中文
相关论文

相关论文: CORSICA: Cross-Origin Web Service Identification

200 篇论文

The use of passwords and the need to protect passwords are not going away. The majority of websites that require authentication continue to support password authentication. Even high-security applications such as Internet Banking portals,…

网络与互联网体系结构 · 计算机科学 2020-11-13 Teik Guan Tan , Pawel Szalachowski , Jianying Zhou

The recent October 2016 DDoS attack on Dyn served as a wakeup call to the security community as many popular and independent webservices (e.g., Twitter, Spotify) were impacted. This incident raises a larger question on the fragility of…

网络与互联网体系结构 · 计算机科学 2018-06-25 Aqsa Kashaf , Carolina Zarate , Hanrou Wang , Yuvraj Agarwal , Vyas Sekar

Cross Site Scripting (XSS) is one of the most critical vulnerabilities exist in web applications. XSS can be prevented by encoding untrusted data that are loaded into browser content of web applications. Security Application Programming…

密码学与安全 · 计算机科学 2018-10-03 Chamila Wijayarathna , Nalin Asanka Gamagedara Arachchilage

Mini-programs, an emerging mobile application paradigm within super-apps, offer a seamless and installation-free experience. However, the adoption of the web-view component has disrupted their isolation mechanisms, exposing new attack…

密码学与安全 · 计算机科学 2025-10-29 Miao Zhang , Shenao Wang , Guilin Zheng , Yanjie Zhao , Haoyu Wang

Proxy servers are being increasingly deployed at organizations for performance benefits; however, there still exists drawbacks in ease of client authentication in interception proxy mode mainly for Open Source Proxy Servers. Technically, an…

网络与互联网体系结构 · 计算机科学 2013-02-19 Tejaswi Agarwal , Mike A. Leonetti

Phishing websites continue to pose a significant security challenge, making the development of robust detection mechanisms essential. Brand Domain Identification (BDI) serves as a crucial step in many phishing detection approaches. This…

密码学与安全 · 计算机科学 2025-03-11 Rina Mishra , Gaurav Varshney

A cyber-attack is a malicious attempt by experienced hackers to breach the target information system. Usually, the cyber-attacks are characterized as hybrid TTPs (Tactics, Techniques, and Procedures) and long-term adversarial behaviors,…

密码学与安全 · 计算机科学 2021-12-17 Mingqi Lv , Chengyu Dong , Tieming Chen , Tiantian Zhu , Qijie Song , Yuan Fan

This paper presents DeepTective, a deep learning approach to detect vulnerabilities in PHP source code. Our approach implements a novel hybrid technique that combines Gated Recurrent Units and Graph Convolutional Networks to detect SQLi,…

密码学与安全 · 计算机科学 2023-06-21 Rishi Rabheru , Hazim Hanif , Sergio Maffeis

The adoption of WebAssembly has rapidly increased in the last few years as it provides a fast and safe model for program execution. However, WebAssembly is not exempt from vulnerabilities that could be exploited by side channels attacks.…

Today, Online Social Networks such as Facebook, LinkedIn and Twitter are the most popular platforms on the Internet, on which millions of users register to share personal information with their friends. A large amount of data, social links…

密码学与安全 · 计算机科学 2014-07-01 Morteza Yousefi Kharaji , Fatemeh Salehi Rizi , Mohammad Reza Khayyambashi

Mobile crowdsourcing services (MCS), enable fast and economical data acquisition at scale and find applications in a variety of domains. Prior work has shown that Foursquare and Waze (a location-based and a navigation MCS) are vulnerable to…

密码学与安全 · 计算机科学 2021-10-20 Sojhal Ismail Khan , Dominika Woszczyk , Chengzeng You , Soteris Demetriou , Muhammad Naveed

SQL injection attacks, a class of injection flaw in which specially crafted input strings leads to illegal queries to databases, are one of the topmost threats to web applications. A Number of research prototypes and commercial products…

数据库 · 计算机科学 2015-04-28 Swapnil Kharche , Jagdish patil , Kanchan Gohad , Bharti Ambetkar

Industrial control systems are a fundamental component of critical infrastructure networks (CIN) such as gas, water and power. With the growing risk of cyberattacks, regulatory compliance requirements are also increasing for large scale…

密码学与安全 · 计算机科学 2025-11-18 Paritosh Ramanan , H. M. Mohaimanul Islam , Abhiram Reddy Alugula

If two or more identical HTTPS clients, located at different geographic locations (regions), make an HTTPS request to the same domain (e.g. example.com), on the same day, will they receive the same HTTPS security guarantees in response? Our…

密码学与安全 · 计算机科学 2020-10-21 Eman Salem Alashwali , Pawel Szalachowski , Andrew Martin

There are many scenarios in which inferring the type of a client browser is desirable, for instance to fight against session stealing. This is known as browser fingerprinting. This paper presents and evaluates a novel fingerprinting…

密码学与安全 · 计算机科学 2012-11-21 Erwan Abgrall , Yves Le Traon , Martin Monperrus , Sylvain Gombault , Mario Heiderich , Alain Ribault

Access control is a security mechanism designed to ensure that only authorized users can access specific resources. Cross-domain access control involves access to resources across different organizations, institutions, or applications.…

密码学与安全 · 计算机科学 2025-12-01 Aiyao Zhang , Xiaodong Lee , Zhixian Zhuang , Jiuqi Wei , Yufan Fu , Botao Peng

Website fingerprinting enables an attacker to infer which web page a client is browsing through encrypted or anonymized network connections. We present a new website fingerprinting technique based on random decision forests and evaluate…

密码学与安全 · 计算机科学 2016-02-22 Jamie Hayes , George Danezis

The decentralized and unregulated nature of cryptocurrencies, combined with their monetary value, has made them a vehicle for various illicit activities. One such activity is cryptojacking, an attack that uses stolen computing resources to…

密码学与安全 · 计算机科学 2025-05-06 Tanapoom Sermchaiwong , Jiasi Shen

This paper conducts a comprehensive examination of the infrastructure supporting cryptojacking operations. The analysis elucidates the methodologies, frameworks, and technologies malicious entities employ to misuse computational resources…

密码学与安全 · 计算机科学 2024-08-08 Ayodeji Adeniran , Kieran Human , David Mohaisen

Conforming to W3C specifications, mobile web browsers allow JavaScript code in a web page to access motion and orientation sensor data without the user's permission. The associated risks to user security and privacy are however not…

密码学与安全 · 计算机科学 2016-05-04 Maryam Mehrnezhad , Ehsan Toreini , Siamak F. Shahandashti , Feng Hao