메뉴 건너뛰기




Volumn , Issue , 2011, Pages 83-93

Position paper: Why are there so many vulnerabilities in web applications?

Author keywords

access control; browser; web security; web server

Indexed keywords

BROWSER; ERROR PRONES; IN-DEPTH ANALYSIS; POSITION PAPERS; PROTECTION LOGIC; SECURITY PROBLEMS; SECURITY PROPERTIES; TRUSTED COMPUTING BASE; WEB APPLICATION; WEB INFRASTRUCTURE; WEB SECURITY; WEB SERVERS;

EID: 84855668211     PISSN: None     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1145/2073276.2073285     Document Type: Conference Paper
Times cited : (4)

References (31)
  • 1
    • 84855654845 scopus 로고    scopus 로고
    • Caja. http://code.google.com/p/google-caja/.
    • Caja
  • 2
    • 84877708479 scopus 로고    scopus 로고
    • Spring Security. http://static.springsource.org/spring-security/site/.
    • Spring Security
  • 4
    • 77955915657 scopus 로고    scopus 로고
    • XSS-GUARD: Precise Dynamic Prevention of Cross-Site Scripting Attacks
    • P. Bisht and V. Venkatakrishnan. XSS-GUARD: Precise Dynamic Prevention of Cross-Site Scripting Attacks . In DIMVA 2008.
    • (2008) DIMVA
    • Bisht, P.1    Venkatakrishnan, V.2
  • 12
    • 35348860223 scopus 로고    scopus 로고
    • Defeating script injection attacks with browser-enforced embedded policies
    • T. Jim, N. Swamy, and M. Hicks. Defeating script injection attacks with browser-enforced embedded policies. In WWW 2007.
    • (2007) WWW
    • Jim, T.1    Swamy, N.2    Hicks, M.3
  • 13
    • 48349104683 scopus 로고    scopus 로고
    • RequestRodeo: Client-side protection against session riding
    • F. Piessens, editor, refereed papers track, Report CW448, May
    • M. Johns and J. Winter. RequestRodeo: Client-side protection against session riding. In F. Piessens, editor, Proceedings of the OWASP Europe 2006 Conference, refereed papers track, Report CW448, pages 5-17, May 2006.
    • (2006) Proceedings of the OWASP Europe 2006 Conference , pp. 5-17
    • Johns, M.1    Winter, J.2
  • 15
    • 51349083251 scopus 로고    scopus 로고
    • Simple cross-site attack prevention
    • F. Kerschbaum. Simple cross-site attack prevention. In SecureComm 2007.
    • (2007) SecureComm
    • Kerschbaum, F.1
  • 17
    • 77955906366 scopus 로고    scopus 로고
    • Noxes: A client-side solution for mitigating cross-site scripting attacks
    • E. Kirda, C. Kruegel, G. Vigna, and N. Jovanovic. Noxes: a client-side solution for mitigating cross-site scripting attacks. In ACM SAC 2006.
    • (2006) ACM SAC
    • Kirda, E.1    Kruegel, C.2    Vigna, G.3    Jovanovic, N.4
  • 20
    • 77955186827 scopus 로고    scopus 로고
    • Conscript: Specifying and enforcing fine-grained security policies for javascript in the browser
    • L. A. Meyerovich and V. B. Livshits. Conscript: Specifying and enforcing fine-grained security policies for javascript in the browser. In IEEE Symposium on Security and Privacy, pages 481-496, 2010.
    • (2010) IEEE Symposium on Security and Privacy , pp. 481-496
    • Meyerovich, L.A.1    Livshits, V.B.2
  • 24
    • 33745213901 scopus 로고    scopus 로고
    • Defending against injection attacks through context-sensitive string evaluation
    • T. Pietraszek and C. V. Berghe. Defending against injection attacks through context-sensitive string evaluation. In RAID 2005.
    • (2005) RAID
    • Pietraszek, T.1    Berghe, C.V.2
  • 29
    • 84887309913 scopus 로고    scopus 로고
    • Cross-site scripting prevention with dynamic data tainting and static analysis
    • P. Vogt, F. Nentwich, N. Jovanovic, E. Kirda, C. Kruegel, and G. Vigna. Cross-site scripting prevention with dynamic data tainting and static analysis. In NDSS 2007.
    • (2007) NDSS
    • Vogt, P.1    Nentwich, F.2    Jovanovic, N.3    Kirda, E.4    Kruegel, C.5    Vigna, G.6
  • 31
    • 68549112050 scopus 로고    scopus 로고
    • URL
    • M. Zalewski. Cross-site cooking. URL: http://www.securityfocus.com/ archive/107/423375/30/0/threaded, 2006.
    • (2006) Cross-site Cooking
    • Zalewski, M.1


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.