{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,10]],"date-time":"2026-04-10T10:04:19Z","timestamp":1775815459670,"version":"3.50.1"},"publisher-location":"Berlin, Heidelberg","reference-count":37,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783642312830","type":"print"},{"value":"9783642312847","type":"electronic"}],"license":[{"start":{"date-parts":[[2012,1,1]],"date-time":"2012-01-01T00:00:00Z","timestamp":1325376000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012]]},"DOI":"10.1007\/978-3-642-31284-7_24","type":"book-chapter","created":{"date-parts":[[2012,6,13]],"date-time":"2012-06-13T06:15:58Z","timestamp":1339568158000},"page":"400-417","source":"Crossref","is-referenced-by-count":3,"title":["ARC: Protecting against HTTP Parameter Pollution Attacks Using Application Request Caches"],"prefix":"10.1007","author":[{"given":"Elias","family":"Athanasopoulos","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vasileios P.","family":"Kemerlis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michalis","family":"Polychronakis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Evangelos P.","family":"Markatos","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"24_CR1","unstructured":"Athanasopoulos, E.: HPP Finder (2011), \n                    \n                      http:\/\/www.ics.forth.gr\/~elathan\/extra\/hpp\/index.html"},{"key":"24_CR2","unstructured":"Bangert, B., Gardner, J.: The Pylons Project, \n                    \n                      http:\/\/pylonsproject.org\n                    \n                    \n                   (last visited on July 2011)"},{"key":"24_CR3","unstructured":"Balduzzi, M., Gimenez, C., Balzarotti, D., Kirda, E.: Automated discovery of parameter pollution vulnerabilities in web applications. In: Proceedings of the 18th Network and Distributed System Security Symposium (2011)"},{"key":"24_CR4","doi-asserted-by":"crossref","unstructured":"Barth, A., Caballero, J., Song, D.: Secure Content Sniffing for Web Browsers or How to Stop Papers from Reviewing Themselves. In: Proceedings of the 30th IEEE Symposium on Security & Privacy, Oakland, CA (May 2009)","DOI":"10.1109\/SP.2009.3"},{"key":"24_CR5","doi-asserted-by":"crossref","unstructured":"Barth, A., Jackson, C., Mitchell, J.C.: Robust Defenses for Cross-Site Request Forgery. In: Proceedings of the 15th ACM Conference on Computer and Communications Security, CCS (2008), \n                    \n                      http:\/\/crypto.stanford.edu\/websec\/csrf\/csrf.pdf","DOI":"10.1145\/1455770.1455782"},{"key":"24_CR6","doi-asserted-by":"crossref","unstructured":"Berners-Lee, T., Masinter, L., McCahill, M.: RFC 1738: Uniform Resource Locators (1994), \n                    \n                      http:\/\/www.ietf.org\/rfc\/rfc1738.txt","DOI":"10.17487\/rfc1738"},{"key":"24_CR7","doi-asserted-by":"publisher","first-page":"420","DOI":"10.1145\/1653662.1653713","volume-title":"CCS 2009: Proceedings of the 16th ACM Conference on Computer and Communications Security","author":"H. Bojinov","year":"2009","unstructured":"Bojinov, H., Bursztein, E., Boneh, D.: XCS: Cross Channel Scripting and Its Impact on Web Applications. In: CCS 2009: Proceedings of the 16th ACM Conference on Computer and Communications Security, pp. 420\u2013431. ACM, New York (2009)"},{"key":"24_CR8","first-page":"263","volume-title":"Proceedings of the 18th ACM Conference on Computer and Communications Security, CCS 2011","author":"P. Chapman","year":"2011","unstructured":"Chapman, P., Evans, D.: Automated Black-Box Detection of Side-Channel Vulnerabilities in Web Applications. In: Proceedings of the 18th ACM Conference on Computer and Communications Security, CCS 2011, pp. 263\u2013274. ACM, New York (2011), \n                    \n                      http:\/\/doi.acm.org\/10.1145\/2046707.2046737"},{"key":"24_CR9","doi-asserted-by":"crossref","unstructured":"Ciurana, E.: Developing with Google AppEngine. Springer (2009)","DOI":"10.1007\/978-1-4302-1832-6"},{"key":"24_CR10","doi-asserted-by":"publisher","first-page":"581","DOI":"10.1145\/1124772.1124861","volume-title":"Proceedings of the SIGCHI Conference on Human Factors in Computing Systems","author":"R. Dhamija","year":"2006","unstructured":"Dhamija, R., Tygar, J., Hearst, M.: Why Phishing Works. In: Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, pp. 581\u2013590. ACM, New York (2006)"},{"key":"24_CR11","doi-asserted-by":"crossref","unstructured":"Fogie, S., Grossman, J., Hansen, R., Rager, A., Petkov, P.: XSS Attacks: Cross Site Scripting Exploits and Defense. Syngress Publishing (2007)","DOI":"10.1016\/B978-159749154-9\/50005-6"},{"key":"24_CR12","unstructured":"Garrett, J., et al.: Ajax: A New Approach to Web Applications. Adaptive Path\u00a018 (2005)"},{"key":"24_CR13","doi-asserted-by":"crossref","unstructured":"Grier, C., Tang, S., King, S.: Secure Web Browsing with the OP Web Browser. In: Security and Privacy, pp. 402\u2013416. IEEE (2008)","DOI":"10.1109\/SP.2008.19"},{"key":"24_CR14","unstructured":"Gundy, M.V., Chen, H.: Noncespaces: Using Randomization to Enforce Information Flow Tracking and Thwart Cross-Site Scripting Attacks. In: Proceedings of the 16th Annual Network and Distributed System Security Symposium (NDSS), San Diego, CA, February 8-11 (2009)"},{"key":"24_CR15","unstructured":"Hansen, R., Grossman, J.: Clickjacking, technical Report, SecTheory (2008), \n                    \n                      http:\/\/www.sectheory.com\/clickjacking.htm"},{"key":"24_CR16","unstructured":"Hansson, D.H., et al.: Ruby on Rails, \n                    \n                      http:\/\/www.rubyonrails.org\n                    \n                    \n                   (last visited on July 2011)"},{"key":"24_CR17","doi-asserted-by":"publisher","first-page":"525","DOI":"10.1145\/1367497.1367569","volume-title":"Proceeding of the 17th International Conference on World Wide Web, WWW 2008","author":"C. Jackson","year":"2008","unstructured":"Jackson, C., Barth, A.: Forcehttps: Protecting High-security Web Sites from Network Attacks. In: Proceeding of the 17th International Conference on World Wide Web, WWW 2008, pp. 525\u2013534. ACM, New York (2008), \n                    \n                      http:\/\/doi.acm.org\/10.1145\/1367497.1367569"},{"key":"24_CR18","doi-asserted-by":"publisher","first-page":"601","DOI":"10.1145\/1242572.1242654","volume-title":"WWW 2007: Proceedings of the 16th International Conference on World Wide Web","author":"T. Jim","year":"2007","unstructured":"Jim, T., Swamy, N., Hicks, M.: Defeating Script Injection Attacks with Browser-Enforced Embedded Policies. In: WWW 2007: Proceedings of the 16th International Conference on World Wide Web, pp. 601\u2013610. ACM, New York (2007)"},{"key":"24_CR19","unstructured":"Baugh, J.P.: Go Programming (June 2010) ISBN: 1453636676"},{"key":"24_CR20","volume-title":"CCS 2010: Proceedings of the 17th ACM Conference on Computer and Communications Security","author":"H. Lin-Shung","year":"2010","unstructured":"Lin-Shung, H., Zack, W., Chris, E., Collin, J.: Protecting Browsers from Cross-Origin CSS Attacks. In: CCS 2010: Proceedings of the 17th ACM Conference on Computer and Communications Security. ACM, New York (2010)"},{"key":"24_CR21","unstructured":"Carettoni, L., di Paola, S: HTTP Parameter Pollution (2009), \n                    \n                      https:\/\/www.owasp.org\/images\/b\/ba\/AppsecEU09_CarettoniDiPaola_v0.8.pdf"},{"key":"24_CR22","doi-asserted-by":"publisher","first-page":"122","DOI":"10.1109\/ICWE.2008.24","volume-title":"Proceedings of the 2008 Eighth International Conference on Web Engineering, ICWE 2008","author":"A. Mesbah","year":"2008","unstructured":"Mesbah, A., Bozdag, E., Deursen, A.: v.: Crawling AJAX by Inferring User Interface State Changes. In: Proceedings of the 2008 Eighth International Conference on Web Engineering, ICWE 2008, pp. 122\u2013134. IEEE Computer Society, Washington, DC (2008), \n                    \n                      http:\/\/dx.doi.org\/10.1109\/ICWE.2008.24"},{"key":"24_CR23","unstructured":"Nadji, Y., Saxena, P., Song, D.: Document Structure Integrity: A Robust Basis for Cross-site Scripting Defense. In: Proceedings of the 16th Annual Network and Distributed System Security Symposium (NDSS), San Diego, CA, February\u00a08-11 (2009)"},{"key":"24_CR24","doi-asserted-by":"crossref","unstructured":"Reis, C., Gribble, S.: Isolating web programs in modern browser architectures. In: Proceedings of the 4th ACM European