-
2
-
-
50249115131
-
Saner: Composing static and dynamic analysis to validate sanitization in web applications
-
Oakland, California, USA
-
BALZAROTTI, D., COVA, M., FELMETSGER, V., JOVANOVIC, N., KIRDA, E., KRUEGEL, C., AND VIGNA, G. Saner: Composing Static and Dynamic Analysis to Validate Sanitization in Web Applications. In SP'08: Proceedings of the 29th IEEE Symposium on Security and Privacy (Oakland, California, USA, 2008).
-
(2008)
SP'08: Proceedings of the 29th IEEE Symposium on Security and Privacy
-
-
Balzarotti, D.1
Cova, M.2
Felmetsger, V.3
Jovanovic, N.4
Kirda, E.5
Kruegel, C.6
Vigna, G.7
-
3
-
-
49949096891
-
Multi-module vulnerability analysis of web-based applications
-
Alexandria, Virginia, USA
-
BALZAROTTI, D., COVA, M., FELMETSGER, V. V., AND VIGNA, G. Multi-Module Vulnerability Analysis of Web-based Applications. In CCS'07: 14th ACM Conference on Computer and Communications Security (Alexandria, Virginia, USA, 2007).
-
(2007)
CCS'07: 14th ACM Conference on Computer and Communications Security
-
-
Balzarotti, D.1
Cova, M.2
Felmetsger, V.V.3
Vigna, G.4
-
4
-
-
49949109144
-
CANDID: Preventing SQL injection attacks using dynamic candidate evaluations
-
Alexandria, Virginia, USA
-
BANDHAKAVI, S., BISHT, P., MADHUSUDAN, P., AND VENKATAKRISHNAN, V. CANDID: Preventing SQL Injection Attacks using Dynamic Candidate Evaluations. In CCS'07: Proceedings of the 14th ACM Conference on Computer and Communications security (Alexandria, Virginia, USA, 2007).
-
(2007)
CCS'07: Proceedings of the 14th ACM Conference on Computer and Communications Security
-
-
Bandhakavi, S.1
Bisht, P.2
Madhusudan, P.3
Venkatakrishnan, V.4
-
5
-
-
18444373554
-
A survey on tree edit distance and related problems
-
BILLE, P. A survey on tree edit distance and related problems. Theoretical Computer Science 337, 1-3 (2005), 217-239.
-
(2005)
Theoretical Computer Science
, vol.337
, Issue.1-3
, pp. 217-239
-
-
Bille, P.1
-
6
-
-
78649981355
-
Automatically preparing safe SQL queries
-
Tenerife, Canary Islands, Spain
-
BISHT, P., SISTLA, A. P., AND VENKATAKRISHNAN, V. Automatically Preparing Safe SQL Queries. In FC'10: Proceedings of the 14th International Conference on Financial Cryptography and Data Security (Tenerife, Canary Islands, Spain, 2010).
-
(2010)
FC'10: Proceedings of the 14th International Conference on Financial Cryptography and Data Security
-
-
Bisht, P.1
Sistla, A.P.2
Venkatakrishnan, V.3
-
7
-
-
85077688456
-
Towards automatic discovery of deviations in binary implementations with applications to error detection and fingerprint generation
-
Berkeley, California, USA
-
BRUMLEY, D., CABALLERO, J., LIANG, Z., NEWSOME, J., AND SONG, D. Towards Automatic Discovery of Deviations in Binary Implementations with Applications to Error Detection and Fingerprint Generation. In SS'07: Proceedings of 16th USENIX Security Symposium (Berkeley, California, USA, 2007).
-
(2007)
SS'07: Proceedings of 16th USENIX Security Symposium
-
-
Brumley, D.1
Caballero, J.2
Liang, Z.3
Newsome, J.4
Song, D.5
-
8
-
-
41149124878
-
Secure Web Application via Automatic Partitioning
-
CHONG, S., LIU, J., MYERS, A. C., QI, X., VIKRAM, K., ZHENG, L., AND ZHENG, X. Secure Web Application via Automatic Partitioning. SIGOPS Oper. Syst. Rev. 41, 6 (2007), 31-44.
-
(2007)
SIGOPS Oper. Syst. Rev.
, vol.41
, Issue.6
, pp. 31-44
-
-
Chong, S.1
Liu, J.2
Myers, A.C.3
Q, I.X.4
Vikram, K.5
Zheng, L.6
Zheng, X.7
-
9
-
-
31844450371
-
DART: Directed automated random testing
-
GODEFROID, P., KLARLUND, N., AND SEN, K. DART: Directed Automated Random Testing. SIGPLAN Not. 40, 6 (2005), 213-223.
