{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:20:02Z","timestamp":1750306802176,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":37,"publisher":"ACM","license":[{"start":{"date-parts":[[2014,3,24]],"date-time":"2014-03-24T00:00:00Z","timestamp":1395619200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2014,3,24]]},"DOI":"10.1145\/2554850.2555071","type":"proceedings-article","created":{"date-parts":[[2014,7,22]],"date-time":"2014-07-22T15:08:30Z","timestamp":1406041710000},"page":"1164-1170","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":7,"title":["Risk assessment of code injection vulnerabilities using fuzzy logic-based system"],"prefix":"10.1145","author":[{"given":"Hossain","family":"Shahriar","sequence":"first","affiliation":[{"name":"Kennesaw State University, Kennesaw, GA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hisham","family":"Haddad","sequence":"additional","affiliation":[{"name":"Kennesaw State University, Kennesaw, GA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2014,3,24]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"SQL Injection https:\/\/www.owasp.org\/index.php\/SQL_Injection.  SQL Injection https:\/\/www.owasp.org\/index.php\/SQL_Injection."},{"key":"e_1_3_2_1_2_1","unstructured":"Cross-site Scripting (XSS) Accessed from https:\/\/www.owasp.org\/index.php\/Cross-site_Scripting_(XSS).  Cross-site Scripting (XSS) Accessed from https:\/\/www.owasp.org\/index.php\/Cross-site_Scripting_(XSS)."},{"key":"e_1_3_2_1_3_1","unstructured":"OWASP Top 10 2013 Accessed from https:\/\/www.owasp.org\/index.php\/Top_10_2013-Top_10  OWASP Top 10 2013 Accessed from https:\/\/www.owasp.org\/index.php\/Top_10_2013-Top_10"},{"key":"e_1_3_2_1_4_1","volume-title":"July","author":"Schaffer R.","year":"2012","unstructured":"R. Schaffer , National Information Assurance Glossary , July 2012 , http:\/\/www.cnss.gov\/Assets\/pdf\/cnssi_4009.pdf. R. Schaffer, National Information Assurance Glossary, July 2012, http:\/\/www.cnss.gov\/Assets\/pdf\/cnssi_4009.pdf."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"crossref","unstructured":"C. May M. Baker D. Gabbard T. Good G. Grimes M. Holmgren R. Nolan R. Nowark and S. Pennline Advanced Information Assurance Handbook CMU\/SEI-2004-HB-001.  C. May M. Baker D. Gabbard T. Good G. Grimes M. Holmgren R. Nolan R. Nowark and S. Pennline Advanced Information Assurance Handbook CMU\/SEI-2004-HB-001.","DOI":"10.21236\/ADA443478"},{"key":"e_1_3_2_1_6_1","unstructured":"March 2004. XSS Session Hijacking proof of concept http:\/\/msujaws.wordpress.com\/2011\/02\/17\/xss-session-hijacking-proof-of-concept\/.  March 2004. XSS Session Hijacking proof of concept http:\/\/msujaws.wordpress.com\/2011\/02\/17\/xss-session-hijacking-proof-of-concept\/."},{"key":"e_1_3_2_1_7_1","unstructured":"W3af Open Source Web Application Security Scanner http:\/\/w3af.org.  W3af Open Source Web Application Security Scanner http:\/\/w3af.org."},{"key":"e_1_3_2_1_8_1","unstructured":"Sqlifuzzer http:\/\/code.google.com\/p\/sqlifuzzer.  Sqlifuzzer http:\/\/code.google.com\/p\/sqlifuzzer."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1049\/iet-sen.2011.0084"},{"key":"e_1_3_2_1_10_1","unstructured":"SQL-inject-me https:\/\/addons.mozilla.org\/en-us\/firefox\/addon\/sql-inject-me\/.  SQL-inject-me https:\/\/addons.mozilla.org\/en-us\/firefox\/addon\/sql-inject-me\/."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/TFUZZ.2002.806316"},{"key":"e_1_3_2_1_12_1","first-page":"116","volume-title":"LNCS","volume":"1910","author":"Han E.","year":"2000","unstructured":"E. Han and G. Karypis , \" Centroid-based Document Classification: Analysis and Experimental Results,\" Principles of Data Mining and Knowledge Discovery , LNCS , Volume 1910 , 2000 , pp. 116 -- 123 . E. Han and G. Karypis, \"Centroid-based Document Classification: Analysis and Experimental Results,\" Principles of Data Mining and Knowledge Discovery, LNCS, Volume 1910, 2000, pp. 116--123."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSYST.2011.2134730"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/17.18829"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1007\/0-387-31167-X_12"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1016\/0167-4048(96)00008-9"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/5254.850830"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1049\/piee.1974.0328"},{"key":"e_1_3_2_1_19_1","volume-title":"Symposium on Secure Software Engineering","author":"Halfond W. G.","year":"2006","unstructured":"W. G. Halfond , J. Viegas , and A. Orso , \" A Classification of SQL-Injection Attacks and Countermeasures,\" Proc. of the Int . Symposium on Secure Software Engineering , Mar. 2006 . W. G. Halfond, J. Viegas, and A. Orso, \"A Classification of SQL-Injection Attacks and Countermeasures,\" Proc. of the Int. Symposium on Secure Software Engineering, Mar. 2006."