{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T02:32:26Z","timestamp":1743042746986,"version":"3.40.3"},"publisher-location":"Cham","reference-count":35,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030884178"},{"type":"electronic","value":"9783030884185"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-88418-5_4","type":"book-chapter","created":{"date-parts":[[2021,9,29]],"date-time":"2021-09-29T21:04:30Z","timestamp":1632949470000},"page":"67-85","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Caught in the Web: DoS Vulnerabilities in Parsers for Structured Data"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7683-4296","authenticated-orcid":false,"given":"Shawn","family":"Rasheed","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9019-6550","authenticated-orcid":false,"given":"Jens","family":"Dietrich","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9454-1366","authenticated-orcid":false,"given":"Amjed","family":"Tahir","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,9,30]]},"reference":[{"key":"4_CR1","doi-asserted-by":"publisher","unstructured":"Bravenboer, M., Smaragdakis, Y.: Strictly declarative specification of sophisticated points-to analyses. In: Proceedings of the 24th ACM SIGPLAN Conference on Object Oriented Programming Systems Languages and Applications, OOPSLA 2009, Association for Computing Machinery, New York, NY, USA, pp. 243\u2013262 (2009). https:\/\/doi.org\/10.1145\/1640089.1640108","DOI":"10.1145\/1640089.1640108"},{"key":"4_CR2","unstructured":"Breen, S.: What Do WebLogic, WebSphere, JBoss, Jenkins, OpenNMS, and Your Application Have in Common? This Vulnerability (2015). https:\/\/goo.gl\/cx7X4D. Accessed on 08 Oct 2020"},{"key":"4_CR3","doi-asserted-by":"crossref","unstructured":"Burnim, J., Juvekar, S., Sen, K.: WISE: automated test generation for worst-case complexity. In: Proceedings of the ICSE 2009. IEEE (2009)","DOI":"10.1109\/ICSE.2009.5070545"},{"issue":"1","key":"4_CR4","first-page":"146","volume":"1","author":"S Ceri","year":"1989","unstructured":"Ceri, S., Gottlob, G., Tanca, L.: What you always wanted to know about Datalog (and never dared to ask). IEEE TKDE 1(1), 146\u2013166 (1989)","journal-title":"IEEE TKDE"},{"key":"4_CR5","unstructured":"Coekaerts, W.: SerialDOS (2015). https:\/\/gist.github.com\/coekie\/a27cc406fc9f3dc7a70d. Accessed on 08 Oct 2020"},{"key":"4_CR6","unstructured":"CVE-2003-1564 (Billion Laughs) (2003). https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2003-1564. Accessed on 14 Jan 2020"},{"key":"4_CR7","unstructured":"Crosby, S.A., Wallach, D.S.: Denial of service via algorithmic complexity attacks. In: Proceedings of the USENIX Security 2003. USENIX Association (2003)"},{"key":"4_CR8","doi-asserted-by":"crossref","unstructured":"Dietrich, J., Hollingum, N., Scholz, B.: Giga-scale exhaustive points-to analysis for Java in under a minute. In: Proceedings of the OOPSLA 2015. ACM (2015)","DOI":"10.1145\/2814270.2814307"},{"key":"4_CR9","unstructured":"Dietrich, J., Jezek, K., Rasheed, S., Tahir, A., Potanin, A.: Evil Pickles: DoS attacks based on object-graph engineering. In: Proceedings of the ECOOP 2017 (2017)"},{"key":"4_CR10","unstructured":"Frohoff, C., Lawrence, G.: Marshalling Pickles (2015). http:\/\/frohoff.github.io\/appseccali-marshalling-pickles\/. Accessed on 08 Oct 2020"},{"key":"4_CR11","unstructured":"Gamma, E., Vlissides, J., Johnson, R., Helm, R.: Design Patterns: Elements of Reusable Object-oriented Software. Addison-Wesley (1994)"},{"key":"4_CR12","unstructured":"GhostScript: An interpreter for the PostScript language and for PDF (2019). https:\/\/www.ghostscript.com\/. Accessed