-
(2005)
SIGPLAN Not.
, vol.40
, Issue.6
, pp. 213-223
-
-
Godefroid, P.1
Klarlund, N.2
Sen, K.3
-
10
-
-
50249104216
-
Automated whitebox fuzz testing
-
San Diego, California, USA
-
GODEFROID, P., LEVIN, M. Y., AND MOLNAR, D. A. Automated Whitebox Fuzz Testing. In NDSS'08: Proceedings of the 16th Annual Network and Distributed System Security Symposium (San Diego, California, USA, 2008).
-
(2008)
NDSS'08: Proceedings of the 16th Annual Network and Distributed System Security Symposium
-
-
Godefroid, P.1
Levin, M.Y.2
Molnar, D.A.3
-
11
-
-
50249182906
-
Secure web browsing with the OP web browser
-
Oakland, California, USA
-
GRIER, C., TANG, S., AND KING, S. T. Secure Web Browsing With the OP Web Browser. In SP'08: Proceedings of the 29th IEEE Symposium on Security and Privacy (Oakland, California, USA, 2008).
-
(2008)
SP'08: Proceedings of the 29th IEEE Symposium on Security and Privacy
-
-
Grier, C.1
Tang, S.2
King, S.T.3
-
12
-
-
40449116802
-
A classification of SQL-injection attacks and countermeasures
-
Washington, DC, USA
-
HALFOND, W. G., VIEGAS, J., AND ORSO, A. A Classification of SQL-Injection Attacks and Countermeasures. In ISSE'06: Proceedings of the International Symposium on Secure Software Engineering (Washington, DC, USA, 2006).
-
(2006)
ISSE'06: Proceedings of the International Symposium on Secure Software Engineering
-
-
Halfond, W.G.1
Viegas, J.2
Orso, A.3
-
13
-
-
85008256304
-
A solver for string constraints
-
Chicago, Illinois, USA
-
KIEZUN, A., GANESH, V., GUO, P. J., HOOIMEIJER, P., AND ERNST, M. D. HAMPI: A Solver for String Constraints. In ISSTA '09: Proceedings of the 18th international symposium on Software testing and analysis (Chicago, Illinois, USA, 2009).
-
(2009)
ISSTA '09: Proceedings of the 18th International Symposium on Software Testing and Analysis
-
-
Kiezun, A.1
Ganesh, V.2
Guo, P.J.3
Hooimeijer, P.4
Ernst, M.D.H.5
-
14
-
-
84923564816
-
Finding security vulnerabilities in java applications with static analysis
-
Baltimore, Maryland, USA
-
LIVSHITS, V. B., AND LAM, M. S. Finding Security Vulnerabilities in Java Applications with Static Analysis. In SS'05: Proceedings of the 14th USENIX Security Symposium (Baltimore, Maryland, USA, 2005).
-
(2005)
SS'05: Proceedings of the 14th USENIX Security Symposium
-
-
Livshits, V.B.1
Lam, M.S.2
-
15
-
-
34547349153
-
Replayer: Automatic protocol replay by binary analysis
-
Alexandria, Virginia, USA
-
NEWSOME, J., BRUMLEY, D., FRANKLIN, J., AND SONG, D. Replayer: Automatic Protocol Replay by Binary Analysis. In CCS'06: Proceedings of the 13th ACM conference on Computer and communications security (Alexandria, Virginia, USA, 2006).
-
(2006)
CCS'06: Proceedings of the 13th ACM Conference on Computer and Communications Security
-
-
Newsome, J.1
Brumley, D.2
Franklin, J.3
Song, D.4
-
16
-
-
0040966631
-
Pattern matching: The gestalt approach
-
July
-
RATCLIFF, J. W., AND METZENER, D. Pattern Matching: The Gestalt Approach. Dr. Dobbs Journal (July 1988), 46.
-
(1988)
Dr Dobbs Journal
, pp. 46
-
-
Ratcliff, J.W.1
Metzener, D.2
-
18
-
-
77955220343
-
A symbolic execution framework for JavaScript
-
Oakland, California, USA
-
SAXENA, P., AKHAWE, D., HANNA, S., MAO, F., MCCAMANT, S., AND SONG, D. A Symbolic Execution Framework for JavaScript. In SP'10: Proceedings of the 31st IEEE Symposium on Security and Privacy (Oakland, California, USA, 2010).
