{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2023,2,20]],"date-time":"2023-02-20T17:30:57Z","timestamp":1676914257098},"reference-count":32,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2010,5,22]],"date-time":"2010-05-22T00:00:00Z","timestamp":1274486400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2010,10]]},"DOI":"10.1007\/s10664-010-9131-y","type":"journal-article","created":{"date-parts":[[2010,5,21]],"date-time":"2010-05-21T04:15:20Z","timestamp":1274415320000},"page":"556-576","source":"Crossref","is-referenced-by-count":13,"title":["An empirical investigation into open source web applications\u2019 implementation vulnerabilities"],"prefix":"10.1007","volume":"15","author":[{"given":"Toan","family":"Huynh","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"James","family":"Miller","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2010,5,22]]},"reference":[{"key":"9131_CR1","doi-asserted-by":"crossref","unstructured":"Agrawal H, Horgan JR (1990) Dynamic program slicing. Proceedings of the ACM SIGPLAN\u201990 Conference on Programming Language Design and Implementation, New York, USA, pp 246\u2013256","DOI":"10.1145\/93542.93576"},{"issue":"3","key":"9131_CR2","doi-asserted-by":"crossref","first-page":"219","DOI":"10.1016\/j.cose.2006.10.002","volume":"26","author":"OH Alhazmi","year":"2007","unstructured":"Alhazmi OH, Malaiya YK, Ray I (2007) Measuring, analyzing and predicting security vulnerabilities in software systems. Comput Secur J 26(3):219\u2013228","journal-title":"Comput Secur J"},{"key":"9131_CR3","unstructured":"Basili V, Caldeira G, Rombach HD (1994) The goal question metric approach. Encyclopedia of Software Engineering, Wiley"},{"issue":"3","key":"9131_CR4","doi-asserted-by":"crossref","first-page":"237","DOI":"10.1111\/j.1365-2575.2004.00171.x","volume":"14","author":"R Baskerville","year":"2004","unstructured":"Baskerville R, Pries-Heje J (2004) Short cycle time systems development. Inf Syst J 14(3):237\u2013264","journal-title":"Inf Syst J"},{"key":"9131_CR5","doi-asserted-by":"crossref","unstructured":"Boyd SW, Keromytis AD (2004) SQLrand: preventing SQL injection attacks. In Proc. of the 2nd Applied Cryptography and Network Security Conf. (ACNS \u201904), Yellow Mountain, China pp 292\u2013302","DOI":"10.1007\/978-3-540-24852-1_21"},{"key":"9131_CR6","doi-asserted-by":"crossref","unstructured":"Buehrer GT, Weide BW, Sivilotti PAG (2005) Using parse tree validation to prevent SQL injection attacks. In Proc. of the 5th Intl. Workshop on Software Engineering and Middleware (SEM \u201905), Lisbon, Portugal, pp 106\u2013113","DOI":"10.1145\/1108473.1108496"},{"key":"9131_CR7","doi-asserted-by":"crossref","unstructured":"Cova M, Balzarotti D, Felmetsger V, Vigna G (2007) Swaddler: an approach for the anomaly-based detection of State violations in web applications, Recent Advance in Intrusion Detection (RAID), pp 63\u201386","DOI":"10.1007\/978-3-540-74320-0_4"},{"key":"9131_CR8","doi-asserted-by":"crossref","first-page":"504","DOI":"10.1145\/359636.359712","volume":"20","author":"DE Denning","year":"1997","unstructured":"Denning DE, Denning PJ (1997) Certification of programs for secure information flow. Commun ACM 20:504\u2013513, New York, USA, ACM","journal-title":"Commun ACM"},{"key":"9131_CR9","doi-asserted-by":"crossref","unstructured":"Halfond WG, Orso A (2005) AMNESIA: analysis and monitoring for NEutralizing SQL-injection attacks. In Proceedings of 20th ACM International Conference on Automated Software Engineering (ASE), Long