on 14 Jan 2020"},{"key":"4_CR13","unstructured":"Gosling, J., Joy, B., Steele, G., Brache, G., Buckley, A.: The Java\u00ae Language Specification Java SE 8 Edition (2015). https:\/\/docs.oracle.com\/javase\/specs\/jls\/se8\/jls8.pdf. Accessed on 08 Oct 2020"},{"key":"4_CR14","doi-asserted-by":"crossref","unstructured":"Grech, N., Smaragdakis, Y.: P\/Taint: unified points-to and taint analysis. In: Proceedings of the OOPSLA 2017. ACM (2017)","DOI":"10.1145\/3133926"},{"key":"4_CR15","doi-asserted-by":"crossref","unstructured":"Holland, B., Santhanam, G.R., Awadhutkar, P., Kothari, S.: Statically-informed dynamic analysis tools to detect algorithmic complexity vulnerabilities. In: Proceedings of the SCAM 2016. IEEE (2016)","DOI":"10.1109\/SCAM.2016.23"},{"key":"4_CR16","doi-asserted-by":"crossref","unstructured":"Klees, G., Ruef, A., Cooper, B., Wei, S., Hicks, M.: Evaluating fuzz testing. In: Proceedings of the CCS 2018. ACM (2018)","DOI":"10.1145\/3243734.3243804"},{"key":"4_CR17","doi-asserted-by":"crossref","unstructured":"Lemieux, C., Padhye, R., Sen, K., Song, D.: PerfFuzz: automatically generating pathological inputs. In: Proceedings of the ISSTA 2018. ACM (2018)","DOI":"10.1145\/3213846.3213874"},{"key":"4_CR18","unstructured":"Livshits, V.B., Lam, M.S.: Finding security vulnerabilities in Java applications with static analysis. In: Proceedings of the USENIX Security 2014. USENIX Association (2005)"},{"key":"4_CR19","doi-asserted-by":"crossref","unstructured":"Nistor, A., Song, L., Marinov, D., Lu, S.: Toddler: detecting performance problems via similar memory-access patterns. In: Proceedings of the ICSE 2013. IEEE (2013)","DOI":"10.1109\/ICSE.2013.6606602"},{"key":"4_CR20","doi-asserted-by":"crossref","unstructured":"Noller, Y., Kersten, R., P\u0103s\u0103reanu, C.S.: Badger: complexity analysis with fuzzing and symbolic execution. In: Proceedings of the ISSTA 2018. ACM (2018)","DOI":"10.1145\/3213846.3213868"},{"key":"4_CR21","doi-asserted-by":"crossref","unstructured":"Olivo, O., Dillig, I., Lin, C.: Static detection of asymptotic performance bugs in collection traversals. In: Proceedings of the PLDI 2015. ACM (2015)","DOI":"10.1145\/2737924.2737966"},{"key":"4_CR22","doi-asserted-by":"crossref","unstructured":"Padhye, R., Sen, K.: Travioli: a dynamic analysis for detecting data-structure traversals. In: Proceedings of the ICSE 2017. IEEE (2017)","DOI":"10.1109\/ICSE.2017.50"},{"key":"4_CR23","doi-asserted-by":"publisher","first-page":"289","DOI":"10.1016\/bs.adcom.2018.10.004","volume":"113","author":"CS P\u0103s\u0103reanu","year":"2019","unstructured":"P\u0103s\u0103reanu, C.S., Kersten, R., Luckow, K., Phan, Q.S.: Symbolic execution and recent applications to worst-case execution, load testing, and security analysis. Adv. Comput. 113, 289\u2013314 (2019). https:\/\/doi.org\/10.1016\/bs.adcom.2018.10.004","journal-title":"Adv. Comput."},{"key":"4_CR24","unstructured":"PDF Reference 6th edition (2006). https:\/\/www.adobe.com\/content\/dam\/acom\/en\/devnet\/-pdf\/pdf_reference_archive\/pdf_reference_1-7.pdf. Accessed on 14 Jan 2020"},{"key":"4_CR25","doi-asserted-by":"crossref","unstructured":"Petsios, T., Zhao, J., Keromytis, A.D., Jana, S.: SlowFuzz: automated domain-independent detection of algorithmic complexity vulnerabilities. In: Proceedings of the CCS 2017. ACM (2017)","DOI":"10.1145\/3133956.3134073"},{"key":"4_CR26","doi-asserted-by":"crossref","unstructured":"Rasheed, S., Dietrich, J., Tahir, A.: Laughter in the wild: a study into DoS vulnerabilities in YAML libraries. In: Proceedings of the TrustCom 2019. IEEE (2019)","DOI":"10.1109\/TrustCom\/BigDataSE.2019.00053"},{"key":"4_CR27","doi-asserted-by":"crossref","unstructured":"Scholz, B., Jordan, H., Suboti\u0107, P., Westmann, T.: On fast large-scale program analysis in datalog. In: Proceedings of the 25th International Conference on Compiler Construction, CC 2016, Barcelona, Spain, March 12\u201318, 2016. ACM (2016)","DOI":"10.1145\/2892208.2892226"},{"key":"4_CR28","doi-asserted-by":"crossref","unstructured":"Sridharan, M., Gopan, D., Shan, L., Bod\u00edk, R.: Demand-driven points-to analysis for Java. In: Proceedings of the OOPSLA 2005. ACM (2005)","DOI":"10.1145\/1094811.1094817"},{"key":"4_CR29","unstructured":"Staicu, C.A., Pradel, M.: Freezing the web: a study of ReDoS vulnerabilities in Javascript-based web servers. In: Proceedings of the USENIX Security 2018. USENIX Association (2018)"},{"key":"4_CR30","doi-asserted-by":"crossref","unstructured":"Sundaresan, V., et al.: Practical virtual method call resolution for Java. In: Proceedings of the OOPSLA 2000. ACM (2000)","DOI":"10.1145\/353171.353189"},{"key":"4_CR31","unstructured":"Scalable Vector Graphics (SVG) 1.1, 2nd edn. (2011). https:\/\/www.w3.org\/TR\/SVG11\/REC-SVG11-20110816.pdf. Accessed on 14 Jan 2020"},{"key":"4_CR32","doi-asserted-by":"crossref","unstructured":"Wei, J., Chen, J., Feng, Y., Ferles, K., Dillig, I.: Singularity: pattern fuzzing for worst case complexity. In: Proceedings of the ESEC\/FSE 2018. ACM (2018)","DOI":"10.1145\/3236024.3236039"},{"key":"4_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-662-54580-5_1","volume-title":"Tools and Algorithms for the Construction and Analysis of Systems","author":"V W\u00fcstholz","year":"2017","unstructured":"W\u00fcstholz, V., Olivo, O., Heule, M.J.H., Dillig, I.: Static detection of DoS vulnerabilities in programs that use regular expressions. In: Legay, A., Margaria, T. (eds.) TACAS 2017. LNCS, vol. 10206, pp. 3\u201320. Springer, Heidelberg (2017). https:\/\/doi.org\/10.1007\/978-3-662-54580-5_1"},{"key":"4_CR34","unstructured":"YAML Ain\u2019t Markup Language (YAML) Version 1.2 (2019). https:\/\/yaml.org\/spec\/1.2\/spec.html. Accessed on 08 Oct 2020"},{"key":"4_CR35","doi-asserted-by":"crossref","unstructured":"Yannakakis, M.: Graph-theoretic methods in database theory. In: Proceedings of the PODS 1990. ACM (1990)","DOI":"10.1145\/298514.298576"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2021"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-88418-5_4","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,9,29]],"date-time":"2021-09-29T21:08:46Z","timestamp":1632949726000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-88418-5_4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030884178","9783030884185"],"references-count":35,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-88418-5_4","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"30 September 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Darmstadt","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Germany","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 October 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"8 October 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2021.athene-center.de\/index.php","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"351","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"71","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"20% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.07","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"6.06","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"The conference was held virtually due to the COVID-19 pandemic.","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}