{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,24]],"date-time":"2025-11-24T07:05:36Z","timestamp":1763967936034,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":36,"publisher":"ACM","license":[{"start":{"date-parts":[[2007,5,8]],"date-time":"2007-05-08T00:00:00Z","timestamp":1178582400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2007,5,8]]},"DOI":"10.1145\/1242572.1242654","type":"proceedings-article","created":{"date-parts":[[2007,6,6]],"date-time":"2007-06-06T14:37:31Z","timestamp":1181140651000},"page":"601-610","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":161,"title":["Defeating script injection attacks with browser-enforced embedded policies"],"prefix":"10.1145","author":[{"given":"Trevor","family":"Jim","sequence":"first","affiliation":[{"name":"AT&amp;T Labs Research"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nikhil","family":"Swamy","sequence":"additional","affiliation":[{"name":"University of Maryland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michael","family":"Hicks","sequence":"additional","affiliation":[{"name":"University of Maryland"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2007,5,8]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Adbrite. http:\/\/www.adbrite.com.  Adbrite. http:\/\/www.adbrite.com."},{"key":"e_1_3_2_1_2_1","volume-title":"February","author":"Malicious HTML","year":"2000","unstructured":"Malicious HTML tags embedded in client web requests. CERT Advisory CA-2000-02 , February 2000 . Malicious HTML tags embedded in client web requests. CERT Advisory CA-2000-02, February 2000."},{"key":"e_1_3_2_1_3_1","volume-title":"August","author":"Chien Eric","year":"2006","unstructured":"Eric Chien . Malicious Yahooligans . Virus Bulletin , August 2006 . Eric Chien. Malicious Yahooligans. Virus Bulletin, August 2006."},{"key":"e_1_3_2_1_4_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy","author":"Feng Henry Hanping","year":"2004","unstructured":"Henry Hanping Feng , Jonathon T. Giffin , Yong Huang , Somesh Jha , Wenke Lee , and Barton P. Miller . Formalizing sensitivity in static analysis for intrusion detection . In Proceedings of the IEEE Symposium on Security and Privacy , 2004 . Henry Hanping Feng, Jonathon T. Giffin, Yong Huang, Somesh Jha, Wenke Lee, and Barton P. Miller. Formalizing sensitivity in static analysis for intrusion detection. In Proceedings of the IEEE Symposium on Security and Privacy, 2004."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1080\/15567280601015598"},{"key":"e_1_3_2_1_6_1","unstructured":"Google web toolkit. http:\/\/code.google.com\/webtoolkit\/.  Google web toolkit. http:\/\/code.google.com\/webtoolkit\/."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICECCS.2005.35"},{"key":"e_1_3_2_1_8_1","unstructured":"Hop home page. http:\/\/hop.inria.fr\/.  Hop home page. http:\/\/hop.inria.fr\/."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/1135777.1135884"},{"key":"e_1_3_2_1_10_1","unstructured":"Trevor Jim Nikhil Swamy and Michael Hicks. BEEP: Browser-enforced embedded policies. http:\/\/www.research.att.com\/~trevor\/beep.html.  Trevor Jim Nikhil Swamy and Michael Hicks. BEEP: Browser-enforced embedded policies. http:\/\/www.research.att.com\/~trevor\/beep.html."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/1134744.1134751"},{"key":"e_1_3_2_1_12_1","unstructured":"Paj's Home: Cryptography. http:\/\/www.pajhome.org.uk\/crypt\/index.html.  Paj's Home: Cryptography. http:\/\/www.pajhome.org.uk\/crypt\/index.html."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1141277.1141357"},{"key":"e_1_3_2_1_14_1","unstructured":"Amit Klein. DOM based cross site scripting or XSS of the third kind. http:\/\/www.webappsec.org\/projects\/articles\/071105.shtml July 2005.  Amit Klein. DOM based cross site scripting or XSS of the third kind. http:\/\/www.webappsec.org\/projects\/articles\/071105.shtml July 2005."},{"key":"e_1_3_2_1_15_1","series-title":"Lecture Notes in Computer Science","volume-title":"The CONTINUE server (or, how I administered PADL 2002 and","author":"Krishnamurthi Shriram","year":"2003","unstructured":"Shriram Krishnamurthi . The CONTINUE server (or, how I administered PADL 2002 and 2003 ). In V. Dahl and P. Wadler, editors, PADL, volume 2562 of Lecture Notes in Computer Science . Springer , 2003. Shriram Krishnamurthi. The CONTINUE server (or, how I administered PADL 2002 and 2003). In V. Dahl and P. Wadler, editors, PADL, volume 2562 of Lecture Notes in Computer Science. Springer, 2003."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/1180405.1180434"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-004-0046-8"},{"key":"e_1_3_2_1_18_1","unstructured":"Links: Linking theory to practice for the web. http:\/\/groups.inf.ed.ac.uk\/links\/.  Links: Linking theory to practice for the web. http:\/\/groups.inf.ed.ac.uk\/links\/."},{"key":"e_1_3_2_1_19_1","unstructured":"Gervase Markham. Content restrictions. http:\/\/www.gerv.net\/security\/content-restrictions\/ January 2006. Version 0.6.  Gervase Markham. Content restrictions. http:\/\/www.gerv.net\/security\/content-restrictions\/ January 2006. Version 0.6."