{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,9]],"date-time":"2026-06-09T15:47:00Z","timestamp":1781020020363,"version":"3.54.1"},"publisher-location":"Cham","reference-count":41,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031541285","type":"print"},{"value":"9783031541292","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-54129-2_26","type":"book-chapter","created":{"date-parts":[[2024,3,11]],"date-time":"2024-03-11T22:03:15Z","timestamp":1710194595000},"page":"442-458","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Finding Server-Side Endpoints with\u00a0Static Analysis of\u00a0Client-Side JavaScript"],"prefix":"10.1007","author":[{"given":"Daniil","family":"Sigalov","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dennis","family":"Gamayunov","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,3,12]]},"reference":[{"issue":"1","key":"26_CR1","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1145\/3477133.3477134","volume":"21","author":"M Leithner","year":"2021","unstructured":"Leithner, M., Simos, D.E.: CHIEv: concurrent hybrid analysis for crawling and modeling of web applications. ACM SIGAPP Appl. Comput. Rev. 21(1), 5\u201323 (2021)","journal-title":"ACM SIGAPP Appl. Comput. Rev."},{"key":"26_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"111","DOI":"10.1007\/978-3-642-14215-4_7","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"A Doup\u00e9","year":"2010","unstructured":"Doup\u00e9, A., Cova, M., Vigna, G.: Why Johnny Can\u2019t Pentest: an analysis of black-box web vulnerability scanners. In: Kreibich, C., Jahnke, M. (eds.) DIMVA 2010. LNCS, vol. 6201, pp. 111\u2013131. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-14215-4_7"},{"issue":"1\/2","key":"26_CR3","first-page":"12","volume":"12","author":"M Rennhard","year":"2019","unstructured":"Rennhard, M., Esposito, D., Ruf, L., Wagner, A.: Improving the effectiveness of web application vulnerability scanning. Int. J. Adv. Internet Technol. 12(1\/2), 12\u201327 (2019)","journal-title":"Int. J. Adv. Internet Technol."},{"issue":"1","key":"26_CR4","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2109205.2109208","volume":"6","author":"A Mesbah","year":"2012","unstructured":"Mesbah, A., Van Deursen, A., Lenselink, S.: Crawling Ajax-based web applications through dynamic analysis of user interface state changes. ACM Trans. Web (TWEB) 6(1), 1\u201330 (2012)","journal-title":"ACM Trans. Web (TWEB)"},{"key":"26_CR5","doi-asserted-by":"crossref","unstructured":"Leithner, M., Simos, D.E.: XIEv: dynamic analysis for crawling and modeling of web applications. In: Proceedings of the 35th Annual ACM Symposium on Applied Computing, pp. 2201\u20132210 (2020)","DOI":"10.1145\/3341105.3373885"},{"key":"26_CR6","doi-asserted-by":"crossref","unstructured":"Guha, A., Krishnamurthi, S., Jim, T.: Using static analysis for Ajax intrusion detection. In: Proceedings of the 18th international conference on World wide web, pp. 561\u2013570 (2009)","DOI":"10.1145\/1526709.1526785"},{"key":"26_CR7","unstructured":"Arachni Framework version 1.6.1.3-0.6.1.1. https:\/\/github.com\/Arachni\/arachni. Accessed 1 Jul 2023"},{"key":"26_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"295","DOI":"10.1007\/978-3-319-26362-5_14","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"G Pellegrino","year":"2015","unstructured":"Pellegrino, G., Tsch\u00fcrtz, C., Bodden, E., Rossow, C.: j\u00c4k: using dynamic analysis to crawl and test modern web applications. In: Bos, H., Monrose, F., Blanc, G. (eds.) RAID 2015. LNCS, vol. 9404, pp. 295\u2013316. Springer, Cham (2015). https:\/\/doi.org\/10.1007\/978-3-319-26362-5_14"},{"key":"26_CR9","doi-asserted-by":"crossref","unstructured":"Hassanshahi, B., Lee, H., Krishnan, P.: Gelato: feedback-driven and guided security analysis of client-side web applications. In: 2022 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER), pp. 618\u2013629. IEEE (2022)","DOI":"10.1109\/SANER53432.2022.00079"},{"key":"26_CR10","unstructured":"Gauthier, F., Hassanshahi, B., Selwyn-Smith, B., Mai, T. N., Schl\u00fcter, M., Williams, M: Experience: model-based, feedback-driven, Greybox