-
1
-
-
50249115131
-
Saner: Composing static and dynamic analysis to validate sanitization in web applications
-
Balzarotti, D., Cova, M., Felmetsger, V., Jovanovic, N., Kirda, E., Kruegel, C., and Vigna, G. (2008). Saner: Composing static and dynamic analysis to validate sanitization in web applications. In S&P '08: Proceedings of the IEEE Symposium on Security and Privacy, 387-401.
-
(2008)
S&P '08: Proceedings of the IEEE Symposium on Security and Privacy
, pp. 387-401
-
-
Balzarotti, D.1
Cova, M.2
Felmetsger, V.3
Jovanovic, N.4
Kirda, E.5
Kruegel, C.6
Vigna, G.7
-
3
-
-
78650858740
-
-
GotoCode (n.d.). Retrieved August 23, 2009, from
-
GotoCode (n.d.). Open source web applications. Retrieved August 23, 2009, from http://www.gotocode.com
-
Open Source Web Applications
-
-
-
7
-
-
60649084590
-
XSSDS: Server-side detection of cross-site scripting attacks
-
Johns, M., Engelmann, B., and Posegga, J. (2008). XSSDS: Server-side detection of cross-site scripting attacks. In ACSAC '08: 2008 Annual Computer Security Applications Conference, 335-344.
-
(2008)
ACSAC '08: 2008 Annual Computer Security Applications Conference
, pp. 335-344
-
-
Johns, M.1
Engelmann, B.2
Posegga, J.3
-
8
-
-
33751027156
-
Pixy: A static analysis tool for detecting web application vulnerabilities
-
Jovanovic, N., Kruegel, C., and Kirda, E. (2006). Pixy: a static analysis tool for detecting web application vulnerabilities. In S&P '06: Proceedings of the IEEE Symposium on Security and Privacy, 258-263.
-
(2006)
S&P '06: Proceedings of the IEEE Symposium on Security and Privacy
, pp. 258-263
-
-
Jovanovic, N.1
Kruegel, C.2
Kirda, E.3
-
9
-
-
70349595106
-
Client-side cross-site scripting protection
-
Kirda, E., Kraegel, C., Vigna, G., Jovanovic, N. (2009). Client-side cross-site scripting protection. Computers & Security, 28, 592-604.
-
(2009)
Computers & Security
, vol.28
, pp. 592-604
-
-
Kirda, E.1
Kraegel, C.2
Vigna, G.3
Jovanovic, N.4
-
11
-
-
47849107582
-
Web application model recovery for user input validation testing
-
Li, N., Wu, J., Jin, M. Z., and Liu, C. (2007). Web application model recovery for user input validation testing. In ICSEA '07: 2nd International Conference on Software Engineering Advances, 85-90.
-
(2007)
ICSEA '07: 2nd International Conference on Software Engineering Advances
, pp. 85-90
-
-
Li, N.1
Wu, J.2
Jin, M.Z.3
Liu, C.4
-
12
-
-
56749091982
-
Covering code behavior on input validation in functional testing
-
Liu, H. and Tan, H. B. K. (2009). Covering code behavior on input validation in functional testing. Information and Software Technology, 51, 546-553.
-
(2009)
Information and Software Technology
, vol.51
, pp. 546-553
-
-
Liu, H.1
Tan, H.B.K.2
-
15
-
-
78651514134
-
-
OWASP May 14, Retrieved January 10, 2010, from
-
OWASP (May 14, 2009). Reviewing Code for Cross-site scripting. Retrieved January 10, 2010, from http://www.owasp.org/index.php/Reviewing-Code-for-Cross- site-scripting
-
(2009)
Reviewing Code for Cross-site Scripting
-
-
-
16
-
-
78651511843
-
-
OWASP January 6, Retrieved January 10, 2010, from
-
OWASP (January 6, 2010). XSS Prevention Cheat Sheet. Retrieved January 10, 2010, from http://www.owasp.org/index.php/XSS-(Cross-Site-Scripting)- Prevention-Cheat-Sheet
-
(2010)
XSS Prevention Cheat Sheet
-
-
-
17
-
-
0040027541
-
Interprocedural control dependence
-
Sinha, S., Harrold M. J., and Rothermel G. (2001). Interprocedural control dependence. ACM Transactions on Software Engineering and Methodology, 10, 209-254.
-
(2001)
ACM Transactions on Software Engineering and Methodology
, vol.10
, pp. 209-254
-
-
Sinha, S.1
Harrold, M.J.2
Rothermel, G.3
-
18
-
-
67650512922
-
-
Soot Retrieved February 12, 2009, from
-
Soot (2008). Soot: a Java Optimization Framework. Retrieved February 12, 2009, from http://www.sable.mcgill.ca/soot/
-
(2008)
Soot: A Java Optimization Framework
-
-
|