-
1
-
-
67449088776
-
Securing frame communication in browsers
-
June
-
A. Barth, C. Jackson, and J. C. Mitchell. Securing frame communication in browsers. Commun. ACM, 52:83-91, June 2009.
-
(2009)
Commun. ACM
, vol.52
, pp. 83-91
-
-
Barth, A.1
Jackson, C.2
Mitchell, J.C.3
-
4
-
-
84861642854
-
Security of web mashups: A survey
-
Springer
-
P. De Ryck, M. Decat, L. Desmet, F. Piessens, and W. Joosen. Security of web mashups: a survey. In 15th Nordic Conference in Secure IT Systems (NordSec 2010). Springer, 2011.
-
(2011)
15th Nordic Conference in Secure IT Systems (NordSec 2010)
-
-
De Ryck, P.1
Decat, M.2
Desmet, L.3
Piessens, F.4
Joosen, W.5
-
5
-
-
77949443194
-
Csfire: Transparent client-side mitigation of malicious cross-domain requests
-
Springer Berlin / Heidelberg, February
-
P. De Ryck, L. Desmet, T. Heyman, F. Piessens, and W. Joosen. Csfire: Transparent client-side mitigation of malicious cross-domain requests. In Lecture Notes in Computer Science, volume 5965, pages 18-34. Springer Berlin / Heidelberg, February 2010.
-
(2010)
Lecture Notes in Computer Science
, vol.5965
, pp. 18-34
-
-
De Ryck, P.1
Desmet, L.2
Heyman, T.3
Piessens, F.4
Joosen, W.5
-
6
-
-
80053028570
-
Automatic and precise client-side protection against csrf attacks
-
V. Atluri and C. Diaz, editors, Computer Security - ESORICS 2011. Springer Berlin / Heidelberg
-
P. De Ryck, L. Desmet, W. Joosen, and F. Piessens. Automatic and precise client-side protection against csrf attacks. In V. Atluri and C. Diaz, editors, Computer Security - ESORICS 2011, volume 6879 of Lecture Notes in Computer Science, pages 100-116. Springer Berlin / Heidelberg, 2011.
-
(2011)
Lecture Notes in Computer Science
, vol.6879
, pp. 100-116
-
-
De Ryck, P.1
Desmet, L.2
Joosen, W.3
Piessens, F.4
-
7
-
-
84855661931
-
A security analysis of next generation web standards. Technical report
-
G. Hogben and M. Dekker (Eds.), July
-
P. De Ryck, L. Desmet, P. Philippaerts, and F. Piessens. A security analysis of next generation web standards. Technical report, G. Hogben and M. Dekker (Eds.), European Network and Information Security Agency (ENISA), July 2011.
-
(2011)
European Network and Information Security Agency (ENISA)
-
-
De Ryck, P.1
Desmet, L.2
Philippaerts, P.3
Piessens, F.4
-
10
-
-
62949235946
-
Talking to strangers without taking their candy: Isolating proxied content
-
New York, NY, USA. ACM
-
A. Felt, P. Hooimeijer, D. Evans, and W. Weimer. Talking to strangers without taking their candy: isolating proxied content. In SocialNets '08: Proceedings of the 1st Workshop on Social Network Systems, pages 25-30, New York, NY, USA, 2008. ACM.
-
(2008)
SocialNets '08: Proceedings of the 1st Workshop on Social Network Systems
, pp. 25-30
-
-
Felt, A.1
Hooimeijer, P.2
Evans, D.3
Weimer, W.4
-
11
-
-
84855661932
-
-
Google. Google Latitude. https://www.google.com/latitude/.
-
-
-
-
12
-
-
84890883068
-
Gatekeeper: Mostly static enforcement of security and reliability policies for javascript code
-
Aug
-
S. Guarnieri and B. Livshits. Gatekeeper: Mostly static enforcement of security and reliability policies for javascript code. In Proceedings of the Usenix Security Symposium, Aug. 2009.
-
(2009)
Proceedings of the Usenix Security Symposium
-
-
Guarnieri, S.1
Livshits, B.2
-
14
-
-
84855700024
-
-
Involver
-
Involver. Tweets To Pages. http://www.facebook.com/TweetsApp.
-
-
-
-
15
-
-
84855661935
-
-
Jacaranda
-
Jacaranda. Jacaranda. http://jacaranda.org.
-
-
-
-
16
-
-
35348860223
-
Defeating script injection attacks with browser-enforced embedded policies
-
DOI 10.1145/1242572.1242654, 16th International World Wide Web Conference, WWW2007
-
T. Jim, N. Swamy, and M. Hicks. Defeating Script Injection Attacks with Browser-Enforced Embedded Policies. In WWW '07: Proceedings of the 16th international conference on World Wide Web, pages 601-610, New York, NY, USA, 2007. ACM. (Pubitemid 47582289)
-
(2007)
16th International World Wide Web Conference, WWW2007
, pp. 601-610
-
-
Jim, T.1
Swamy, N.2
Hicks, M.3
-
17
-
-
77956566246
-
Mash-if: Practical information-flow control within client-side mashups
-
28 2010-july 1
-
Z. Li, K. Zhang, and X. Wang. Mash-if: Practical information-flow control within client-side mashups. In Dependable Systems and Networks (DSN), 2010 IEEE/IFIP International Conference on, pages 251 -260, 28 2010-july 1 2010.