web fuzzing with BackREST. In: 36th European Conference on Object-Oriented Programming (ECOOP 2022). Schloss Dagstuhl-Leibniz-Zentrum f\u00fcr Informatik (2022)"},{"key":"26_CR11","doi-asserted-by":"crossref","unstructured":"Eriksson, B., Pellegrino, G., Sabelfeld, A.: Black widow: blackbox data-driven web scanning. In: 2021 IEEE Symposium on Security and Privacy (SP), pp. 1125\u20131142. IEEE (2021)","DOI":"10.1109\/SP40001.2021.00022"},{"key":"26_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"52","DOI":"10.1007\/978-3-642-22655-7_4","volume-title":"ECOOP 2011 \u2013 Object-Oriented Programming","author":"G Richards","year":"2011","unstructured":"Richards, G., Hammer, C., Burg, B., Vitek, J.: The Eval That Men Do: a large-scale study of the use of Eval in JavaScript applications. In: Mezini, M. (ed.) ECOOP 2011. LNCS, vol. 6813, pp. 52\u201378. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-22655-7_4"},{"key":"26_CR13","doi-asserted-by":"crossref","unstructured":"Fard, A.M., Mesbah, A.: Feedback-directed exploration of web applications to derive test models. In: ISSRE (Vol. 13), pp. 278\u2013287 (2013)","DOI":"10.1109\/ISSRE.2013.6698880"},{"key":"26_CR14","doi-asserted-by":"crossref","unstructured":"Kim, I.L., et al.: Finding client-side business flow tampering vulnerabilities. In: Proceedings of the ACM\/IEEE 42nd International Conference on Software Engineering, pp. 222\u2013233 (2020)","DOI":"10.1145\/3377811.3380355"},{"key":"26_CR15","doi-asserted-by":"crossref","unstructured":"Cousot, P., Cousot, R.: Abstract interpretation: a unified lattice model for static analysis of programs by construction or approximation of fixpoints. In: Proceedings of the 4th ACM SIGACT-SIGPLAN Symposium on Principles of Programming Languages, pp. 238\u2013252 (1977)","DOI":"10.1145\/512950.512973"},{"key":"26_CR16","unstructured":"Usage statistics of client-side programming languages. https:\/\/w3techs.com\/technologies\/overview\/client_side_language. Accessed 30 Apr 2022"},{"key":"26_CR17","doi-asserted-by":"crossref","unstructured":"Richards, G., Lebresne, S., Burg, B., Vitek, J.: An analysis of the dynamic behavior of JavaScript programs. In: Proceedings of the 31st ACM SIGPLAN Conference on Programming Language Design and Implementation, pp. 1\u201312. ACM, Toronto, Ontario, Canada (2010)","DOI":"10.1145\/1806596.1806598"},{"issue":"3","key":"26_CR18","doi-asserted-by":"publisher","first-page":"74","DOI":"10.1109\/MS.2018.110113408","volume":"36","author":"S Ryu","year":"2018","unstructured":"Ryu, S., Park, J., Park, J.: Toward analysis and bug finding in JavaScript web applications in the wild. IEEE Softw. 36(3), 74\u201382 (2018)","journal-title":"IEEE Softw."},{"key":"26_CR19","unstructured":"Esben, A., M\u00f8ller, A.: Determinacy in static analysis of jQuery. In: Proceedings of the 2014 ACM International Conference on Object Oriented Programming Systems Languages & Applications, pp. 17\u201331. ACM, Portland, OR, USA (2014)"},{"key":"26_CR20","unstructured":"Doup\u00e9, A., Cavedon, L., Kruegel, C., Vigna, G.: Enemy of the state: a state-aware black-box web vulnerability scanner. In: 21st USENIX Security Symposium, pp. 523\u2013538 (2012)"},{"key":"26_CR21","series-title":"Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","doi-asserted-by":"publisher","first-page":"704","DOI":"10.1007\/978-3-319-78813-5_37","volume-title":"Security and Privacy in Communication Networks","author":"X Hu","year":"2018","unstructured":"Hu, X., Cheng, Y., Duan, Y., Henderson, A., Yin, H.: JSForce: a forced execution engine for\u00a0malicious JavaScript detection. In: Lin, X., Ghorbani, A., Ren, K., Zhu, S., Zhang, A. (eds.) SecureComm 2017. LNICST, vol. 238, pp. 704\u2013720. