-
1
-
-
84855654845
-
-
Caja. http://code.google.com/p/google-caja/.
-
Caja
-
-
-
2
-
-
84877708479
-
-
Spring Security. http://static.springsource.org/spring-security/site/.
-
Spring Security
-
-
-
3
-
-
70349266257
-
Robust defenses for cross-site request forgery
-
New York, NY, USA, ACM
-
A. Barth, C. Jackson, and J. C. Mitchell. Robust defenses for cross-site request forgery. In CCS '08: Proceedings of the 15th ACM conference on Computer and communications security, pages 75-88, New York, NY, USA, 2008. ACM.
-
(2008)
CCS '08: Proceedings of the 15th ACM Conference on Computer and Communications Security
, pp. 75-88
-
-
Barth, A.1
Jackson, C.2
Mitchell, J.C.3
-
4
-
-
77955915657
-
XSS-GUARD: Precise Dynamic Prevention of Cross-Site Scripting Attacks
-
P. Bisht and V. Venkatakrishnan. XSS-GUARD: Precise Dynamic Prevention of Cross-Site Scripting Attacks . In DIMVA 2008.
-
(2008)
DIMVA
-
-
Bisht, P.1
Venkatakrishnan, V.2
-
6
-
-
84855704721
-
Re-designing the web's access control system (invited talk)
-
W. Du, X. Tan, T. Luo, K. Jayaraman, and Z. Zhu. Re-designing the web's access control system (invited talk). In Proceedings of the 25th Annual WG 11.3 Conference on Data and Applications Security and Privacy, Richmond, Virgina USA, July 11-13 2011.
-
Proceedings of the 25th Annual WG 11.3 Conference on Data and Applications Security and Privacy, Richmond, Virgina USA, July 11-13 2011
-
-
Du, W.1
Tan, X.2
Luo, T.3
Jayaraman, K.4
Zhu, Z.5
-
7
-
-
80051989642
-
Cryptography in the web: The case of cryptographic design flaws in asp.net
-
IEEE Computer Society
-
T. Duong and J. Rizzo. Cryptography in the web: The case of cryptographic design flaws in asp.net. In Proceedings of the 2011 IEEE Symposium on Security and Privacy, SP '11, Washington, DC, USA, 2011. IEEE Computer Society.
-
Proceedings of the 2011 IEEE Symposium on Security and Privacy, SP '11, Washington, DC, USA, 2011
-
-
Duong, T.1
Rizzo, J.2
-
10
-
-
77955860750
-
Escudo: A fine-grained protection model for web browsers
-
K. Jayaraman, W. Du, B. Rajagopalan, and S. J. Chapin. Escudo: A fine-grained protection model for web browsers. In Proceedings of the 30th International Conference on Distributed Computing Systems (ICDCS), Genoa, Italy, June 21-25 2010.
-
Proceedings of the 30th International Conference on Distributed Computing Systems (ICDCS), Genoa, Italy, June 21-25 2010
-
-
Jayaraman, K.1
Du, W.2
Rajagopalan, B.3
Chapin, S.J.4
-
11
-
-
77958475027
-
Enforcing request integrity in web applications
-
Berlin, Heidelberg, Springer-Verlag
-
K. Jayaraman, G. Lewandowski, P. G. Talaga, and S. J. Chapin. Enforcing request integrity in web applications. In Proceedings of the 24th annual IFIP WG 11.3 working conference on Data and applications security and privacy, DBSec'10, pages 225-240, Berlin, Heidelberg, 2010. Springer-Verlag.
-
(2010)
Proceedings of the 24th Annual IFIP WG 11.3 Working Conference on Data and Applications Security and Privacy, DBSec'10
, pp. 225-240
-
-
Jayaraman, K.1
Lewandowski, G.2
Talaga, P.G.3
Chapin, S.J.4
-
12
-
-
35348860223
-
Defeating script injection attacks with browser-enforced embedded policies
-
T. Jim, N. Swamy, and M. Hicks. Defeating script injection attacks with browser-enforced embedded policies. In WWW 2007.
-
(2007)
WWW
-
-
Jim, T.1
Swamy, N.2
Hicks, M.3
-
13
-
-
48349104683
-
RequestRodeo: Client-side protection against session riding
-
F. Piessens, editor, refereed papers track, Report CW448, May
-
M. Johns and J. Winter. RequestRodeo: Client-side protection against session riding. In F. Piessens, editor, Proceedings of the OWASP Europe 2006 Conference, refereed papers track, Report CW448, pages 5-17, May 2006.