},{"key":"e_1_3_2_1_20_1","unstructured":"MITRE. Common vulnerabilities and exposures. http:\/\/cve.mitre.org.  MITRE. Common vulnerabilities and exposures. http:\/\/cve.mitre.org."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/0-387-25660-1_20"},{"key":"e_1_3_2_1_22_1","unstructured":"Les Orchard. S3AjaxWiki. http:\/\/decafbad.com\/trac\/wiki\/S3Ajax.  Les Orchard. S3AjaxWiki. http:\/\/decafbad.com\/trac\/wiki\/S3Ajax."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1007\/11663812_7"},{"key":"e_1_3_2_1_24_1","volume-title":"Inc.","author":"Thomas","year":"1998","unstructured":"Thomas H. Ptacek and Timothy N. Newsham. Insertion, evasion, and denial of service: Eluding network intrusion detection. Technical report, Secure Networks , Inc. , January 1998 . Thomas H. Ptacek and Timothy N. Newsham. Insertion, evasion, and denial of service: Eluding network intrusion detection. Technical report, Secure Networks, Inc., January 1998."},{"key":"e_1_3_2_1_25_1","volume-title":"Proceedings of the USENIX Symposium on Operating System Design and Implementation (OSDI)","author":"Reis Charlie","year":"2006","unstructured":"Charlie Reis , John Dunagan , Helen J. Wang , Opher Dubrovsky , and Saher Esmeir . BrowserShield : Vulnerability-driven filtering of dynamic HTML . In Proceedings of the USENIX Symposium on Operating System Design and Implementation (OSDI) , 2006 . Charlie Reis, John Dunagan, Helen J. Wang, Opher Dubrovsky, and Saher Esmeir. BrowserShield: Vulnerability-driven filtering of dynamic HTML. In Proceedings of the USENIX Symposium on Operating System Design and Implementation (OSDI), 2006."},{"key":"e_1_3_2_1_26_1","unstructured":"R. Snake. XSS (cross site scripting) cheat sheet. Esp: for filter evasion. http:\/\/ha.ckers.org\/xss.html.  R. Snake. XSS (cross site scripting) cheat sheet. Esp: for filter evasion. http:\/\/ha.ckers.org\/xss.html."},{"key":"e_1_3_2_1_27_1","unstructured":"Jesse Ruderman. Signed scripts in mozilla. http:\/\/www.mozilla.org\/projects\/security\/components\/signed-scripts.html.  Jesse Ruderman. Signed scripts in mozilla. http:\/\/www.mozilla.org\/projects\/security\/components\/signed-scripts.html."},{"key":"e_1_3_2_1_28_1","unstructured":"Jesse Ruderman. The same origin policy. http:\/\/www.mozilla.org\/projects\/security\/components\/same-origin.html August 2001.  Jesse Ruderman. The same origin policy. http:\/\/www.mozilla.org\/projects\/security\/components\/same-origin.html August 2001."},{"key":"e_1_3_2_1_29_1","unstructured":"Optimizing page load time (and a little about the debug menu). http:\/\/webkit.org\/blog\/?p=75.  Optimizing page load time (and a little about the debug menu). http:\/\/webkit.org\/blog\/?p=75."},{"key":"e_1_3_2_1_30_1","unstructured":"Samy. I'm popular. http:\/\/namb.la\/popular\/ October 2005. Description of the MySpace worm by the author including a technical explanation.  Samy. I'm popular. http:\/\/namb.la\/popular\/ October 2005. Description of the MySpace worm by the author including a technical explanation."},{"key":"e_1_3_2_1_31_1","unstructured":"Christian Schmidt. Comment on content restrictions proposal. http:\/\/weblogs.mozillazine.org\/gerv\/archives\/007821.html March 2005.  Christian Schmidt. Comment on content restrictions proposal. http:\/\/weblogs.mozillazine.org\/gerv\/archives\/007821.html March 2005."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/1111037.1111070"},{"key":"e_1_3_2_1_33_1","unstructured":"HTML Tidy project page. http:\/\/tidy.sourceforge.net\/.  HTML Tidy project page. http:\/\/tidy.sourceforge.net\/."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.5555\/882495.884434"},{"key":"e_1_3_2_1_35_1","volume-title":"Proceedings of the USENIX Security Symposium","author":"Xie Yichen","year":"2006","unstructured":"Yichen Xie and Alex Aiken . Static detection of security vulnerabilities in scripting languages . In Proceedings of the USENIX Security Symposium , 2006 . Yichen Xie and Alex Aiken. Static detection of security vulnerabilities in scripting languages. In Proceedings of the USENIX Security Symposium, 2006."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/1190216.1190252"}],"event":{"name":"WWW'07: 16th International World Wide Web Conference","sponsor":["ACM Association for Computing Machinery"],"location":"Banff Alberta Canada","acronym":"WWW'07"},"container-title":["Proceedings of the 16th international conference on World Wide Web"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1242572.1242654","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1242572.1242654","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T14:47:54Z","timestamp":1750258074000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1242572.1242654"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2007,5,8]]},"references-count":36,"alternative-id":["10.1145\/1242572.1242654","10.1145\/1242572"],"URL":"https:\/\/doi.org\/10.1145\/1242572.1242654","relation":{},"subject":[],"published":{"date-parts":[[2007,5,8]]},"assertion":[{"value":"2007-05-08","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}