中文
相关论文

相关论文: Securing the Web: Analysis of HTTP Security Header…

200 篇论文

The increasing reliance on web services has led to a rise in cybersecurity threats, particularly Cross-Site Scripting (XSS) attacks, which target client-side layers of web applications by injecting malicious scripts. Traditional Web…

密码学与安全 · 计算机科学 2025-04-14 Vahid Babaey , Arun Ravindran

With the growing of network technology along with the need of human for social interaction, using websites nowadays becomes critically important which leads in the increasing number of websites and servers. One popular solution for managing…

密码学与安全 · 计算机科学 2018-11-05 Seyed Ali Mirheidari , Sajjad Arshad , Saeidreza Khoshkdahan , Rasool Jalili

Cross Site Scripting (XSS) Flaws are currently the most popular security problems in modern web applications. These Flaws make use of vulnerabilities in the code of web-applications, resulting in serious consequences, such as theft of…

密码学与安全 · 计算机科学 2010-04-13 K. Selvamani , A. Duraisamy , A. Kannan

The large-scale deployment of modern phishing attacks relies on the automatic exploitation of vulnerable websites in the wild, to maximize profit while hindering attack traceability, detection and blacklisting. To the best of our knowledge,…

密码学与安全 · 计算机科学 2017-07-04 Igino Corona , Battista Biggio , Matteo Contini , Luca Piras , Roberto Corda , Mauro Mereu , Guido Mureddu , Davide Ariu , Fabio Roli

Unsafe websites consist of malicious as well as inappropriate sites, such as those hosting questionable or offensive content. Website reputation systems are intended to help ordinary users steer away from these unsafe sites. However, the…

密码学与安全 · 计算机科学 2015-04-21 Sourav Bhattacharya , Otto Huhta , N. Asokan

Single-factor password-based authentication is generally the norm to access on-line Web-sites. While single-factor authentication is well known to be a weak form of authentication, a further concern arises when considering the possibility…

密码学与安全 · 计算机科学 2020-01-30 Simone Raponi , Roberto Di Pietro

Most TLS clients such as modern web browsers enforce coarse-grained TLS security configurations. They support legacy versions of the protocol that have known design weaknesses, and weak ciphersuites that provide fewer security guarantees…

密码学与安全 · 计算机科学 2018-09-18 Eman Salem Alashwali , Pawel Szalachowski

Service Workers (SWs) are a powerful feature at the core of Progressive Web Apps, namely web applications that can continue to function when the user's device is offline and that have access to device sensors and capabilities previously…

密码学与安全 · 计算机科学 2024-09-02 Karthika Subramani , Jordan Jueckstock , Alexandros Kapravelos , Roberto Perdisci

Many cyberattacks succeed because they exploit flaws at the human level. To address this problem, organizations rely on security awareness programs, which aim to make employees more resilient against social engineering. While some works…

密码学与安全 · 计算机科学 2025-12-01 Matthias Pfister , Giovanni Apruzzese , Irdin Pekaric

Secure communication is an integral feature of many Internet services. The widely deployed TLS protects reliable transport protocols. DTLS extends TLS security services to protocols relying on plain UDP packet transport, such as VoIP or IoT…

网络与互联网体系结构 · 计算机科学 2019-04-26 Sebastian Gallenmüller , Dominik Schöffmann , Dominik Scholz , Fabien Geyer , Georg Carle

Detection and mitigation of critical web vulnerabilities and attacks like cross-site scripting (XSS), and cross-site request forgery (CSRF) have been a great concern in the field of web security. Such web attacks are evolving and becoming…

密码学与安全 · 计算机科学 2023-05-01 Mahnoor Shahid

Several encryption proposals for DNS have been presented since 2016, but their adoption was not comprehensively studied yet. This research measured the current adoption of DoH (DNS over HTTPS), DoT (DNS over TLS), and DoQ (DNS over QUIC)…

密码学与安全 · 计算机科学 2021-07-12 Sebastián García , Karel Hynek , Dmtrii Vekshin , Tomáš Čejka , Armin Wasicek

Large language models (LLMs) are increasingly deployed through open-source and commercial frameworks, enabling individuals and organizations to self-host advanced LLM capabilities. As LLM deployments become prevalent, particularly in…

密码学与安全 · 计算机科学 2025-08-27 Xinyi Hou , Jiahao Han , Yanjie Zhao , Haoyu Wang

DNS over TLS (DoT) and DNS over HTTPS (DoH) encrypt DNS to guard user privacy by hiding DNS resolutions from passive adversaries. Yet, past attacks have shown that encrypted DNS is still sensitive to traffic analysis. As a consequence, RFC…

密码学与安全 · 计算机科学 2019-07-03 Jonas Bushart , Christian Rossow

Algorithmic complexity vulnerabilities are a class of security problems that enables attackers to trigger the worst-case complexity of certain algorithms. Such vulnerabilities can be leveraged to deploy low-volume, asymmetric, CPU-based…

密码学与安全 · 计算机科学 2022-11-22 Masudul Hasan Masud Bhuiyan , Cristian-Alexandru Staicu

The rapid adoption of Web3 infrastructures has led to a growing number of security incidents affecting cryptocurrency exchanges, custody services and blockchain-based platforms. While existing research predominantly focuses on…

密码学与安全 · 计算机科学 2026-05-20 Tarkan Yavas , Arslan Brömme

Recent multi-media data such as images and videos have been rapidly spread out on various online services such as social network services (SNS). With the explosive growth of online media services, the number of image content that may harm…

计算机视觉与模式识别 · 计算机科学 2023-10-10 Eungyeom Ha , Heemook Kim , Sung Chul Hong , Dongbin Na

Web attacks, i.e. attacks exclusively using the HTTP protocol, are rapidly becoming one of the fundamental threats for information systems connected to the Internet. When the attacks suffered by web servers through the years are analyzed,…

密码学与安全 · 计算机科学 2007-05-23 Gonzalo Alvarez , Slobodan Petrovic

Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks have emerged as a popular means of causing collection particular overhaul disruptions, often for total periods of instance. The relative ease and low costs of…

密码学与安全 · 计算机科学 2013-02-22 Saravanan Kumarasamy , Dr. R. Asokan

Domain name system communication may provide sensitive information on users' Internet activity. DNS-over-TLS and DNS-over-HTTPS are proposals aiming at increasing the privacy of Internet end users. In this paper we present an overview of…

网络与互联网体系结构 · 计算机科学 2022-04-11 Kamil Jerabek , Ondrej Rysavy , Ivana Burgetova