{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,24]],"date-time":"2026-01-24T07:37:09Z","timestamp":1769240229489,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":48,"publisher":"ACM","license":[{"start":{"date-parts":[[2010,10,4]],"date-time":"2010-10-04T00:00:00Z","timestamp":1286150400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2010,10,4]]},"DOI":"10.1145\/1866307.1866374","type":"proceedings-article","created":{"date-parts":[[2010,10,5]],"date-time":"2010-10-05T14:38:23Z","timestamp":1286289503000},"page":"595-606","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":41,"title":["Sidebuster"],"prefix":"10.1145","author":[{"given":"Kehuan","family":"Zhang","sequence":"first","affiliation":[{"name":"Indiana University, Bloomington, IN, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhou","family":"Li","sequence":"additional","affiliation":[{"name":"Indiana University, Bloomington, IN, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rui","family":"Wang","sequence":"additional","affiliation":[{"name":"Indiana University, Bloomington, IN, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"XiaoFeng","family":"Wang","sequence":"additional","affiliation":[{"name":"Indiana University, Bloomington, IN, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shuo","family":"Chen","sequence":"additional","affiliation":[{"name":"Microsoft Corporation, Redmond, WA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2010,10,4]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"}}The cross-site scripting (xss) faq. http:\/\/www.cgisecurity. com\/xss-faq.html.  }}The cross-site scripting (xss) faq. http:\/\/www.cgisecurity. com\/xss-faq.html."},{"key":"e_1_3_2_1_2_1","unstructured":"}}gwt-advanced-table. http:\/\/code.google.com\/p\/gwt-advanced-table\/.  }}gwt-advanced-table. http:\/\/code.google.com\/p\/gwt-advanced-table\/."},{"key":"e_1_3_2_1_3_1","unstructured":"}}Htmlunit - welcome to htmlunit. hhtmlunit.sourceforge.net\/.  }}Htmlunit - welcome to htmlunit. hhtmlunit.sourceforge.net\/."},{"key":"e_1_3_2_1_4_1","unstructured":"}}Introduction to gwt - ete 2009.http:\/\/gwtsandbox.com\/ete2009.  }}Introduction to gwt - ete 2009.http:\/\/gwtsandbox.com\/ete2009."},{"key":"e_1_3_2_1_5_1","unstructured":"}}jpcap - a network packet capture library for applications written in java. http:\/\/jpcap.sourceforge.net\/.  }}jpcap - a network packet capture library for applications written in java. http:\/\/jpcap.sourceforge.net\/."},{"key":"e_1_3_2_1_6_1","unstructured":"}}Sql injection. http:\/\/en.wikipedia.org\/wiki\/Sql_injection.  }}Sql injection. http:\/\/en.wikipedia.org\/wiki\/Sql_injection."},{"key":"e_1_3_2_1_7_1","volume-title":"http:\/\/en.wikipedia.org\/wiki\/HTTP_Secure","author":"Http","year":"2010","unstructured":"}} Http secure. http:\/\/en.wikipedia.org\/wiki\/HTTP_Secure , 2010 . }}Http secure. http:\/\/en.wikipedia.org\/wiki\/HTTP_Secure, 2010."},{"key":"e_1_3_2_1_8_1","volume-title":"Wi-fi protected access: Strong, standards-based, interoperable security for today's wi-fi networks. White paper","author":"Alliance Wi-Fi","year":"2003","unstructured":"}} Wi-Fi Alliance . Wi-fi protected access: Strong, standards-based, interoperable security for today's wi-fi networks. White paper , University of Cape Town , April 2003 . }}Wi-Fi Alliance. Wi-fi protected access: Strong, standards-based, interoperable security for today's wi-fi networks. White paper, University of Cape Town, April 2003."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-88313-5_33"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2009.18"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2009.9"},{"key":"e_1_3_2_1_12_1","first-page":"29","volume-title":"Proceedings of the Second UNIX Workshop on Electronic Commerce","author":"Bruce David Wagner","year":"1996","unstructured":"}} David Wagner Bruce , David Wagner , and Bruce Schneier . Analysis of the ssl 3.0 protocol . In Proceedings of the Second UNIX Workshop on Electronic Commerce , pages 29 -- 40 , 1996 . }}David Wagner Bruce, David Wagner, and Bruce Schneier. Analysis of the ssl 3.0 protocol. In Proceedings of the Second UNIX Workshop on Electronic Commerce, pages 29--40, 1996."