• Documents
  • Authors
  • Tables
  • Log in
  • Sign up
  • MetaCart
  • DMCA
  • Donate

CiteSeerX logo

Advanced Search Include Citations
Advanced Search Include Citations | Disambiguate

DMCA

Static analysis for Ajax intrusion detection (2009)

Cached

  • Download as a PDF

Download Links

  • [www.cs.brown.edu]
  • [www.cs.brown.edu]
  • [cs.brown.edu]
  • [cs.brown.edu]
  • [cs.brown.edu]
  • [trevorjim.com]
  • [www.cs.brown.edu]
  • [www.cs.brown.edu]
  • [cs.brown.edu]
  • [cs.brown.edu]
  • [cs.brown.edu]
  • [people.cs.umass.edu]
  • [people.cs.umass.edu]

  • Save to List
  • Add to Collection
  • Correct Errors
  • Monitor Changes
by Arjun Guha , Shriram Krishnamurthi , Trevor Jim
Venue:In International World Wide Web Conference
Citations:66 - 3 self
  • Summary
  • Citations
  • Active Bibliography
  • Co-citation
  • Clustered Documents
  • Version History

BibTeX

@INPROCEEDINGS{Guha09staticanalysis,
    author = {Arjun Guha and Shriram Krishnamurthi and Trevor Jim},
    title = {Static analysis for Ajax intrusion detection},
    booktitle = {In International World Wide Web Conference},
    year = {2009}
}

Share

Facebook Twitter Reddit Bibsonomy

OpenURL

 

Abstract

We present a static control-flow analysis for JavaScript programs running in a web browser. Our analysis tackles numerous challenges posed by modern web applications including asynchronous communication, frameworks, and dynamic code generation. We use our analysis to extract a model of expected client behavior as seen from the server, and build an intrusion-prevention proxy for the server: the proxy intercepts client requests and disables those that do not meet the expected behavior. We insert random asynchronous requests to foil mimicry attacks. Finally, we evaluate our technique against several real applications and show that it protects against an attack in a widely-used web application.

Keyphrases

ajax intrusion detection    static analysis    client request    mimicry attack    asynchronous communication    modern web application    several real application    dynamic code generation    asynchronous request    numerous challenge    intrusion-prevention proxy    javascript program    static control-flow analysis    web browser    client behavior    widely-used web application   

Powered by: Apache Solr
  • About CiteSeerX
  • Submit and Index Documents
  • Privacy Policy
  • Help
  • Data
  • Source
  • Contact Us

Developed at and hosted by The College of Information Sciences and Technology

© 2007-2019 The Pennsylvania State University