Zhendong Su and Gary Wassermann. The Essence of Command Injection Attacks in Web Applications. POPL 2006.
Nenad Jovanovic, Christopher Kruegel, and Engin Kirda. Pixy: A Static Analysis Tool for Detecting Web Application Vulnerabilities (Short Paper). 2006 IEEE Symposium on Security and Privacy, Oakland, CA, May 2006. [Tech Report]
Philipp Vogt, Florian Nentwich, Nenad Jovanovic, Engin Kirda, Christopher Kruegel, Giovanni Vigna. Cross Site Scripting Prevention with Dynamic Data Tainting and Static Analysis. NDSS 2007.
Nenad Jovanovic, Christopher Kruegel, and Engin Kirda. Precise Alias Analysis for Static Detection of Web Application Vulnerabilities. ACM SIGPLAN Workshop on Programming Languages and Analysis for Security, Ottawa, Canada, June 2006.
Yichen Xie and Alex Aiken. Static Detection of Security Vulnerabilities in Scripting Languages. USENIX Security 2006.
Stefan Kals, Engin Kirda, Christopher Kruegel, Nenad Jovanovic. SecuBat: A Web Vulnerability Scanner. WWW 2006.
Michael Martin, Benjamin Livshits, and Monica S. Lam. Finding Application Errors and Security Flaws Using PQL: a Program Query Language. Conference on Object-Oriented Programming, Systems, Languages, and Applications (OOPSLA), October 2005.
Benjamin Livshits and Monica S. Lam. Finding Security Vulnerabilities in Java Applications with Static Analysis. USENIX Security 2005.
William G.J. Halfond and Jeremy Viegas and Alessandro Orso. A Classification of SQL-Injection Attacks and Countermeasures. International Symposium on Secure Software Engineering 2006.
Yao-Wen Huang, Fang Yu, Christian Hang, Chung-Hung Tsai, Der-Tsai Lee, Sy-Yen Kuo. Securing Web Application Code by Static Analysis and Runtime Protection. 13th International World Wide Web Conference (WWW2004).
Wei Xu, Sandeep Bhatkar, and R. Sekar. Taint-Enhanced Policy Enforcement: A Practical Approach to Defeat a Wide Range of Attacks. USENIX Security 2006.
W. Halfond and A. Orso and P. Manolios. Using Positive Tainting and Syntax-Aware Evaluation to Counter SQL Injection Attacks. ACM SIGSOFT Symposium on the Foundations of Software Engineering (FSE) 2006.
Emre Kiciman and Benjamin Livshits. AjaxScope: A Platform for Remotely Monitoring the Client-Side Behavior of Web 2.0 Applications. SOSP 2007.
Trevor Jim, Nikhil Swamy, Michael Hicks. Defeating Script Injection Attacks with Browser-Enforced Embedded Policies. WWW 2007.
Ulfar Erlingsson, Benjamin Livshits, Yinglian Xie. End-to-end Web Application Security. Hot Topics in Operating Systems, 2007.
Chris Karlof, Umesh Shankar, J. D. Tygar, David Wagner. Dynamic Pharming Attacks and the Locked Same-Origin Policies for Web Browsers. ACM CCS 2007.
Charles Reis, John Dunagan, Helen J. Wang, Opher Dubrovsky, Saher Esmeir. BrowserShield: Vulnerability-Driven Filtering of Dynamic HTML. OSDI 2006.
Benjamin Livshits and Ulfar Erlingsson. Using Web Application Construction Frameworks to Protect Against Code Injection Attacks. Workshop on Programming Languages and Analysis for Security (PLAS 2007), June 2007.
Collin Jackson, Helen Wang. Subspace: Secure Cross-Domain Communication for Web Mashups. WWW 2007.
Raman Kazhamiakin, Marco Pistore, Luca Santuari. Analysis of communication models in web service compositions. WWW 2006. Paul A. Karger. Mashups Legitimize Man-in-the-Middle Attacks (Position Paper). Web 2.0 Security and Privacy Workshop 2007.
K. Vikram and Michael Steiner. Mashup Component Isolation via Server-Side Analysis and Instrumention. Web 2.0 Security and Privacy Workshop 2007.
Ravi Kumar, Jasmine Novak, Bo Pang, Andrew Tomkins. On Anonymizing Query Logs via Token-based Hashing. WWW 2007.
Yabo Xu, Benyu Zhang, Zheng Chen, Ke Wang. Privacy-Enhancing Personalized Web Search. WWW 2007.
S.E. Coull, M.P. Collins, C.V. Wright, F. Monrose, M.K. Reiter. On Web Browsing Privacy in Anonymized NetFlows. USENIX Security 2007.
Umesh Shankar and Chris Karlof. Doppelganger: Better Browser Privacy Without the Bother. CCS 2006.
Collin Jackson, Andrew Bortz, Dan Boneh, John C Mitchell.
Protecting
Browser State from Web Privacy Attacks. WWW 2006.
Threats
Threat Assessment
Yi-Min Wang, Doug Beck, Xuxian Jiang, Roussi Roussev, Chad Verbowski,
Shuo Chen, and Sam King. Automated
Web Patrol with Strider HoneyMonkeys: Finding Web Sites That Exploit
Browser Vulnerabilities. NDSS 2006.
Niels Provos, Dean McNamee, Panayiotis Mavrommatis, Ke Wang and Nagendra Modadugu. The Ghost In The Browser: Analysis of Web-based Malware. HotBots 2007.
V. T. Lam, S. Antonatos, P. Akritidis, and K. G.. Anagnostakis. Puppetnets: Misusing Web Browsers as a Distributed Attack Infrastructure. CCS 2006.
Jason Franklin, Vern Paxson, Adrian Perrig, and Stefan Savage. An Inquiry into the Nature and Causes of the Wealth of Internet Miscreants. CCS 2007.
Yi-Min Wang, Ming Ma, Yuan Niu, Hao Chen. Spam Double-Funnel: Connecting Web Spammers with Advertisers. WWW 2007.
Y. Niu, Y. M. Wang, H. Chen, M. Ma, and F. Hsu. A Quantitative Study of Forum Spamming Using Context-based Analysis. NDSS 2007.
David S. Anderson, Chris Fleizach, Stefan Savage, and Geoffrey M. Voelker. Spamscatter: Characterizing Internet Scam Hosting Infrastructure. USENIX Security 2007.
Baoning Wu, Brian D. Davison. Detecting Semantic Cloaking on the Web. WWW 2006.
Alexandros Ntoulas, Marc Najork, Mark Manasse, Dennis Fetterly. Detecting Spam Web Pages through Content Analysis. WWW 2006.
Ian Fette, Norman Sadeh, Anthony Tomasic. Learning to Detect Phishing Emails . WWW 2007.
Markus Jakobsson, Jacob Ratkiewicz. Designing ethical phishing experiments: a study of (ROT13) rOnl query features. WWW 2006.
Ahmed Metwally, Divyakant Agrawal, Amr El Abbadi. DETECTIVES: DETEcting Coalition hiT Inflation attacks in adVertising nEtworks Streams. WWW 2007.
Neil Daswani, Michael Stoppelman, and the Google Click Quality and Security Teams. The Anatomy of Clickbot.A. HotBots 2007.
Ari Juels, Sid Stamm, Markus Jakobsson. Combating Click Fraud via Premium Clicks. USENIX Security 2007.