{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,16]],"date-time":"2025-10-16T03:49:01Z","timestamp":1760586541030,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":46,"publisher":"ACM","license":[{"start":{"date-parts":[[2010,12,6]],"date-time":"2010-12-06T00:00:00Z","timestamp":1291593600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000144","name":"Division of Computer and Network Systems","doi-asserted-by":"publisher","award":["CNS-0716292CNS-1017782"],"award-info":[{"award-number":["CNS-0716292CNS-1017782"]}],"id":[{"id":"10.13039\/100000144","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2010,12,6]]},"DOI":"10.1145\/1920261.1920289","type":"proceedings-article","created":{"date-parts":[[2010,12,20]],"date-time":"2010-12-20T16:13:47Z","timestamp":1292861627000},"page":"181-190","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["FIRM"],"prefix":"10.1145","author":[{"given":"Zhou","family":"Li","sequence":"first","affiliation":[{"name":"Indiana University, Bloomington"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"XiaoFeng","family":"Wang","sequence":"additional","affiliation":[{"name":"Indiana University, Bloomington"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2010,12,6]]},"reference":[{"unstructured":"Adobe flash cs4. http:\/\/www.adobe.com\/products\/flash\/.  Adobe flash cs4. http:\/\/www.adobe.com\/products\/flash\/.","key":"e_1_3_2_1_1_1"},{"unstructured":"Adobe flash player clipboard security weakness. http:\/\/www.securityfocus.com\/bid\/31117.  Adobe flash player clipboard security weakness. http:\/\/www.securityfocus.com\/bid\/31117.","key":"e_1_3_2_1_2_1"},{"unstructured":"Antlr parser generator. http:\/\/www.antlr.org\/.  Antlr parser generator. http:\/\/www.antlr.org\/.","key":"e_1_3_2_1_3_1"},{"unstructured":"Bbcode. http:\/\/www.bbcode.org\/.  Bbcode. http:\/\/www.bbcode.org\/.","key":"e_1_3_2_1_4_1"},{"unstructured":"Cnn. http:\/\/http:\/\/www.cnn.com.  Cnn. http:\/\/http:\/\/www.cnn.com.","key":"e_1_3_2_1_5_1"},{"unstructured":"drupal community pluminbing. http:\/\/drupal.org.  drupal community pluminbing. http:\/\/drupal.org.","key":"e_1_3_2_1_6_1"},{"unstructured":"Ecmascript. http:\/\/www.ecmascript.org.  Ecmascript. http:\/\/www.ecmascript.org.","key":"e_1_3_2_1_7_1"},{"unstructured":"Flash url parameter attacks. http:\/\/code.google.com\/p\/doctype\/wiki\/ArticleFlashSecurityURL.  Flash url parameter attacks. http:\/\/code.google.com\/p\/doctype\/wiki\/ArticleFlashSecurityURL.","key":"e_1_3_2_1_8_1"},{"unstructured":"Kimili flash embed. http:\/\/kimili.com\/plugins\/kml_flashembed\/.  Kimili flash embed. http:\/\/kimili.com\/plugins\/kml_flashembed\/.","key":"e_1_3_2_1_9_1"},{"unstructured":"Mashup dashboard - programmableweb. http:\/\/www.programmableweb.com\/mashups.  Mashup dashboard - programmableweb. http:\/\/www.programmableweb.com\/mashups.","key":"e_1_3_2_1_10_1"},{"unstructured":"phpbb - creating communities worldwide. http:\/\/www.phpBB.com.  phpbb - creating communities worldwide. http:\/\/www.phpBB.com.","key":"e_1_3_2_1_11_1"},{"unstructured":"Standard ecma-262. http:\/\/www.ecma-international.org\/publications\/standards\/Ecma-262.htm.  Standard ecma-262. http:\/\/www.ecma-international.org\/publications\/standards\/Ecma-262.htm.","key":"e_1_3_2_1_12_1"},{"unstructured":"Swfscan. https:\/\/h30406.www3.hp.com\/campaigns\/2009\/wwcampaign\/1-5TUVE\/index.php?key=swf.  Swfscan. https:\/\/h30406.www3.hp.com\/campaigns\/2009\/wwcampaign\/1-5TUVE\/index.php?key=swf.","key":"e_1_3_2_1_13_1"},{"unstructured":"Wordpress - blog tool and publishing platform. http:\/\/wordpress.org.  Wordpress - blog tool and publishing platform. http:\/\/wordpress.org.","key":"e_1_3_2_1_14_1"},{"unstructured":"Yahoo! http:\/\/www.yahoo.com.  Yahoo! http:\/\/www.yahoo.com.","key":"e_1_3_2_1_15_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_16_1","DOI":"10.1145\/1102120.1102165"},{"unstructured":"Adobe. Flash player security - controlling outbound url access. http:\/\/help.adobe.com\/en_US\/ActionScript\/3.0_ProgrammingAS3\/WS5b3ccc516d4fbf351e63e3d118a9b90204-7c9b.html 2009.  