{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T12:15:43Z","timestamp":1763468143543,"version":"3.40.3"},"publisher-location":"Berlin, Heidelberg","reference-count":46,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642402029"},{"type":"electronic","value":"9783642402036"}],"license":[{"start":{"date-parts":[[2013,1,1]],"date-time":"2013-01-01T00:00:00Z","timestamp":1356998400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2013]]},"DOI":"10.1007\/978-3-642-40203-6_41","type":"book-chapter","created":{"date-parts":[[2013,8,14]],"date-time":"2013-08-14T02:48:53Z","timestamp":1376448533000},"page":"736-754","source":"Crossref","is-referenced-by-count":19,"title":["Data-Confined HTML5 Applications"],"prefix":"10.1007","author":[{"given":"Devdatta","family":"Akhawe","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Frank","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Warren","family":"He","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Prateek","family":"Saxena","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dawn","family":"Song","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"41_CR1","unstructured":"Chromium Bug Tracker: \n                    \n                      http:\/\/crbug.com\/107538"},{"key":"41_CR2","doi-asserted-by":"crossref","unstructured":"Agten, P., Acker, S.V., Brondsema, Y., Phung, P.H., Desmet, L., Piessens, F.: JSand: Complete client-side sandboxing of third-party javascript without browser modifications. In: ACSAC (2012)","DOI":"10.1145\/2420950.2420952"},{"key":"41_CR3","doi-asserted-by":"crossref","unstructured":"Akhawe, D., Barth, A., Lam, P., Mitchell, J., Song, D.: Towards a Formal Foundation of Web Security. In: CSF (2010)","DOI":"10.1109\/CSF.2010.27"},{"key":"41_CR4","doi-asserted-by":"crossref","unstructured":"Akhawe, D., Saxena, P., Song, D.: Privilege Separation in HTML5 Applications. In: USENIX Security (2012)","DOI":"10.1007\/978-3-642-40203-6_41"},{"key":"41_CR5","doi-asserted-by":"crossref","unstructured":"Akhawe, D., Li, F., He, W., Saxena, P., Song, D.: Data-confined html5 applications. Technical Report UCB\/EECS-2013-20, EECS Department, University of California, Berkeley (March 2013)","DOI":"10.1007\/978-3-642-40203-6_41"},{"key":"41_CR6","unstructured":"Barth, A.: Timing Attacks on CSS Shaders (2011), \n                    \n                      http:\/\/goo.gl\/Mos4a"},{"key":"41_CR7","unstructured":"Brumley, D., Song, D.: Privtrans: Automatically Partitioning Programs for Privilege Separation. In: USENIX Security (2004)"},{"key":"41_CR8","doi-asserted-by":"crossref","unstructured":"Cabuk, S., Brodley, C.E., Shields, C.: Ip covert timing channels: design and detection. In: CCS (2004)","DOI":"10.1145\/1030083.1030108"},{"key":"41_CR9","unstructured":"Chen, E., Gorbaty, S., Singhal, A., Jackson, C.: Self-exfiltration: The dangers of browser-enforced information flow control. In: W2SP (2012)"},{"key":"41_CR10","doi-asserted-by":"crossref","unstructured":"Chia, P.H., Yamamoto, Y., Asokan, N.: Is this app safe?: A large scale study on application permissions and risk signals. In: WWW (2012)","DOI":"10.1145\/2187836.2187879"},{"key":"41_CR11","doi-asserted-by":"crossref","unstructured":"Chugh, R., Meister, J.A., Jhala, R., Lerner, S.: Staged information flow for JavaScript. In: PLDI (2009)","DOI":"10.1145\/1542476.1542483"},{"key":"41_CR12","unstructured":"Clipperz: \n                    \n                      http:\/\/www.clipperz.com\/"},{"key":"41_CR13","unstructured":"Code Release: \n                    \n                      https:\/\/github.com\/devd\/data-confined-html5-applications"},{"key":"41_CR14","unstructured":"Crockford, D.: