{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,27]],"date-time":"2026-02-27T03:47:29Z","timestamp":1772164049434,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":46,"publisher":"ACM","license":[{"start":{"date-parts":[[2013,1,23]],"date-time":"2013-01-23T00:00:00Z","timestamp":1358899200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2013,1,23]]},"DOI":"10.1145\/2429069.2429115","type":"proceedings-article","created":{"date-parts":[[2013,1,22]],"date-time":"2013-01-22T10:29:29Z","timestamp":1358850569000},"page":"385-398","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":30,"title":["Towards fully automatic placement of security sanitizers and declassifiers"],"prefix":"10.1145","author":[{"given":"Benjamin","family":"Livshits","sequence":"first","affiliation":[{"name":"Microsoft Research, Redmond, WA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stephen","family":"Chong","sequence":"additional","affiliation":[{"name":"Harvard University, Cambridge, MA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2013,1,23]]},"reference":[{"key":"e_1_3_2_2_1_1","volume-title":"Compilers: Principles, Techniques, and Tools","author":"Aho A. V.","year":"2007","unstructured":"A. V. Aho , M. Lam , R. Sethi , and J. D. Ullman . Compilers: Principles, Techniques, and Tools . Addison-Wesley , 2007 . A. V. Aho, M. Lam, R. Sethi, and J. D. Ullman. Compilers: Principles, Techniques, and Tools. Addison-Wesley, 2007."},{"key":"e_1_3_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1062455.1062520"},{"key":"e_1_3_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.22"},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/1772690.1772701"},{"key":"e_1_3_2_2_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/178243.178257"},{"key":"e_1_3_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1655121.1655125"},{"key":"e_1_3_2_2_8_1","volume-title":"Sif: enforcing confidentiality and integrity in Web applications. In phProceedings of Usenix Security Symposium","author":"Chong S.","year":"2007","unstructured":"S. Chong , K. Vikram , and A. C. Myers . Sif: enforcing confidentiality and integrity in Web applications. In phProceedings of Usenix Security Symposium , 2007 . S. Chong, K. Vikram, and A. C. Myers. Sif: enforcing confidentiality and integrity in Web applications. In phProceedings of Usenix Security Symposium, 2007."},{"key":"e_1_3_2_2_9_1","volume-title":"Proceedings of the Annual Network and Distributed System Security Symposium","author":"Egele M.","year":"2011","unstructured":"M. Egele , C. Kruegel , E. Kirda , and G. Vigna . PiOS: Detecting privacy leaks in iOS applications . In Proceedings of the Annual Network and Distributed System Security Symposium , Feb. 2011 . M. Egele, C. Kruegel, E. Kirda, and G. Vigna. PiOS: Detecting privacy leaks in iOS applications. In Proceedings of the Annual Network and Distributed System Security Symposium, Feb. 2011."},{"key":"e_1_3_2_2_10_1","volume-title":"Proceedings of the Usenix Conference on Operating Systems Design and Implementation","author":"Enck W.","year":"2010","unstructured":"W. Enck , P. Gilbert , B.-G. Chun , L. P. Cox , J. Jung , P. McDaniel , and A. N. Sheth . TaintDroid: an information-flow tracking system for realtime privacy monitoring on smartphones . In Proceedings of the Usenix Conference on Operating Systems Design and Implementation , 2010 . W. Enck, P. Gilbert, B.-G. Chun, L. P. Cox, J. Jung, P. McDaniel, and A. N. Sheth. TaintDroid: an information-flow tracking system for realtime privacy monitoring on smartphones. In Proceedings of the Usenix Conference on Operating Systems Design and Implementation, 2010."},{"key":"e_1_3_2_2_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2005.21"},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-009-0086-1"},{"key":"e_1_3_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISoLA.2006.39"},{"key":"e_1_3_2_2_14_1","volume-title":"IEEE International Symposium on Secure Software Engineering","author":"Hammer C.","year":"2006","unstructured":"C. Hammer , J. Krinke , and G. Snelting . Information flow control for java based on path conditions in dependence graphs . In IEEE International Symposium on Secure Software Engineering , Mar. 2006 . C. Hammer, J. Krinke, and G. Snelting. Information flow control for java based on path conditions in dependence graphs. In IEEE International Symposium on Secure Software Engineering, Mar. 2006."