2013 · 19 citations · 15 references
Software SecurityServer Side CodebaseOnline DefenseEngineeringProgram AnalysisInformation SecuritySoftware TestingSecurity TestingSecurity Testing MethodSecure By DesignData PrivacyInformation ForensicsWeb ApplicationSoftware AnalysisData SecurityCryptography
Parameter tampering attacks are dangerous to a web application whose server performs weaker data sanitization than its client. This paper presents TamperProof, a methodology and tool that offers a novel and efficient mechanism to protect Web applications from parameter tampering attacks. TamperProof is an online defense deployed in a trusted environment between the client and server and requires no access to, or knowledge of, the server side codebase, making it effective for both new and legacy applications. The paper reports on experiments that demonstrate TamperProof's power in efficiently preventing all known parameter tampering vulnerabilities on ten different applications.
15
A Symbolic Execution Framework for JavaScript
Prateek Saxena, Devdatta Akhawe, Steve Hanna et al. · 2010 · 450 citations
Secure web applications via automatic partitioning
Stephen Chong, Jed Liu, Andrew C. Myers et al. · 2007 · 242 citations
Preventing Cross Site Request Forgery Attacks
Nenad Jovanović, Engin Kirda, Christopher Kruegel · 2006 · 164 citations
Detecting Manipulated Remote Call Streams
Jonathon Giffin, Somesh Jha, Barton P. Miller · 2002 · 128 citations