Beach, CA, USA, pp 174\u2013183","DOI":"10.1145\/1101908.1101935"},{"key":"9131_CR10","doi-asserted-by":"crossref","unstructured":"Halfond WG, Orso A, Manolios P (2006) Using positive tainting and syntax-aware evaluation to counter SQL injection attacks. In Proceedings of the 14th ACM SIGSOFT international Symposium on Foundations of Software Engineering, Portland, Oregon, USA, pp 175\u2013185","DOI":"10.1145\/1181775.1181797"},{"issue":"1","key":"9131_CR11","doi-asserted-by":"crossref","first-page":"65","DOI":"10.1109\/TSE.2007.70748","volume":"34","author":"WGJ Halfond","year":"2008","unstructured":"Halfond WGJ, Orso A, Manolios P (2008) WASP: protecting web applications using positive tainting and syntax-aware evaluation. IEEE Trans Softw Eng 34(1):65\u201381","journal-title":"IEEE Trans Softw Eng"},{"key":"9131_CR12","doi-asserted-by":"crossref","unstructured":"Huang YW, Yu F, Hang C, Tsai CH, Lee DT, Kuo SY (2004) Securing web application code by static analysis and runtime protection, in WWW \u201904: Proceedings of the 13th International Conference on World Wide Web. New York, NY, USA: ACM Press, pp 40\u201352","DOI":"10.1145\/988672.988679"},{"key":"9131_CR13","doi-asserted-by":"crossref","unstructured":"Liu A, Yuan Y, Wijesekera D, Stavrou A (2009) SQLProb: a proxy-based architecture towards preventing SQL injection attacks. Proceedings of the 2009 ACM symposium on Applied Computing, Honolulu, Hawaii, pp 2054\u20132061","DOI":"10.1145\/1529282.1529737"},{"key":"9131_CR14","unstructured":"Johnson R, Wagner D (2004) Finding user\/kernel pointer bugs with type inference. In Proceedings of the 2004 Usenix Security Conference, San Diego, CA, USA, pp 119\u2013134"},{"key":"9131_CR15","doi-asserted-by":"crossref","unstructured":"Jovanovic N, Kruegel C, Kirda E (2006) Pixy: a static analysis tool for detecting web application vulnerabilities. In 2006 IEEE Symposium on Security and Privacy, Berkeley\/Oakland, CA, USA, pp 258\u2013263","DOI":"10.1109\/SP.2006.29"},{"key":"9131_CR16","doi-asserted-by":"crossref","unstructured":"Kals S, Kirda E, Kruegel C, Jovanovic N (2006) SecuBat: a web vulnerability scanner. The 15th International World Wide Web Conference (WWW 2006), Edinburgh, Scotland, pp 247\u2013256","DOI":"10.1145\/1135777.1135817"},{"key":"9131_CR17","unstructured":"Kiezun A, Guo PJ, Jayaraman K, Ernst MD (2008) Automatic creation of SQL injection and cross-site scripting attacks. Proceedings of the 2009 IEEE 31st International Conference on Software Engineering, Vancouver, British Columbia, Canada, pp 199\u2013209"},{"key":"9131_CR18","doi-asserted-by":"crossref","unstructured":"Lin J-C, Chen J-M (2006) An automatic revised tool for anti-malicious injection. Sixth IEEE International Conference on Computer and Information Technology (CIT\u201906), Seoul, South Korea, pp 164\u2013170","DOI":"10.1109\/CIT.2006.40"},{"key":"9131_CR19","unstructured":"Martin M, Lam M (2008) Automatic generation of XSS and SQL injection attacks with goal-directed model checking. Proceedings of the 17th conference on Security symposium, San Jose, CA, pp 31\u201343"},{"key":"9131_CR20","doi-asserted-by":"crossref","unstructured":"Martin M, Livshits B, Lam MS (2005) Finding application errors and security flaws using PQL: a program query language. In OOPSLA \u201905: Proc. of the 20th Annual ACM SIGPLAN Conference on Object Oriented Programming Systems Languages and Applications, San Diego, CA, USA, pp 365\u2013383","DOI":"10.1145\/1094811.1094840"},{"key":"9131_CR21","doi-asserted-by":"crossref","unstructured":"Nguyen-Tuong