},{"key":"e_1_3_2_2_15_1","volume-title":"Proceedings of the Usenix Security Symposium","author":"Hooimeijer P.","year":"2011","unstructured":"P. Hooimeijer , B. Livshits , D. Molnar , P. Saxena , and M. Veanes . Fast and precise sanitizer analysis with BEK . In Proceedings of the Usenix Security Symposium , Aug. 2011 . P. Hooimeijer, B. Livshits, D. Molnar, P. Saxena, and M. Veanes. Fast and precise sanitizer analysis with BEK. In Proceedings of the Usenix Security Symposium, Aug. 2011."},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1002\/spe.371"},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/988672.988679"},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.29"},{"key":"e_1_3_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-11957-6_18"},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/989393.989439"},{"key":"e_1_3_2_2_21_1","volume-title":"Symposium on Operating Systems Design and Implementation","author":"Kremenek T.","year":"2006","unstructured":"T. Kremenek , P. Twohey , G. Back , A. Y. Ng , and D. R. Engler . From uncertainty to belief: Inferring the specification within . In Symposium on Operating Systems Design and Implementation , Nov. 2006 . T. Kremenek, P. Twohey, G. Back, A. Y. Ng, and D. R. Engler. From uncertainty to belief: Inferring the specification within. In Symposium on Operating Systems Design and Implementation, Nov. 2006."},{"key":"e_1_3_2_2_22_1","volume-title":"Proceedings of the Usenix Security Symposium","author":"Livshits B.","year":"2005","unstructured":"B. Livshits and M. S. Lam . Finding security errors in Java programs with static analysis . In Proceedings of the Usenix Security Symposium , 2005 . B. Livshits and M. S. Lam. Finding security errors in Java programs with static analysis. In Proceedings of the Usenix Security Symposium, 2005."},{"key":"e_1_3_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/1542476.1542485"},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/1094811.1094840"},{"key":"e_1_3_2_2_25_1","volume-title":"SecuriFly: runtime vulnerability protection for Web applications. Technical report","author":"Martin M.","year":"2006","unstructured":"M. Martin , B. Livshits , and M. S. Lam . SecuriFly: runtime vulnerability protection for Web applications. Technical report , Stanford University , 2006 . M. Martin, B. Livshits, and M. S. Lam. SecuriFly: runtime vulnerability protection for Web applications. Technical report, Stanford University, 2006."},{"key":"e_1_3_2_2_26_1","volume-title":"http:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=19968, 3","author":"Analysis Tool Microsoft Code","year":"2009","unstructured":"Microsoft Code Analysis Tool . NET (CAT.NET). http:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=19968, 3 2009 . Microsoft Code Analysis Tool .NET (CAT.NET). http:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=19968, 3 2009."},{"key":"e_1_3_2_2_27_1","volume-title":"http:\/\/wpl.codeplex.com\/","author":"Microsoft","year":"2012","unstructured":"Microsoft web protection library. http:\/\/wpl.codeplex.com\/ , 2012 . Microsoft web protection library. http:\/\/wpl.codeplex.com\/, 2012."},{"key":"e_1_3_2_2_28_1","volume-title":"Proceedings of the European Conference on Object-Oriented Programming, Systems, Languages, and Applications","author":"Mitchell N.","year":"2005","unstructured":"N. Mitchell , G. Sevitsky , and H. Srinivasan . The diary of a datum: an approach to modeling runtime complexity in framework-based applications . In Proceedings of the European Conference on Object-Oriented Programming, Systems, Languages, and Applications , 2005 . N. Mitchell, G. Sevitsky, and H. Srinivasan. The diary of a datum: an approach to modeling runtime complexity in framework-based applications. In Proceedings of the European Conference on Object-Oriented Programming, Systems, Languages, and Applications, 2005."},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1007\/0-387-25660-1_20"},{"key":"e_1_3_2_2_30_1","volume-title":"http:\/\/code.google.com\/p\/owasp-java-html-sanitizer\/","author":"OWASP.","year":"2011","unstructured":"OWASP. OWASP-Java-HTML-sanitizer. http:\/\/code.google.com\/p\/owasp-java-html-sanitizer\/ , 2011 . OWASP. OWASP-Java-HTML-sanitizer. http:\/\/code.google.com\/p\/owasp-java-html-sanitizer\/, 2011."