-
(2006)
Proceedings of the OWASP Europe 2006 Conference
, pp. 5-17
-
-
Johns, M.1
Winter, J.2
-
15
-
-
51349083251
-
Simple cross-site attack prevention
-
F. Kerschbaum. Simple cross-site attack prevention. In SecureComm 2007.
-
(2007)
SecureComm
-
-
Kerschbaum, F.1
-
17
-
-
77955906366
-
Noxes: A client-side solution for mitigating cross-site scripting attacks
-
E. Kirda, C. Kruegel, G. Vigna, and N. Jovanovic. Noxes: a client-side solution for mitigating cross-site scripting attacks. In ACM SAC 2006.
-
(2006)
ACM SAC
-
-
Kirda, E.1
Kruegel, C.2
Vigna, G.3
Jovanovic, N.4
-
20
-
-
77955186827
-
Conscript: Specifying and enforcing fine-grained security policies for javascript in the browser
-
L. A. Meyerovich and V. B. Livshits. Conscript: Specifying and enforcing fine-grained security policies for javascript in the browser. In IEEE Symposium on Security and Privacy, pages 481-496, 2010.
-
(2010)
IEEE Symposium on Security and Privacy
, pp. 481-496
-
-
Meyerovich, L.A.1
Livshits, V.B.2
-
21
-
-
78650896178
-
Document structure integrity: A robust basis for cross-site scripting defense
-
Y. Nadji, P. Saxena, and D. Song. Document structure integrity: A robust basis for cross-site scripting defense. In Proceedings of the 16th Annual Network and Distributed System Security Symposium (NDSS), San Diego, CA, February 2009.
-
Proceedings of the 16th Annual Network and Distributed System Security Symposium (NDSS), San Diego, CA, February 2009
-
-
Nadji, Y.1
Saxena, P.2
Song, D.3
-
24
-
-
33745213901
-
Defending against injection attacks through context-sensitive string evaluation
-
T. Pietraszek and C. V. Berghe. Defending against injection attacks through context-sensitive string evaluation. In RAID 2005.
-
(2005)
RAID
-
-
Pietraszek, T.1
Berghe, C.V.2
-
26
-
-
79960271437
-
-
Technical Report SYR-EECS-2011-09, Syracuse University - Department of Electrical Engineering & Computer Science, July
-
X. Tan, W. Du, T. Luo, and K. D. Soundararaj. Scuta: A server-side access control system for web applications. Technical Report SYR-EECS-2011-09, Syracuse University - Department of Electrical Engineering & Computer Science, July 2011.
-
(2011)
Scuta: A Server-side Access Control System for Web Applications
-
-
Tan, X.1
Du, W.2
Luo, T.3
Soundararaj, K.D.4
-
28
-
-
74049104017
-
Ripley: Automatically securing web 2.0 applications through replicated execution
-
New York, NY, USA, ACM
-
K. Vikram, A. Prateek, and B. Livshits. Ripley: automatically securing web 2.0 applications through replicated execution. In Proceedings of the 16th ACM conference on Computer and communications security, CCS '09, pages 173-186, New York, NY, USA, 2009. ACM.
-
(2009)
Proceedings of the 16th ACM Conference on Computer and Communications Security, CCS '09
, pp. 173-186
-
-
Vikram, K.1
Prateek, A.2
Livshits, B.3
-
29
-
-
84887309913
-
Cross-site scripting prevention with dynamic data tainting and static analysis
-
P. Vogt, F. Nentwich, N. Jovanovic, E. Kirda, C. Kruegel, and G. Vigna. Cross-site scripting prevention with dynamic data tainting and static analysis. In NDSS 2007.
-
(2007)
NDSS
-
-
Vogt, P.1
Nentwich, F.2
Jovanovic, N.3
Kirda, E.4
Kruegel, C.5
Vigna, G.6
-
31
-
-
68549112050
-
-
URL
-
M. Zalewski. Cross-site cooking. URL: http://www.securityfocus.com/ archive/107/423375/30/0/threaded, 2006.
-
(2006)
Cross-site Cooking
-
-
Zalewski, M.1
|