-
(2010)
SP'10: Proceedings of the 31st IEEE Symposium on Security and Privacy
-
-
Saxena, P.1
Akhawe, D.2
Hanna, S.3
Mao, F.4
McCamant, S.5
Song, D.6
-
19
-
-
80051946867
-
FLAX: Systematic discovery of client-side validation vulnerabilities in rich web applications
-
San Diego, California, USA
-
SAXENA, P., HANNA, S., POOSANKAM, P., AND SONG, D. FLAX: Systematic Discovery of Client-side Validation Vulnerabilities in Rich Web Applications. In NDSS'10: Proceedings of the 17th Annual Network and Distributed System Security Symposium (San Diego, California, USA, 2010).
-
(2010)
NDSS'10: Proceedings of the 17th Annual Network and Distributed System Security Symposium
-
-
Saxena, P.1
Hanna, S.2
Poosankam, P.3
Song, D.4
-
20
-
-
79551514936
-
Document structure integrity: A robust basis for cross-site scripting defense
-
San Diego, California, USA
-
SAXENA, P., SONG, D., AND NADJI, Y. Document Structure Integrity: A Robust Basis for Cross-site Scripting Defense. In NDSS'09: Proceedings of 16th Annual Network & Distributed System Security Symposium (San Diego, California, USA, 2009).
-
(2009)
NDSS'09: Proceedings of 16th Annual Network & Distributed System Security Symposium
-
-
Saxena, P.1
Song, D.2
Nadji, Y.3
-
21
-
-
78650032558
-
The essence of command injection attacks in web applications
-
Charleston, South Carolina, USA
-
SU, Z., AND WASSERMANN, G. The Essence of Command Injection Attacks in Web Applications. In POPL'06: Proceedings of the 33rd symposium on Principles of programming languages (Charleston, South Carolina, USA, 2006).
-
(2006)
POPL'06: Proceedings of the 33rd Symposium on Principles of Programming Languages
-
-
S, U.Z.1
Wassermann, G.2
-
22
-
-
82155200850
-
BluePrint: Robust prevention of cross-site scripting attacks for existing browsers
-
Oakland, California, USA
-
TER LOUW, M., AND VENKATAKRISHNAN, V. BluePrint: Robust Prevention of Cross-site Scripting Attacks for Existing Browsers. In SP'09: Proceedings of the 30th IEEE Symposium on Security and Privacy (Oakland, California, USA, 2009).
-
(2009)
SP'09: Proceedings of the 30th IEEE Symposium on Security and Privacy
-
-
Ter Louw, M.1
Venkatakrishnan, V.2
-
23
-
-
70349921536
-
Noncespaces: Using randomization to enforce information flow tracking and thwart cross-site scripting attacks
-
San Diego, California, USA
-
VAN GUNDY, M., AND CHEN, H. Noncespaces: Using Randomization to Enforce Information Flow Tracking and Thwart Cross-site Scripting Attacks. In NDSS'09: Proceedings of the 16th Annual Network & Distributed System Security Symposium (San Diego, California, USA, 2009).
-
(2009)
NDSS'09: Proceedings of the 16th Annual Network & Distributed System Security Symposium
-
-
Van Gundy, M.1
Chen, H.2
-
24
-
-
74049104017
-
Ripley: Automatically securing distributed web applications through replicated execution
-
Chicago, Illinois, USA
-
VIKRAM, K., PRATEEK, A., AND LIVSHITS, B. Ripley: Automatically Securing Distributed Web Applications Through Replicated Execution. In CCS'09: Proceedings of the 16th Conference on Computer and Communications Security (Chicago, Illinois, USA, 2009).
-
(2009)
CCS'09: Proceedings of the 16th Conference on Computer and Communications Security
-
-
Vikram, K.1
Prateek, A.2
Livshits, B.3
-
25
-
-
77954608267
-
The multi-principal OS construction of the gazelle web browser
-
Montreal, Canada
-
WANG, H. J., GRIER, C., MOSHCHUK, A., KING, S. T., CHOUDHURY, P., AND VENTER, H. The Multi-Principal OS Construction of the Gazelle Web Browser. In SS'09: Proceedings of the 18th USENIX Security Symposium (Montreal, Canada, 2009).
-
(2009)
SS'09: Proceedings of the 18th USENIX Security Symposium
-
-
Wang, H.J.1
Grier, C.2
Moshchuk, A.3
King, S.T.4
Choudhury, P.5
Venter, H.6
|