},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/11663812_7"},{"key":"e_1_3_2_2_32_1","volume-title":"Proceedings of the Usenix Security Symposium","author":"Robertson W.","unstructured":"W. Robertson and G. Vigna . Static enforcement of web application integrity through strong typing . In Proceedings of the Usenix Security Symposium , 2009\\natexlaba. W. Robertson and G. Vigna. Static enforcement of web application integrity through strong typing. In Proceedings of the Usenix Security Symposium, 2009\\natexlaba."},{"key":"e_1_3_2_2_33_1","volume-title":"Proceedings of the Usenix Security Symposium","author":"Robertson W.","unstructured":"W. Robertson and G. Vigna . Static enforcement of web application integrity through strong typing . In Proceedings of the Usenix Security Symposium , Aug. 2009\\natexlabb. W. Robertson and G. Vigna. Static enforcement of web application integrity through strong typing. In Proceedings of the Usenix Security Symposium, Aug. 2009\\natexlabb."},{"key":"e_1_3_2_2_34_1","unstructured":"RSnake. XSS cheat sheet for filter evasion. http:\/\/ha.ckers.org\/xss.html.  RSnake. XSS cheat sheet for filter evasion. http:\/\/ha.ckers.org\/xss.html."},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/325694.325715"},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2002.806121"},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSFW.2005.15"},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046775"},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046776"},{"key":"e_1_3_2_2_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/1993498.1993539"},{"key":"e_1_3_2_2_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/1111037.1111070"},{"key":"e_1_3_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/1542476.1542486"},{"key":"e_1_3_2_2_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2011.20"},{"key":"e_1_3_2_2_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/2103656.2103674"},{"key":"e_1_3_2_2_46_1","volume-title":"Sept.","author":"Weinberger J.","year":"2011","unstructured":"J. Weinberger , P. Saxena , D. Akhawe , M. Finifter , R. Shin , and D. Song . A systematic analysis of XSS sanitization in web application frameworks. In phProceedings of the European Symposium on Research in Computer Security , Sept. 2011 . J. Weinberger, P. Saxena, D. Akhawe, M. Finifter, R. Shin, and D. Song. A systematic analysis of XSS sanitization in web application frameworks. In phProceedings of the European Symposium on Research in Computer Security, Sept. 2011."},{"key":"e_1_3_2_2_47_1","volume-title":"Proceedings of the Usenix Security Symposium","author":"Xie Y.","year":"2006","unstructured":"Y. Xie and A. Aiken . Static detection of security vulnerabilities in scripting languages . In Proceedings of the Usenix Security Symposium , 2006 . Y. Xie and A. Aiken. Static detection of security vulnerabilities in scripting languages. In Proceedings of the Usenix Security Symposium, 2006."},{"key":"e_1_3_2_2_48_1","unstructured":"E. Z. Yang. HTML purifier. http:\/\/code.google.com\/p\/owasp-java-html-sanitizer\/ 2011.  E. Z. Yang. HTML purifier. http:\/\/code.google.com\/p\/owasp-java-html-sanitizer\/ 2011."}],"event":{"name":"POPL '13: The 40th Annual ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages","location":"Rome Italy","acronym":"POPL '13","sponsor":["SIGPLAN ACM Special Interest Group on Programming Languages","SIGACT ACM Special Interest Group on Algorithms and Computation Theory"]},"container-title":["Proceedings of the 40th annual ACM SIGPLAN-SIGACT symposium on Principles of programming languages"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2429069.2429115","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2429069.2429115","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:35:35Z","timestamp":1750221335000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2429069.2429115"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013,1,23]]},"references-count":46,"alternative-id":["10.1145\/2429069.2429115","10.1145\/2429069"],"URL":"https:\/\/doi.org\/10.1145\/2429069.2429115","relation":{"is-identical-to":[{"id-type":"doi","id":"10.1145\/2480359.2429115","asserted-by":"object"}]},"subject":[],"published":{"date-parts":[[2013,1,23]]},"assertion":[{"value":"2013-01-23","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}