Adobe. Flash player security - controlling outbound url access. http:\/\/help.adobe.com\/en_US\/ActionScript\/3.0_ProgrammingAS3\/WS5b3ccc516d4fbf351e63e3d118a9b90204-7c9b.html 2009.","key":"e_1_3_2_1_17_1"},{"key":"e_1_3_2_1_18_1","volume-title":"IBM, As of","author":"Baror Y.","year":"2008","unstructured":"Y. Baror , A. Yogev , and A. Sharabani . Flash parameter injection. Technical report , IBM, As of September 2008 . Y. Baror, A. Yogev, and A. Sharabani. Flash parameter injection. Technical report, IBM, As of September 2008."},{"key":"e_1_3_2_1_19_1","volume-title":"Proceedings of Web 2.0 Security and Privacy 2009 (W2SP 2009)","author":"Barth A.","year":"2009","unstructured":"A. Barth , C. Jackson , and W. Li . Attacks on javascript mashup communication . In Proceedings of Web 2.0 Security and Privacy 2009 (W2SP 2009) , 2009 . A. Barth, C. Jackson, and W. Li. Attacks on javascript mashup communication. In Proceedings of Web 2.0 Security and Privacy 2009 (W2SP 2009), 2009."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_20_1","DOI":"10.1145\/1065010.1065047"},{"unstructured":"S. Chenette. Malicious flash redirectors - security labs blog. http:\/\/securitylabs.websense.com\/content\/Blogs\/3165.aspx 2008.  S. Chenette. Malicious flash redirectors - security labs blog. http:\/\/securitylabs.websense.com\/content\/Blogs\/3165.aspx 2008.","key":"e_1_3_2_1_21_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_22_1","DOI":"10.1145\/1455770.1455784"},{"unstructured":"DP. Flash clicktag parameter xss. banks e-shops adobe and others vulnerable. http:\/\/xssed.org\/news\/98\/Flash_clickTAG_parameter_XSS._Banks_e-shops_Adobe_and_others_vulnerable\/ 2009.  DP. Flash clicktag parameter xss. banks e-shops adobe and others vulnerable. http:\/\/xssed.org\/news\/98\/Flash_clickTAG_parameter_XSS._Banks_e-shops_Adobe_and_others_vulnerable\/ 2009.","key":"e_1_3_2_1_23_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_24_1","DOI":"10.5555\/882494.884407"},{"volume-title":"http:\/\/code.google.com\/p\/google-caja\/wiki\/AttackVectors","year":"2010","unstructured":"Google. Attackvectors. http:\/\/code.google.com\/p\/google-caja\/wiki\/AttackVectors , 2010 . Google. Attackvectors. http:\/\/code.google.com\/p\/google-caja\/wiki\/AttackVectors, 2010.","key":"e_1_3_2_1_25_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_26_1","DOI":"10.1109\/SP.2008.19"},{"key":"e_1_3_2_1_27_1","volume-title":"Proceedings of the USENIX Security Symposium","author":"Guarnieri S.","year":"2009","unstructured":"S. Guarnieri and B. Livshits . Gatekeeper: Mostly static enforcement of security and reliability policies for javascript code . In Proceedings of the USENIX Security Symposium , Montreal, Canada , August 2009 . S. Guarnieri and B. Livshits. Gatekeeper: Mostly static enforcement of security and reliability policies for javascript code. In Proceedings of the USENIX Security Symposium, Montreal, Canada, August 2009."},{"key":"e_1_3_2_1_28_1","volume-title":"NDSS'09: Proceedings of the 16th Network and Distributed System Security Symposium","author":"Gundy M. V.","year":"2009","unstructured":"M. V. Gundy and H. Chen . Noncespaces: Using randomization to enforce information flow tracking and thwart cross-site scripting attacks . In NDSS'09: Proceedings of the 16th Network and Distributed System Security Symposium , 2009 . M. V. Gundy and H. Chen. Noncespaces: Using randomization to enforce information flow tracking and thwart cross-site scripting attacks. In NDSS'09: Proceedings of the 16th Network and Distributed System Security Symposium, 2009."},{"key":"e_1_3_2_1_29_1","volume-title":"Black Hat DC 2009","author":"Jagdale P.","year":"2009","unstructured":"P. Jagdale . Blinded by flash: Widespread security risks flash developers don't see . In Black Hat DC 2009 . Hewlett-Packard , 2009 . P. Jagdale. Blinded by flash: Widespread security risks flash developers don't see. In Black Hat DC 2009. Hewlett-Packard, 2009."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_30_1","DOI":"10.1145\/1242572.1242654"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_31_1","DOI":"10.1145\/948109.948146"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_32_1","DOI":"10.1145\/1141277.1141357"},{"key":"e_1_3_2_1_33_1","volume-title":"Butterworth-Heinemann","author":"Levy H. M.","year":"1984","unstructured":"H. M. Levy . Capability-Based Computer Systems . Butterworth-Heinemann , Newton, MA, USA , 1984 . H. M. Levy. Capability-Based Computer Systems. Butterworth-Heinemann, Newton, MA, USA, 1984."