AdSafe, \n                    \n                      http:\/\/www.adsafe.org\/"},{"key":"41_CR15","unstructured":"Hayes, G.: Hacking caja part 2, \n                    \n                      http:\/\/www.thespanner.co.uk\/2012\/09\/18\/hacking-caja-part-2\/"},{"key":"41_CR16","unstructured":"Google: Caja, \n                    \n                      http:\/\/developers.google.com\/caja\/"},{"key":"41_CR17","unstructured":"Google: Chrome web store, \n                    \n                      https:\/\/chrome.google.com\/webstore"},{"key":"41_CR18","unstructured":"Google: Chromium os, \n                    \n                      http:\/\/www.chromium.org\/chromium-os"},{"key":"41_CR19","unstructured":"Google: Seccomp sandbox for linux, \n                    \n                      http:\/\/code.google.com\/p\/seccompsandbox\/"},{"key":"41_CR20","unstructured":"Google Caja Bug 51: \n                    \n                      http:\/\/code.google.com\/p\/google-caja\/issues\/detail?id=51"},{"key":"41_CR21","unstructured":"Google Caja Bug 1093: \n                    \n                      http:\/\/code.google.com\/p\/google-caja\/issues\/detail?id=1093"},{"key":"41_CR22","unstructured":"Google Caja: \n                    \n                      http:\/\/code.google.com\/p\/google-caja\/issues\/detail?id=520"},{"key":"41_CR23","doi-asserted-by":"crossref","unstructured":"Guha, A., Fredrikson, M., Livshits, B., Swamy, N.: Verified security for browser extensions. In: IEEE S&P (2011)","DOI":"10.1109\/SP.2011.36"},{"key":"41_CR24","unstructured":"Hanna, S., Shin, E., Akhawe, D., Boehm, A., Saxena, P., Song, D.: The emperor\u2019s new apis: On the (in) secure usage of new client-side primitives. In: W2SP (2010)"},{"key":"41_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"281","DOI":"10.1007\/978-3-642-23644-0_15","volume-title":"Recent Advances in Intrusion Detection","author":"M. Heiderich","year":"2011","unstructured":"Heiderich, M., Frosch, T., Holz, T.: IceShield: Detection and mitigation of malicious websites with a frozen DOM. In: Sommer, R., Balzarotti, D., Maier, G. (eds.) RAID 2011. LNCS, vol.\u00a06961, pp. 281\u2013300. Springer, Heidelberg (2011)"},{"key":"41_CR26","doi-asserted-by":"crossref","unstructured":"Heiderich, M., Niemietz, M., Schuster, F., Holz, T., Schwenk, J.: Scriptless attacks: stealing the pie without touching the sill. In: CCS (2012)","DOI":"10.1145\/2382196.2382276"},{"key":"41_CR27","unstructured":"Ingram, L., Walfish, M.: Treehouse: Javascript sandboxes to help web developers help themselves. In: USENIX ATC (2012)"},{"key":"41_CR28","doi-asserted-by":"crossref","unstructured":"Jackson, C., Bortz, A., Boneh, D., Mitchell, J.C.: Protecting browser state from web privacy attacks. In: WWW (2006)","DOI":"10.1145\/1135777.1135884"},{"key":"41_CR29","unstructured":"Jupiter-IT: EJS Javascript Templates, \n                    \n                      http:\/\/embeddedjs.com\/"},{"key":"41_CR30","doi-asserted-by":"crossref","unstructured":"Khatiwala, T., Swaminathan, R., Venkatakrishnan, V.: Data Sandboxing: A Technique for Enforcing Confidentiality Policies. In: ACSAC (2006)","DOI":"10.1109\/ACSAC.2006.22"},{"key":"41_CR31","doi-asserted-by":"crossref","unstructured":"Maffeis, S., Mitchell, J.C., Taly, A.: Object capabilities and isolation of untrusted web applications. In: IEEE S&P (2010)","DOI":"10.1109\/SP.2010.16"},{"key":"41_CR32","unstructured":"Microsoft: Metro Apps, \n                    \n                      http:\/\/msdn.microsoft.com\/en-us\/windows\/apps\/"},{"key":"41_CR33","unstructured":"Mozilla: Boot2gecko, \n                    \n                      https:\/\/wiki.mozilla.org\/B2G"},{"key":"41_CR34","unstructured":"phpMyAdmin: \n                    \n                      http:\/\/www.phpmyadmin.net\/"},{"key":"41_CR35","unstructured":"Politz, J.G., Eliopoulos, S.A., Guha, A., Krishnamurthi, S.: ADsafety: type-based verification of javascriptsandboxing. In: USENIX Security (2011)"},{"key":"41_CR36","first-page":"18","volume-title":"Proceedings of the 12th Conference on USENIX Security Symposium","author":"N. Provos","year":"2003","unstructured":"Provos, N.: Improving host security with system call policies. In: Proceedings of the 12th Conference on USENIX Security Symposium, vol.\u00a012, p. 18. USENIX Association, Berkeley (2003)"},{"key":"41_CR37","doi-asserted-by":"crossref","unstructured":"Richards, G., Lebresne, S., Burg, B., Vitek, J.: An analysis of the dynamic behavior of javascript programs. ACM SIGPLAN Notices (2010)","DOI":"10.1145\/1806596.1806598"},{"key":"41_CR38","unstructured":"Riley, S.: 5 OpenSource EMRs worth reviewing (2011), \n                    \n                      http:\/\/bit.ly\/hUa6l1"},{"issue":"9","key":"41_CR39","doi-asserted-by":"publisher","first-page":"1278","DOI":"10.1109\/PROC.1975.9939","volume":"63","author":"J. Saltzer","year":"1975","unstructured":"Saltzer, J., Schroeder, M.: The protection of information in computer systems. Proceedings of the IEEE\u00a063(9), 1278\u20131308 (1975)","journal-title":"Proceedings of the IEEE"},{"key":"41_CR40","doi-asserted-by":"crossref","unstructured":"Singh, K., Moshchuk, A., Wang, H., Lee, W.: On the incoherencies in web browser access control policies. In: IEEE S&P (2010)","DOI":"10.1109\/SP.2010.35"},{"key":"41_CR41","doi-asserted-by":"crossref","unstructured":"Sun, S., Hawkey, K., Beznosov, K.: Systematically breaking and fixing openid security: Formal analysis, semi-automated empirical evaluation, and practical countermeasures. Computers & Security (2012)","DOI":"10.1016\/j.cose.2012.02.005"},{"key":"41_CR42","unstructured":"Tizen: \n                    \n                      https:\/\/www.tizen.org\/"},{"key":"41_CR43","doi-asserted-by":"crossref","unstructured":"Wang, R., Chen, S., Wang, X.: Signing me onto your accounts through facebook and google: a traffic-guided security study of commercially deployed single-sign-on web services. In: IEEE S&P (2012)","DOI":"10.1109\/SP.2012.30"},{"key":"41_CR44","doi-asserted-by":"crossref","unstructured":"Xu, Y., Bailey, M., Jahanian, F., Joshi, K., Hiltunen, M., Schlichting, R.: An exploration of l2 cache covert channels in virtualized environments. In: CCSW (2011)","DOI":"10.1145\/2046660.2046670"},{"key":"41_CR45","unstructured":"Zalewski, M.: Postcards from the post-xss world, \n                    \n                      http:\/\/lcamtuf.coredump.cx\/postxss\/"},{"key":"41_CR46","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Juels, A., Reiter, M.K., Ristenpart, T.: Cross-VM side channels and their use to extract private keys. In: CCS (2012)","DOI":"10.1145\/2382196.2382230"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2013"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-40203-6_41","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,2]],"date-time":"2019-06-02T20:47:22Z","timestamp":1559508442000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-40203-6_41"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013]]},"ISBN":["9783642402029","9783642402036"],"references-count":46,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-40203-6_41","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2013]]}}}