-
(2010)
Dependable Systems and Networks (DSN), 2010 IEEE/IFIP International Conference on
, pp. 251-260
-
-
Li, Z.1
Zhang, K.2
Wang, X.3
-
18
-
-
77954492783
-
A lattice-based approach to mashup security
-
New York, NY, USA. ACM
-
J. Magazinius, A. Askarov, and A. Sabelfeld. A lattice-based approach to mashup security. In Proceedings of the 5th ACM Symposium on Information, Computer and Communications Security, ASIACCS '10, pages 15-23, New York, NY, USA, 2010. ACM.
-
(2010)
Proceedings of the 5th ACM Symposium on Information, Computer and Communications Security, ASIACCS '10
, pp. 15-23
-
-
Magazinius, J.1
Askarov, A.2
Sabelfeld, A.3
-
20
-
-
84855675152
-
-
G. Maone. Noscript 2.0.9.9. http://noscript.net/, 2011.
-
(2011)
-
-
Maone, G.1
-
21
-
-
77955186827
-
ConScript: Specifying and enforcing fine-grained security policies for Javascript in the browser
-
May
-
L. Meyerovich and B. Livshits. ConScript: Specifying and enforcing fine-grained security policies for Javascript in the browser. In IEEE Symposium on Security and Privacy, May 2010.
-
(2010)
IEEE Symposium on Security and Privacy
-
-
Meyerovich, L.1
Livshits, B.2
-
23
-
-
70349127409
-
-
Technical report, Google Inc., June
-
M. S. Miller, M. Samuel, B. Laurie, I. Awad, and M. Stay. Caja - safe active content in sanitized JavaScript. Technical report, Google Inc., June 2008.
-
(2008)
Caja - Safe Active Content in Sanitized JavaScript
-
-
Miller, M.S.1
Samuel, M.2
Laurie, B.3
Awad, I.4
Stay, M.5
-
24
-
-
77952327855
-
Lightweight self-protecting javascript
-
New York, NY, USA. ACM
-
P. H. Phung, D. Sands, and A. Chudnov. Lightweight self-protecting javascript. In Proceedings of the 4th International Symposium on Information, Computer, and Communications Security, ASIACCS '09, pages 47-60, New York, NY, USA, 2009. ACM.
-
(2009)
Proceedings of the 4th International Symposium on Information, Computer, and Communications Security, ASIACCS '09
, pp. 47-60
-
-
Phung, P.H.1
Sands, D.2
Chudnov, A.3
-
26
-
-
85076780225
-
BrowserShield: Vulnerability-driven filtering of dynamic HTML
-
Berkeley, CA, USA. USENIX Association
-
C. Reis, J. Dunagan, H. J. Wang, O. Dubrovsky, and S. Esmeir. BrowserShield: vulnerability-driven filtering of dynamic HTML. In OSDI '06: Proceedings of the 7th symposium on Operating systems design and implementation, pages 61-74, Berkeley, CA, USA, 2006. USENIX Association.
-
(2006)
OSDI ' 06: Proceedings of the 7th Symposium on Operating Systems Design and Implementation
, pp. 61-74
-
-
Reis, C.1
Dunagan, J.2
Wang, H.J.3
Dubrovsky, O.4
Esmeir, S.5
-
27
-
-
84855661941
-
-
J. Ruderman. Configurable Security Policies. http://www.mozilla.org/ projects/security/components/ConfigPolicy.html.
-
-
-
Ruderman, J.1
-
28
-
-
84855655942
-
-
J. Samuel. Requestpolicy 0.5.20. http://www.requestpolicy.com, 2011.
-
(2011)
-
-
Samuel, J.1
-
29
-
-
77954584716
-
Reining in the web with content security policy
-
New York, NY, USA. ACM
-
S. Stamm, B. Sterne, and G. Markham. Reining in the web with content security policy. In Proceedings of the 19th international conference on World wide web, WWW '10, pages 921-930, New York, NY, USA, 2010. ACM.
-
(2010)
Proceedings of the 19th International Conference on World Wide Web, WWW '10
, pp. 921-930
-
-
Stamm, S.1
Sterne, B.2
Markham, G.3
-
30
-
-
84907402135
-
Adjail: Practical enforcement of confidentiality and integrity policies on web advertisements
-
Aug
-
M. Ter Louw, K. T. Ganesh, and V. Venkatakrishnan. Adjail: Practical enforcement of confidentiality and integrity policies on web advertisements. In 19th USENIX Security Symposium, Aug. 2010.
-
(2010)
19th USENIX Security Symposium
-
-
Ter Louw, M.1
Ganesh, K.T.2
Venkatakrishnan, V.3
-
31
-
-
84855661938
-
-
The FaceBook Team. FBJS. http://wiki.developers.facebook.com/index.php/ FBJS.
-
-
-
-
32
-
-
84855655939
-
-
W3C. W3C Standards and drafts - Javascript APIs. http://www.w3.org/TR/ #tr-Javascript-APIs.
-
-
-
-
33
-
-
84855700027
-
-
Willem De Groef. ConScript For Firefox. http://cqrit.be/conscript/.
-
-
-
De Groef, W.1
|