},{"key":"e_1_3_2_1_34_1","volume-title":"6th OWASP AppSec Conference","author":"Paola S. D.","year":"2007","unstructured":"S. D. Paola . Testing flash applications . In 6th OWASP AppSec Conference , 2007 . S. D. Paola. Testing flash applications. In 6th OWASP AppSec Conference, 2007."},{"unstructured":"I. Parakey. Firebug - web development evolved. http:\/\/getfirebug.com\/ 2009.  I. Parakey. Firebug - web development evolved. http:\/\/getfirebug.com\/ 2009.","key":"e_1_3_2_1_35_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_36_1","DOI":"10.1145\/1533057.1533067"},{"key":"e_1_3_2_1_37_1","volume-title":"Proc. OSDI","author":"Reis C.","year":"2006","unstructured":"C. Reis , J. Dunagan , H. J. Wang , O. Dubrovsky , and S. Esmeir . Browsershield: Vulnerability-driven filtering of dynamic html . In Proc. OSDI , 2006 . C. Reis, J. Dunagan, H. J. Wang, O. Dubrovsky, and S. Esmeir. Browsershield: Vulnerability-driven filtering of dynamic html. In Proc. OSDI, 2006."},{"unstructured":"J. Ruderman. The same origin policy. http:\/\/www.mozilla.org\/projects\/security\/components\/same-origin.html 2008.  J. Ruderman. The same origin policy. http:\/\/www.mozilla.org\/projects\/security\/components\/same-origin.html 2008.","key":"e_1_3_2_1_38_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_39_1","DOI":"10.1109\/JSAC.2002.806121"},{"key":"e_1_3_2_1_40_1","volume-title":"Proceedings of the USENIX Security Symposium","author":"Singh K.","year":"2009","unstructured":"K. Singh , S. Bhola , and W. Lee . xbook: Redesigning privacy control in social networking platforms . In Proceedings of the USENIX Security Symposium , Montreal, Canada , August 2009 . K. Singh, S. Bhola, and W. Lee. xbook: Redesigning privacy control in social networking platforms. In Proceedings of the USENIX Security Symposium, Montreal, Canada, August 2009."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_41_1","DOI":"10.1007\/978-3-642-11503-5_13"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_42_1","DOI":"10.1109\/ACSAC.2009.42"},{"key":"e_1_3_2_1_43_1","volume-title":"30th IEEE Symposium on Security and Privacy","author":"Ter Louw M.","year":"2009","unstructured":"M. Ter Louw and V. Venkatakrishnan . Blueprint: Precise browser-neutral prevention of cross-site scripting attacks . In 30th IEEE Symposium on Security and Privacy , May 2009 . M. Ter Louw and V. Venkatakrishnan. Blueprint: Precise browser-neutral prevention of cross-site scripting attacks. In 30th IEEE Symposium on Security and Privacy, May 2009."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_44_1","DOI":"10.1145\/1294261.1294263"},{"key":"e_1_3_2_1_45_1","volume-title":"Proceedings of the 15th USENIX Security Symposium","author":"Xu W.","year":"2006","unstructured":"W. Xu , S. Bhatkar , and R. Sekar . Taint-enhanced policy enforcement: A practical approach to defeat a wide range of attacks . In Proceedings of the 15th USENIX Security Symposium , Vancouver, BC, Canada , August 2006 . W. Xu, S. Bhatkar, and R. Sekar. Taint-enhanced policy enforcement: A practical approach to defeat a wide range of attacks. In Proceedings of the 15th USENIX Security Symposium, Vancouver, BC, Canada, August 2006."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_46_1","DOI":"10.1145\/1519065.1519091"}],"event":{"sponsor":["ACSA Applied Computing Security Assoc"],"acronym":"ACSAC '10","name":"ACSAC '10: 2010 Annual Computer Security Applications Conference","location":"Austin Texas USA"},"container-title":["Proceedings of the 26th Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1920261.1920289","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1920261.1920289","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T20:22:43Z","timestamp":1750278163000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1920261.1920289"}},"subtitle":["capability-based inline mediation of Flash behaviors"],"short-title":[],"issued":{"date-parts":[[2010,12,6]]},"references-count":46,"alternative-id":["10.1145\/1920261.1920289","10.1145\/1920261"],"URL":"https:\/\/doi.org\/10.1145\/1920261.1920289","relation":{},"subject":[],"published":{"date-parts":[[2010,12,6]]},"assertion":[{"value":"2010-12-06","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}