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.20"},{"key":"e_1_3_2_1_14_1","unstructured":"}}Heyning Cheng and Ron Avnur. Traffic analysis of ssl encrypted web browsing. http:\/\/www.cs.berkeley.edu\/~daw\/teaching\/cs261-f98\/projects\/final-reports\/ronathan-heyning.ps 1998.  }}Heyning Cheng and Ron Avnur. Traffic analysis of ssl encrypted web browsing. http:\/\/www.cs.berkeley.edu\/~daw\/teaching\/cs261-f98\/projects\/final-reports\/ronathan-heyning.ps 1998."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.5555\/1370628.1370629"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.5555\/1662658.1662660"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/1273463.1273490"},{"key":"e_1_3_2_1_18_1","volume-title":"http:\/\/code.google.com\/webtoolkit\/, as of","author":"Code Google","year":"2009","unstructured":"}} Google Code . http:\/\/code.google.com\/webtoolkit\/, as of 2009 . }}Google Code. http:\/\/code.google.com\/webtoolkit\/, as of 2009."},{"key":"e_1_3_2_1_19_1","unstructured":"}}George Danezis. Traffic analysis of the http protocol over tls. http:\/\/research.microsoft.com\/en-us\/um\/people\/gdane\/papers\/tlsanon.pdf as of June 2010.  }}George Danezis. Traffic analysis of the http protocol over tls. http:\/\/research.microsoft.com\/en-us\/um\/people\/gdane\/papers\/tlsanon.pdf as of June 2010."},{"key":"e_1_3_2_1_20_1","volume-title":"Cryptography and data security","author":"Robling Denning Dorothy Elizabeth","year":"1982","unstructured":"}} Dorothy Elizabeth Robling Denning . Cryptography and data security . Addison-Wesley Longman Publishing Co., Inc. , Boston, MA, USA , 1982 . }}Dorothy Elizabeth Robling Denning. Cryptography and data security. Addison-Wesley Longman Publishing Co., Inc., Boston, MA, USA, 1982."},{"key":"e_1_3_2_1_21_1","volume-title":"NSA Cryptologic Spectrum","author":"Friedman Jeffrey","year":"1972","unstructured":"}} Jeffrey Friedman . Tempest : A signal problem . NSA Cryptologic Spectrum , 1972 . }}Jeffrey Friedman. Tempest: A signal problem. NSA Cryptologic Spectrum, 1972."},{"key":"e_1_3_2_1_22_1","unstructured":"}}Jesse James Garrett. Ajax: A new approach to web applications. http:\/\/adaptivepath.com\/ideas\/essays\/archives\/000385.php February 2005.  }}Jesse James Garrett. Ajax: A new approach to web applications. http:\/\/adaptivepath.com\/ideas\/essays\/archives\/000385.php February 2005."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.1982.10014"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.14"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1002\/swf.41"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/988672.988679"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.29"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2009.5070521"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/360248.360252"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315282"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/1328408.1328410"},{"key":"e_1_3_2_1_32_1","unstructured":"}}Ondrej Lhotak. Spark: A flexible points-to analysis framework for java. http:\/\/plg.uwaterloo.ca\/~olhotak\/pubs\/thesis-olhotak-msc.ps 2002.  }}Ondrej Lhotak. Spark: A flexible points-to analysis framework for java. http:\/\/plg.uwaterloo.ca\/~olhotak\/pubs\/thesis-olhotak-msc.ps 2002."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/1190216.1190251"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2009.88"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/363516.363526"},{"key":"e_1_3_2_1_37_1","volume-title":"Proceedings of the 12th Annual Network and Distributed System Security Symposium (NDSS 05)","author":"Newsome James","year":"2005","unstructured":"}} James Newsome and Dawn Song . Dynamic taint analysis for automatic detection, analysis, and signature generation of exploits on commodity software . In Proceedings of the 12th Annual Network and Distributed System Security Symposium (NDSS 05) , 2005 . }}James Newsome and Dawn Song. Dynamic taint analysis for automatic detection, analysis, and signature generation of exploits on commodity software. In Proceedings of the 12th Annual Network and Distributed System Security Symposium (NDSS 05), 2005."},{"key":"e_1_3_2_1_39_1","unstructured":"}}The Tor Project. Tor: anonymity online. http:\/\/www.torproject.org\/ 2009.  }}The Tor Project. Tor: anonymity online. http:\/\/www.torproject.org\/ 2009."