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-78813-5_37"},{"key":"26_CR22","doi-asserted-by":"crossref","unstructured":"Ko, Y., Lee, H., Dolby, J., Ryu, S.: Practically tunable static analysis framework for large-scale JavaScript applications. In: 30th IEEE\/ACM International Conference on Automated Software Engineering (ASE), pp. 541\u2013551. IEEE (2015)","DOI":"10.1109\/ASE.2015.28"},{"key":"26_CR23","unstructured":"Lee, H., Won, S., Jin, J., Cho, J., Ryu, S.: SAFE: Formal specification and implementation of a scalable analysis framework for ECMAScript. In: 19th International Workshop on Foundations of Object-Oriented Languages, p. 96 (2012)"},{"key":"26_CR24","doi-asserted-by":"crossref","unstructured":"Wittern, E., Ying, A. T., Zheng, Y., Dolby, J., Laredo, J. A.: Statically checking web API requests in JavaScript. In: IEEE\/ACM 39th International Conference on Software Engineering (ICSE), pp. 244\u2013254. IEEE (2017)","DOI":"10.1109\/ICSE.2017.30"},{"key":"26_CR25","unstructured":"PT Bbs. https:\/\/bbs.ptsecurity.com\/. Accessed 30 Apr 2022"},{"key":"26_CR26","unstructured":"Acunetix Homepage. https:\/\/www.acunetix.com. Accessed 30 Apr 2022"},{"key":"26_CR27","unstructured":"Detectify Homepage. https:\/\/detectify.com. Accessed 30 Apr 2022"},{"key":"26_CR28","doi-asserted-by":"crossref","unstructured":"Burp Scanner. https:\/\/portswigger.net\/burp\/vulnerability-scanner. Accessed 30 Apr 2022","DOI":"10.47750\/jptcp.2023.30.15.005"},{"key":"26_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"238","DOI":"10.1007\/978-3-642-03237-0_17","volume-title":"Static Analysis","author":"SH Jensen","year":"2009","unstructured":"Jensen, S.H., M\u00f8ller, A., Thiemann, P.: Type analysis for JavaScript. In: Palsberg, J., Su, Z. (eds.) SAS 2009. LNCS, vol. 5673, pp. 238\u2013255. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-642-03237-0_17"},{"key":"26_CR30","unstructured":"HCL AppScan. https:\/\/www.hcltechsw.com\/appscan. Accessed 30 Apr 2022"},{"key":"26_CR31","unstructured":"Damn Vulnerable Web Application (DVWA). https:\/\/github.com\/digininja\/DVWA. Accessed 1 Jul 2023"},{"key":"26_CR32","unstructured":"MyBB 1.8.19. https:\/\/mybb.com\/. Accessed 1 Jul 2023"},{"key":"26_CR33","unstructured":"The T.J. Watson Libraries for Analysis (WALA). http:\/\/wala.sourceforge.net\/. Accessed 1 Jul 2023"},{"key":"26_CR34","unstructured":"Htcap 1.1.0. https:\/\/github.com\/fcavallarin\/htcap. Accessed 1 Jul 2023"},{"key":"26_CR35","unstructured":"W3af. http:\/\/w3af.org\/. Accessed 1 Jul 2023"},{"key":"26_CR36","unstructured":"Ajax Search Lite plugin for WordPress (version 4.11.2). https:\/\/wordpress.org\/plugins\/ajax-search-lite\/. Accessed 1 Jul 2023"},{"key":"26_CR37","unstructured":"Juice Shop 8.3.0. https:\/\/github.com\/juice-shop\/juice-shop\/tree\/v8.3.0. Accessed 1 Jul 2023"},{"key":"26_CR38","unstructured":"OWASP WebGoat Project. https:\/\/owasp.org\/www-project-webgoat\/. Accessed 1 Jul 2023"},{"key":"26_CR39","unstructured":"Web Input Vector Extractor Teaser. https:\/\/github.com\/bedirhan\/wivet. Accessed 1 Jul 2023"},{"key":"26_CR40","unstructured":"Wget. https:\/\/www.gnu.org\/software\/wget\/. Accessed 1 Jul 2023"},{"key":"26_CR41","unstructured":"Babel library. https:\/\/babeljs.io\/. Accessed 1 Jul 2023"}],"container-title":["Lecture Notes in Computer Science","Computer Security. ESORICS 2023 International Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-54129-2_26","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,11]],"date-time":"2024-03-11T22:07:22Z","timestamp":1710194842000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-54129-2_26"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031541285","9783031541292"],"references-count":41,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-54129-2_26","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"12 March 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Hague","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Netherlands","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 September 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 September 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2023.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Easychair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"478","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"93","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"19% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3-4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"10","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}