A survey on server-side approaches to securing web applications

X Li, Y Xue - ACM Computing Surveys (CSUR), 2014 - dl.acm.org
Web applications are one of the most prevalent platforms for information and service
delivery over the Internet today. As they are increasingly used for critical services, web …

Language-based information-flow security

A Sabelfeld, AC Myers - IEEE Journal on selected areas in …, 2003 - ieeexplore.ieee.org
Current standard security practices do not provide substantial assurance that the end-to-end
behavior of a computing system satisfies important security policies such as confidentiality …

Automatic inference of search patterns for taint-style vulnerabilities

F Yamaguchi, A Maier, H Gascon… - 2015 IEEE Symposium …, 2015 - ieeexplore.ieee.org
Taint-style vulnerabilities are a persistent problem in software development, as the recently
discovered" Heart bleed" vulnerability strikingly illustrates. In this class of vulnerabilities …

[PDF][PDF] Scandroid: Automated security certification of android applications

AP Fuchs, A Chaudhuri, JS Foster - … , Univ. of Maryland, http://www. cs …, 2009 - cs.umd.edu
Android is a popular mobile-device platform developed by Google. Android's application
model is designed to encourage applications to share their code and data with other …

Spectre is here to stay: An analysis of side-channels and speculative execution

R Mcilroy, J Sevcik, T Tebbi, BL Titzer… - arxiv preprint arxiv …, 2019 - arxiv.org
The recent discovery of the Spectre and Meltdown attacks represents a watershed moment
not just for the field of Computer Security, but also of Programming Languages. This paper …

[PDF][PDF] A survey on web application security

X Li, Y Xue - Nashville, TN USA, 2011 - isis.vanderbilt.edu
Web applications are one of the most prevalent platforms for information and services
delivery over Internet today. As they are increasingly used for critical services, web …

JSFlow: Tracking information flow in JavaScript and its APIs

D Hedin, A Birgisson, L Bello, A Sabelfeld - Proceedings of the 29th …, 2014 - dl.acm.org
JavaScript drives the evolution of the web into a powerful application platform. Increasingly,
web applications combine services from different providers. The script inclusion mechanism …

Polyglot: An extensible compiler framework for Java

N Nystrom, MR Clarkson, AC Myers - International Conference on …, 2003 - Springer
Polyglot is an extensible compiler framework that supports the easy creation of compilers for
languages similar to Java, while avoiding code duplication. The Polyglot framework is useful …

Declassification: Dimensions and principles

A Sabelfeld, D Sands - Journal of Computer Security, 2009 - content.iospress.com
Computing systems often deliberately release (or declassify) sensitive information. A
principal security concern for systems permitting information release is whether this release …

Dynamic vs. static flow-sensitive security analysis

A Russo, A Sabelfeld - 2010 23rd IEEE Computer Security …, 2010 - ieeexplore.ieee.org
This paper seeks to answer fundamental questions about trade-offs between static and
dynamic security analysis. It has been previously shown that flow-sensitive static information …