barth, "ForceHTTPS: Protecting HighSecurity Web Sites from Network Attacks," in WWW, 2008.
-
(2008)
WWW
-
-
Jackson, C.1
Barth, A.2
-
12
-
-
77955180982
-
-
October
-
"HTML 5 Editor's Draft," October 2008, http://www.w3.org/ html/wg/html5/.
-
(2008)
HTML 5 editor's draft
-
-
-
14
-
-
77955202085
-
-
Accessed on Nov. 14
-
"XMLHttpRequest," http://www.w3.org/TR/ XMLHttpRequest/. Accessed on Nov. 14, 2009.
-
(2009)
XMLHttpRequest
-
-
-
15
-
-
77955214548
-
-
Accessed on Nov. 14
-
"XMLHttpRequest Level 2," http://www.w3.org/TR/ XMLHttpRequest2/. Accessed on Nov. 14, 2009.
-
(2009)
XMLHttpRequest Level 2
-
-
-
17
-
-
77955220375
-
-
Accessed on Nov. 14
-
"HttpOnly," http://www.owasp.org/index.php/HTTPOnly. Accessed on Nov. 14, 2009.
-
(2009)
HttpOnly
-
-
-
19
-
-
77954470294
-
-
"Clickjacking," http://en.wikipedia.org/wiki/Clickjacking.
-
Clickjacking
-
-
-
20
-
-
79959877427
-
-
Accessed on Nov. 14, 2009.
-
"Whats New in Internet Explorer 8," 2008, http:// msdn.microsoft.com/en-us/library/cc288472.aspx. Accessed on Nov. 14, 2009.
-
(2008)
Whats New in Internet Explorer 8
-
-
-
26
-
-
77955223886
-
-
Accessed on Nov. 14
-
"FiddlerCore," http://flddler.wikidot.com/flddlercore. Accessed on Nov. 14, 2009.
-
(2009)
FiddlerCore
-
-
-
27
-
-
78650757983
-
-
Accessed on Mar. 1
-
"BugMeNot," http://www.bugmenot.com/. Accessed on Mar. 1, 2010.
-
(2010)
BugMeNot
-
-
-
28
-
-
77955202083
-
-
Accessed on Nov. 14
-
M. O'Neal, "Cookie Path Best Practice," http://research. corsaire.com/whitepapers/040323-cookie-path-best-practice. pdf. Accessed on Nov. 14, 2009.
-
(2009)
Cookie Path Best Practice
-
-
O'Neal, M.1
-
29
-
-
77955179745
-
-
Accessed on Nov. 14
-
"Browserscope," http://www.browserscope.org/. Accessed on Nov. 14, 2009.
-
(2009)
-
-
-
31
-
-
77954485245
-
Automated web patrol with strider honeymonkeys
-
San Diego, CA, Feb.
-
th Network and Distributed System Security Symposium (NDSS), San Diego, CA, Feb. 2006.
-
(2006)
th Network and Distributed System Security Symposium (NDSS)
-
-
Wang, Y.-M.1
Beck, D.2
Jiang, X.3
Roussev, R.4
Verbowski, C.5
Chen, S.6
King, S.7
-
33
-
-
85080711655
-
The ghost in the browser: Analysis of webbased malware
-
Berkeley, CA, USA
-
st Workshop on Hot Topics in Understanding Botnets (HotBots), Berkeley, CA, USA, 2007.
-
(2007)
st Workshop on Hot Topics in Understanding Botnets (HotBots)
-
-
Provos, N.1
McNamee, D.2
Mavrommatis, P.3
Wang, K.4
Modadugu, N.5
-
34
-
-
85076893377
-
Spy proxy: Execution-based detection of malicious web content
-
Boston, MA, Aug.
-
th USENIX Security Symposium, Boston, MA, Aug. 2007.
-
(2007)
th USENIX Security Symposium
-
-
Moshchuk, A.1
Bragin, T.2
Deville, D.3
Gribble, S.D.4
Levy, H.M.5
|