89 citations · 89 across the 8 of their papers we have counts for
6 papers · 1 filter
User Profiles: The Achilles' Heel of Web Browsers
Dolière Francis Somé, Moaz Airan, Zakir Durumeric +1
Web browsers provide the security foundation for our online experiences. Significant research has been done into the security of browsers themselves, but relatively little investig…
SoK: A Literature and Engineering Review of Regular Expression Denial of Service (ReDoS)
Masudul Hasan Masud Bhuiyan, Berk Çakar, Ethan H. Burmane +2
Regular Expression Denial of Service (ReDoS) is a vulnerability class that has become prominent in recent years. Attackers can weaponize such weaknesses as part of asymmetric cyber…
A Tale of Frozen Clouds: Quantifying the Impact of Algorithmic Complexity Vulnerabilities in Popular Web Servers
Masudul Hasan Masud Bhuiyan, Cristian-Alexandru Staicu
Algorithmic complexity vulnerabilities are a class of security problems that enables attackers to trigger the worst-case complexity of certain algorithms. Such vulnerabilities can…
Mir: Automated Quantifiable Privilege Reduction Against Dynamic Library Compromise in JavaScript
Nikos Vasilakis, Cristian-Alexandru Staicu, Grigoris Ntousakis +4
Third-party libraries ease the development of large-scale software systems. However, they often execute with significantly more privilege than needed to complete their task. This a…
An Empirical Study of Information Flows in Real-World JavaScript
Cristian-Alexandru Staicu, Daniel Schoepe, Musard Balliu +2
Information flow analysis prevents secret or untrusted data from flowing into public or trusted sinks. Existing mechanisms cover a wide array of options, ranging from lightweight t…
Small World with High Risks: A Study of Security Threats in the npm Ecosystem
Markus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny +1
The popularity of JavaScript has lead to a large ecosystem of third-party packages available via the npm software package registry. The open nature of npm has boosted its growth, p…