A, Guarnieri S, Greene D, Shirley J, Evans D (2005) Automatically hardening web applications using precise tainting. In Proceedings of the 20th IFIP International Information Security Conference, Chiba, Japan, pp 372\u2013382","DOI":"10.1007\/0-387-25660-1_20"},{"key":"9131_CR22","unstructured":"OWASP (2007) Top 10 2007. http:\/\/www.owasp.org\/index.php\/Top_10_2007 , last accessed June 29, 2009"},{"key":"9131_CR23","unstructured":"Pietraszek T, Berghe CV (2005) Defending against injection attacks through context-sensitive string evaluation. In Proceedings of Recent Advances in Intrusion Detection (RAID2005), Seattle, Washington, USA, pp 124\u2013145"},{"key":"9131_CR24","unstructured":"Rapid7 (2005) Vulnerability management trends. (2)1\u20139"},{"key":"9131_CR25","volume-title":"Hacking exposed: web applications second edition","author":"J Scambray","year":"2006","unstructured":"Scambray J, Shema M, Sima C (2006) Hacking exposed: web applications second edition. McGraw-Hill, San Francisco"},{"key":"9131_CR26","doi-asserted-by":"crossref","unstructured":"Scott D, Sharp R (2002) Abstracting application-level web security. In Proc. of the 11th Intl. Conference on the World Wide Web (WWW 2002), Honolulu, Hawaii, USA, pp 396\u2013407","DOI":"10.1145\/511446.511498"},{"key":"9131_CR27","unstructured":"Shankar U, Talwar K, Foster JS, Wagner D (2001) Detecting format string vulnerabilities with type qualifiers. In 10th USENIX Security Symposium, Washington, D.C., pp 201\u2013220"},{"key":"9131_CR28","doi-asserted-by":"crossref","unstructured":"Su Z, Wassermann G (2006) The essence of command injection attacks in web applications. In The 33rd Annual Symposium on Principles of Programming Languages, Charleston, South Carolina, USA, pp 372\u2013382","DOI":"10.1145\/1111037.1111070"},{"key":"9131_CR29","volume-title":"Threat modeling","author":"F Swiderski","year":"2004","unstructured":"Swiderski F, Snyder W (2004) Threat modeling. Microsoft Press, Redmond"},{"issue":"3","key":"9131_CR30","first-page":"121","volume":"3","author":"F Tip","year":"1995","unstructured":"Tip F (1995) A survey of program slicing techniques. J Program Lang 3(3):121\u2013189","journal-title":"J Program Lang"},{"issue":"4","key":"9131_CR31","doi-asserted-by":"crossref","first-page":"352","DOI":"10.1109\/TSE.1984.5010248","volume":"SE-10","author":"M Weiser","year":"1984","unstructured":"Weiser M (1984) Program slicing. IEEE Trans Softw Eng SE-10(4):352\u2013357","journal-title":"IEEE Trans Softw Eng"},{"key":"9131_CR32","unstructured":"Zhang X, Edwards A, Jaeger T (2002) Using CQual for static analysis of authorization hook placement. In the Proceedings of the 11th USENIX Security Symposium, San Francisco, CA, USA, pp 33\u201348"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-010-9131-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10664-010-9131-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-010-9131-y","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,30]],"date-time":"2019-05-30T21:15:10Z","timestamp":1559250910000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10664-010-9131-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010,5,22]]},"references-count":32,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2010,10]]}},"alternative-id":["9131"],"URL":"https:\/\/doi.org\/10.1007\/s10664-010-9131-y","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"value":"1382-3256","type":"print"},{"value":"1573-7616","type":"electronic"}],"subject":[],"published":{"date-parts":[[2010,5,22]]}}}