Current state of research on cross-site scripting (XSS)–A systematic literature review

I Hydara, ABM Sultan, H Zulzalil… - Information and Software …, 2015 - Elsevier
Context Cross-site scripting (XSS) is a security vulnerability that affects web applications. It
occurs due to improper or lack of sanitization of user inputs. The security vulnerability …

A survey on server-side approaches to securing web applications

X Li, Y Xue - ACM Computing Surveys (CSUR), 2014 - dl.acm.org
Web applications are one of the most prevalent platforms for information and service
delivery over the Internet today. As they are increasingly used for critical services, web …

A symbolic execution framework for javascript

P Saxena, D Akhawe, S Hanna, F Mao… - … IEEE Symposium on …, 2010 - ieeexplore.ieee.org
As AJAX applications gain popularity, client-side JavaScript code is becoming increasingly
complex. However, few automated vulnerability analysis tools for JavaScript exist. In this …

The devil is in the (implementation) details: an empirical analysis of OAuth SSO systems

ST Sun, K Beznosov - Proceedings of the 2012 ACM conference on …, 2012 - dl.acm.org
Millions of web users today employ their Facebook accounts to sign into more than one
million relying party (RP) websites. This web-based single sign-on (SSO) scheme is enabled …

Towards a formal foundation of web security

D Akhawe, A Barth, PE Lam, J Mitchell… - 2010 23rd IEEE …, 2010 - ieeexplore.ieee.org
We propose a formal model of web security based on an abstraction of the web platform and
use this model to analyze the security of several sample web mechanisms and applications …

Site isolation: Process separation for web sites within the browser

C Reis, A Moshchuk, N Oskov - 28th USENIX Security Symposium …, 2019 - usenix.org
Current production web browsers are multi-process but place different web sites in the same
renderer process, which is not sufficient to mitigate threats present on the web today. With …

[KIRJA][B] Digital preservation for libraries, archives, and museums

EM Corrado, HM Sandy - 2017 - books.google.com
This new edition of Digital Preservation in Libraries, Archives, and Museums is the most
current, complete guide to digital preservation available today. For administrators and …

Building web applications on top of encrypted data using Mylar

RA Popa, E Stark, S Valdez, J Helfer… - … USENIX Symposium on …, 2014 - usenix.org
Web applications rely on servers to store and process confidential information. However,
anyone who gains access to the server (eg, an attacker, a curious administrator, or a …

[PDF][PDF] FLAX: Systematic Discovery of Client-side Validation Vulnerabilities in Rich Web Applications.

P Saxena, S Hanna, P Poosankam, D Song - NDss, 2010 - vividmachines.com
The complexity of the client-side components of web applications has exploded with the
increase in popularity of web 2.0 applications. Today, traditional desktop applications, such …

A systematic analysis of XSS sanitization in web application frameworks

J Weinberger, P Saxena, D Akhawe, M Finifter… - … –ESORICS 2011: 16th …, 2011 - Springer
While most research on XSS defense has focused on techniques for securing existing
applications and re-architecting browser mechanisms, sanitization remains the industry …