activity
20182022
most citedCoding Practices and Recommendations of Spring Security for Enterprise Applications

3 citations · 3 across the 2 of their papers we have counts for

collaborators

5 papers

cs.PL2022

Automatic Root Cause Quantification for Missing Edges in JavaScript Call Graphs (Extended Version)

Madhurima Chakraborty, Renzo Olivares, Manu Sridharan +1

Building sound and precise static call graphs for real-world JavaScript applications poses an enormous challenge, due to many hard-to-analyze language features. Further, the relati…

cs.CR2021

BackREST: A Model-Based Feedback-Driven Greybox Fuzzer for Web Applications

François Gauthier, Behnaz Hassanshahi, Benjamin Selwyn-Smith +3

Following the advent of the American Fuzzy Lop (AFL), fuzzing had a surge in popularity, and modern day fuzzers range from simple blackbox random input generators to complex whiteb…

cs.CR20203 cited

Coding Practices and Recommendations of Spring Security for Enterprise Applications

Mazharul Islam, Sazzadur Rahaman, Na Meng +4

Spring security is tremendously popular among practitioners for its ease of use to secure enterprise applications. In this paper, we study the application framework misconfiguratio…

cs.SE2020

Gelato: Feedback-driven and Guided Security Analysis of Client-side Web Applications

Behnaz Hassanshahi, Hyunjun Lee, Paddy Krishnan +1

Even though a lot of effort has been invested in analyzing client-side web applications during the past decade, the existing tools often fail to deal with the complexity of modern…

cs.CR2018

SAFE-PDF: Robust Detection of JavaScript PDF Malware Using Abstract Interpretation

Alexander Jordan, François Gauthier, Behnaz Hassanshahi +1

The popularity of the PDF format and the rich JavaScript environment that PDF viewers offer make PDF documents an attractive attack vector for malware developers. PDF documents pre…