{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T15:00:13Z","timestamp":1784300413682,"version":"3.55.0"},"reference-count":75,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2019,3,1]],"date-time":"2019-03-01T00:00:00Z","timestamp":1551398400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2019,3,1]],"date-time":"2019-03-01T00:00:00Z","timestamp":1551398400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2019,3,1]],"date-time":"2019-03-01T00:00:00Z","timestamp":1551398400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["cns-13-18415"],"award-info":[{"award-number":["cns-13-18415"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2019,3,1]]},"DOI":"10.1109\/tdsc.2017.2665620","type":"journal-article","created":{"date-parts":[[2017,3,1]],"date-time":"2017-03-01T19:17:34Z","timestamp":1488395854000},"page":"188-203","source":"Crossref","is-referenced-by-count":42,"title":["Defending Against Web Application Attacks: Approaches, Challenges and Implications"],"prefix":"10.1109","volume":"16","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5061-9018","authenticated-orcid":false,"given":"Dimitris","family":"Mitropoulos","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Panos","family":"Louridas","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michalis","family":"Polychronakis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Angelos Dennis","family":"Keromytis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref73","doi-asserted-by":"crossref","first-page":"101","DOI":"10.1214\/ss\/1009213286","article-title":"Interval estimation for a binomial proportion","volume":"16","author":"brown","year":"2001","journal-title":"Statist Sci"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.1987.232894"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1145\/1255329.1255336"},{"key":"ref70","article-title":"DTA++: Dynamic taint analysis with targeted control-flow propagation","author":"kang","year":"2011","journal-title":"Proc Symp Network and Distributed System Security"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516703"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/1244002.1244071"},{"key":"ref75","author":"vance","year":"2014","journal-title":"Quality Code Software Testing Principles Practices and Patterns"},{"key":"ref38","article-title":"Noncespaces: Using randomization to enforce information flow tracking and thwart cross-site scripting attacks","author":"gundy","year":"2009","journal-title":"Proc 16th Annu Netw Distrib Syst Secur Symp"},{"key":"ref33","first-page":"131","article-title":"Protecting users by confining JavaScript with COWL","author":"stefan","year":"2014","journal-title":"Proc 11th USENIX Conf Operating Syst Des Implementation"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/2554850.2554909"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/1772690.1772784"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-70542-0_2"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/SECCOMW.2006.359531"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/1281480.1281481"},{"key":"ref35","first-page":"47","article-title":"Hails: Protecting data privacy in untrusted web applications","author":"giffin","year":"2012","journal-title":"Proc USENIX Conf Operating System Design and Implementations"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23295"},{"key":"ref60","author":"jain","year":"1991","journal-title":"The Art of Computer Systems Performance Analysis"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1108\/09685221111153555"},{"key":"ref61","author":"brendan","year":"2014","journal-title":"Systems Performance Enterprise and the Cloud"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1145\/360051.360056"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-11747-3_2"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1145\/586110.586145"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455783"},{"key":"ref65","year":"2015"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2009.15"},{"key":"ref29","first-page":"12","article-title":"Cross-site scripting prevention with dynamic data tainting and static analysis","author":"vogt","year":"2007","journal-title":"Proc Symp Network and Distributed System Security"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948146"},{"key":"ref68","first-page":"10","article-title":"Where's the FEEB? The effectiveness of instruction set randomization","author":"sovarel","year":"2005","journal-title":"Proc 14th Usenix Security"},{"key":"ref69","article-title":"Taintless: Defeating taint-powered protection tachniques","author":"naderi","year":"2014"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/2103656.2103678"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/1111037.1111070"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/1242572.1242654"},{"key":"ref22","first-page":"13","article-title":"xJS: Practical XSS prevention for web application development","author":"athanasopoulos","year":"2010","journal-title":"Proc USENIX Conf Web Appl"},{"key":"ref21","first-page":"463","article-title":"Document structure integrity: A robust basis for cross-site scripting defense","author":"nadji","year":"2006","journal-title":"Proc Symp Network and Distributed System Security"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/1190216.1190252"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.36"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/2076732.2076775"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/1533057.1533067"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/1101908.1101935"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-24852-1_21"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1038\/ngeo2283"},{"key":"ref58","author":"pfleeger","year":"2012","journal-title":"Analyzing Computer Security A Threat\/Vulnerability\/Countermeasure Approach"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1080\/10691898.2004.11910632"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1145\/1128817.1128834"},{"key":"ref55","first-page":"12","article-title":"Abstractions for usable information flow control in Aeolus","author":"cheng","year":"2012","journal-title":"Proc USENIX Conf Annu Tech Conf"},{"key":"ref54","first-page":"1:1","article-title":"SIF: Enforcing confidentiality and integrity in web applications","author":"chong","year":"2007","journal-title":"Proc 16th USENIX Security Symp"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1007\/11506881_8"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45853-0_16"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1038\/514536a"},{"key":"ref11","first-page":"13","article-title":"Exploit programming: From buffer overflows to &#x2018;Weird Machines&#x2019; and theory of computation","volume":"36","author":"bratus","year":"2011","journal-title":"login"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/1377943.1377956"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1002\/spe.515"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/2187671.2187679"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516696"},{"key":"ref15","first-page":"655","article-title":"Precise client-side protection against DOM-based cross-site scripting","author":"stock","year":"2014","journal-title":"Proc 23rd USENIX Secur Symp"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CSE.2009.372"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653713"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2009.04.008"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2009.33"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660363"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382276"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2012.6227141"},{"key":"ref5","first-page":"13","article-title":"A classification of SQL-injection attacks and countermeasures","author":"halfond","year":"2006","journal-title":"Proc Int'l Symp Secure Software Engineering"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/357830.357849"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/2187671.2187673"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2008.09.005"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.13"},{"key":"ref46","first-page":"121","article-title":"Taint-enhanced policy enforcement: A practical approach to defeat a wide range of attacks","author":"xu","year":"2006","journal-title":"Proc 15th Usenix Security Symp"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2005.21"},{"key":"ref48","first-page":"2","article-title":"PHP Aspis: Using partial taint tracking to protect against injection attacks","author":"papagiannis","year":"2011","journal-title":"Proc 2nd USENIX Conf Web Appl Develop"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1007\/11663812_7"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2008.36"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/IWSESS.2009.5068456"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1145\/1108473.1108496"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/2076732.2076768"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8858\/8666010\/07865911.pdf?arnumber=7865911","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,13]],"date-time":"2022-07-13T20:53:03Z","timestamp":1657745583000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/7865911\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,3,1]]},"references-count":75,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2017.2665620","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,3,1]]}}}