Conference on Computer Systems (EuroSys), pp. 219\u2013232. ACM (2009)","DOI":"10.1145\/1519065.1519090"},{"key":"24_CR25","unstructured":"Robertson, W., Vigna, G., Kruegel, C., Kemmerer, R.: Using Generalization and Characterization Techniques in the Anomaly-based Detection of Web Attacks. In: Proceeding of the Network and Distributed System Security Symposium (NDSS), San Diego, CA (February 2006)"},{"key":"24_CR26","unstructured":"Robertson, W., Vigna, G.: Static Enforcement of Web Application Integrity Through Strong Typing. In: Proceedings of the 18th USENIX Security Symposium, Montreal, Quebec (August 2009)"},{"key":"24_CR27","unstructured":"Saxena, P., Hanna, S., Poosankam, P., Song, D.: FLAX: Systematic Discovery of Client-side Validation Vulnerabilities in Rich Web Applications. In: Proceedings of the 17th Annual Network and Distributed System Security Symposium (NDSS)"},{"key":"24_CR28","unstructured":"Sekar, R.: An Efficient Black-box Technique for Defeating Web Application Attacks. In: Proceedings of the 16th Annual Network and Distributed System Security Symposium (NDSS), San Diego, CA, February 8-11 (2009)"},{"key":"24_CR29","doi-asserted-by":"publisher","first-page":"305","DOI":"10.1109\/SP.2010.25","volume-title":"Proceedings of the 2010 IEEE Symposium on Security and Privacy, SP 2010","author":"R. Sommer","year":"2010","unstructured":"Sommer, R., Paxson, V.: Outside the closed world: On using machine learning for network intrusion detection. In: Proceedings of the 2010 IEEE Symposium on Security and Privacy, SP 2010, pp. 305\u2013316. IEEE Computer Society, Washington, DC (2010), \n                    \n                      http:\/\/dx.doi.org\/10.1109\/SP.2010.25"},{"key":"24_CR30","unstructured":"Song, Y., Keromytis, A., Stolfo, S.: Spectrogram: A Mixture-of-Markov-Chains Model for Anomaly Detection in Web Traffic. In: Proceedings of the 16th Annual Network and Distributed System Security Symposium, NDSS (2009)"},{"key":"24_CR31","unstructured":"Tang, S., Mai, H., King, S.: Trust and Protection in the Illinois Browser Operating System. In: Proceedings of the 10th USENIX Conference on Operating Systems Design and Implementation (OSDI). USENIX (2010)"},{"key":"24_CR32","doi-asserted-by":"crossref","unstructured":"Ter Louw, M., Venkatakrishnan, V.: Blueprint: Precise Browser-neutral Prevention of Cross-site Scripting Attacks. In: Proceedings of the 30th IEEE Symposium on Security & Privacy, Oakland, CA (May 2009)","DOI":"10.1109\/SP.2009.33"},{"key":"24_CR33","unstructured":"Berners-Lee, T.: Tim Berners-Lee on the WorldWideWeb project. USENET post (1991), \n                    \n                      http:\/\/groups.google.com\/group\/alt.hypertext\/tree\/browse_frm\/thread\/7824e490ea164c06\/f61c1ef93d2a8398"},{"key":"24_CR34","doi-asserted-by":"crossref","unstructured":"Wang, H.J., Fan, X., Howell, J., Jackson, C.: Protection and Communication Abstractions for Web Browsers in MashupOS. In: Bressoud, T.C., Kaashoek, M.F. (eds.) SOSP, pp. 1\u201316. ACM (2007)","DOI":"10.1145\/1323293.1294263"},{"key":"24_CR35","unstructured":"Wang, H.J., Grier, C., Moshchuk, A., King, S.T., Choudhury, P., Venter, H.: The Multi-Principal OS Construction of the Gazelle Web Browser. In: Proceedings of the 18th USENIX Security Symposium, Montreal, Canada (August 2009)"},{"key":"24_CR36","unstructured":"Weinberg, Z., Chen, E., Jayaraman, P., Jackson, C.: I Still Know What You Visited Last Summer. In: Proceedings of the 32th IEEE Symposium on Security & Privacy, Oakland, CA (May 2011)"},{"key":"24_CR37","unstructured":"XSSed.com: XSS exploit in key example, \n                    \n                      http:\/\/xssed.com\/mirror\/33541\/"}],"container-title":["Lecture Notes in Computer Science","Applied Cryptography and Network Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-31284-7_24","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,19]],"date-time":"2019-05-19T20:44:44Z","timestamp":1558298684000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-31284-7_24"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012]]},"ISBN":["9783642312830","9783642312847"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-31284-7_24","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012]]}}}