},{"key":"e_1_3_2_1_40_1","first-page":"1","volume-title":"Proceedings of 16th USENIX Security Symposium","author":"Saponas T. Scott","year":"2007","unstructured":"}} T. Scott Saponas , Jonathan Lester , Carl Hartung , Sameer Agarwal , and Tadayoshi Kohno . Devices that tell on you: privacy trends in consumer ubiquitous computing . In Proceedings of 16th USENIX Security Symposium , pages 1 -- 16 , 2007 . }}T. Scott Saponas, Jonathan Lester, Carl Hartung, Sameer Agarwal, and Tadayoshi Kohno. Devices that tell on you: privacy trends in consumer ubiquitous computing. In Proceedings of 16th USENIX Security Symposium, pages 1--16, 2007."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/1519065.1519073"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.5555\/1251327.1251352"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.5555\/3088723.3088767"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/1024393.1024404"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"crossref","first-page":"19","DOI":"10.1109\/SECPRI.2002.1004359","volume-title":"Proceedings of the 2002 IEEE Symposium on Security and Privacy","author":"Sun Qixiang","year":"2002","unstructured":"}} Qixiang Sun , Daniel R. Simon , Yi-Min Wang , Wilf Russell , Venkata N. Padmanabhan , and Lili Qiu . Statistical identification of encrypted web browsing traffic . In Proceedings of the 2002 IEEE Symposium on Security and Privacy , page 19 , 2002 . }}Qixiang Sun, Daniel R. Simon, Yi-Min Wang, Wilf Russell, Venkata N. Padmanabhan, and Lili Qiu. Statistical identification of encrypted web browsing traffic. In Proceedings of the 2002 IEEE Symposium on Security and Privacy, page 19, 2002."},{"key":"e_1_3_2_1_46_1","first-page":"13","volume-title":"CASCON'99: Proceedings of the 1999 conference of the Centre for Advanced Studies on Collaborative research","author":"Vallee-Rai Raja","unstructured":"}} Raja Vallee-Rai , Phong Co , Etienne Gagnon , Laurie Hendren , Patrick Lam , and Vijay Sundaresan . Soot - a java bytecode optimization framework . In CASCON'99: Proceedings of the 1999 conference of the Centre for Advanced Studies on Collaborative research , page 13 . IBM Press, 1999. }}Raja Vallee-Rai, Phong Co, Etienne Gagnon, Laurie Hendren, Patrick Lam, and Vijay Sundaresan. Soot - a java bytecode optimization framework. In CASCON'99: Proceedings of the 1999 conference of the Centre for Advanced Studies on Collaborative research, page 13. IBM Press, 1999."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/1250734.1250739"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.5555\/800078.802557"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.21"},{"key":"e_1_3_2_1_50_1","volume-title":"Proceedings of the 18th USENIX Security Symposium","author":"Zhang Kehuan","year":"2009","unstructured":"}} Kehuan Zhang and XiaoFeng Wang . Peeping tom in the neighborhood: Keystroke eavesdropping on multi-user systems . In Proceedings of the 18th USENIX Security Symposium , Montreal, Canada , 2009 . USENIX Association. }}Kehuan Zhang and XiaoFeng Wang. Peeping tom in the neighborhood: Keystroke eavesdropping on multi-user systems. In Proceedings of the 18th USENIX Security Symposium, Montreal, Canada, 2009. USENIX Association."}],"event":{"name":"CCS '10: 17th ACM Conference on Computer and Communications Security 2010","location":"Chicago Illinois USA","acronym":"CCS '10","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 17th ACM conference on Computer and communications security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1866307.1866374","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1866307.1866374","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T12:08:59Z","timestamp":1750248539000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1866307.1866374"}},"subtitle":["automated detection and quantification of side-channel leaks in web application development"],"short-title":[],"issued":{"date-parts":[[2010,10,4]]},"references-count":48,"alternative-id":["10.1145\/1866307.1866374","10.1145\/1866307"],"URL":"https:\/\/doi.org\/10.1145\/1866307.1866374","relation":{},"subject":[],"published":{"date-parts":[[2010,10,4]]},"assertion":[{"value":"2010-10-04","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}