},{"key":"e_1_3_2_1_20_1","unstructured":"SQL Injection Walkthrough Accessed from http:\/\/www.securiteam.com\/securityreviews\/5DP0N1P76E.html.  SQL Injection Walkthrough Accessed from http:\/\/www.securiteam.com\/securityreviews\/5DP0N1P76E.html."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISA.2008.50"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2010.04.044"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.5555\/1671729.1671767"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/DASC.2011.45"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2007.70240"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSYST.2011.2134730"},{"key":"e_1_3_2_1_27_1","first-page":"25","volume-title":"CZ","author":"Hanacek P","unstructured":"P Hanacek , P. Peringer , and Z. Rabova , \" Knowledge-based Approach to Risk Analysis Modelling,\" Proc. of JCKBSE 2000, Brno , CZ , pp. 25 -- 30 , http:\/\/www.fit.vutbr.cz\/~hanacek\/papers\/JCKBSE00.pdf. P Hanacek, P. Peringer, and Z. Rabova, \"Knowledge-based Approach to Risk Analysis Modelling,\" Proc. of JCKBSE 2000, Brno, CZ, pp. 25--30, http:\/\/www.fit.vutbr.cz\/~hanacek\/papers\/JCKBSE00.pdf."},{"key":"e_1_3_2_1_28_1","first-page":"2823","volume-title":"Baoding","author":"Sanguansat K.","year":"2009","unstructured":"K. Sanguansat and S. Chen , \" A New Method for Analyzing Fuzzy Risk Based on A New Fuzzy Ranking Method Between Generalized Fuzzy Numbers,\" Proc. of the 8th International Conf. on Machine Learning and Cyber Security , Baoding , China , 2009 , pp. 2823 -- 2827 . K. Sanguansat and S. Chen, \"A New Method for Analyzing Fuzzy Risk Based on A New Fuzzy Ranking Method Between Generalized Fuzzy Numbers,\" Proc. of the 8th International Conf. on Machine Learning and Cyber Security, Baoding, China, 2009, pp. 2823--2827."},{"key":"e_1_3_2_1_29_1","first-page":"1","volume-title":"Proc. of the International Conf. on Information Science and Applications","author":"Kim J.","year":"2011","unstructured":"J. Kim , \" Injection Attack Detection Using the Removal of SQL Query Attribute Values ,\" Proc. of the International Conf. on Information Science and Applications , Jeju, Korea , 2011 , pp. 1 -- 7 . J. Kim, \"Injection Attack Detection Using the Removal of SQL Query Attribute Values,\" Proc. of the International Conf. on Information Science and Applications, Jeju, Korea, 2011, pp. 1--7."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/1108473.1108496"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/ITNG.2012.167"},{"key":"e_1_3_2_1_32_1","first-page":"107","volume-title":"Miami","author":"Kosuga Y.","year":"2007","unstructured":"Y. Kosuga , K. Kono , M. Hanaoka , M. Hishiyama , Y. Takahama , \"Sania : Syntactic and Semantic Analysis for Automated Testing against SQL Injection,\" Proc. of the 23rd Annual Computer Security Applications Conference (ACSAC) , Miami , Dec 2007 , pp. 107 -- 117 . Y. Kosuga, K. Kono, M. Hanaoka, M. Hishiyama, Y. Takahama, \"Sania: Syntactic and Semantic Analysis for Automated Testing against SQL Injection,\" Proc. of the 23rd Annual Computer Security Applications Conference (ACSAC), Miami, Dec 2007, pp. 107--117."},{"key":"e_1_3_2_1_33_1","unstructured":"CVSS Scoring System http:\/\/nvd.nist.gov\/cvss.cfm  CVSS Scoring System http:\/\/nvd.nist.gov\/cvss.cfm"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/DASC.2011.26"},{"key":"e_1_3_2_1_35_1","article-title":"Design and Development of Anti-XSS Proxy","author":"Shahriar H.","year":"2013","unstructured":"H. Shahriar , S. North , W. Chen , and E. Mawangi , \" Design and Development of Anti-XSS Proxy ,\" Proc. of the 8th International Conference for Internet Technology and Secured Transactions (ICITST) , December 2013 , London, UK, 6 pp. (to appear). H. Shahriar, S. North, W. Chen, and E. Mawangi, \"Design and Development of Anti-XSS Proxy,\" Proc. of the 8th International Conference for Internet Technology and Secured Transactions (ICITST), December 2013, London, UK, 6 pp. (to appear).","journal-title":"Proc. of the 8th International Conference for Internet Technology and Secured Transactions (ICITST)"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/HASE.2012.31"},{"key":"e_1_3_2_1_37_1","unstructured":"jFuzzyLogic http:\/\/jfuzzylogic.sourceforge.net.  jFuzzyLogic http:\/\/jfuzzylogic.sourceforge.net."}],"event":{"name":"SAC 2014: Symposium on Applied Computing","sponsor":["SIGAPP ACM Special Interest Group on Applied Computing"],"location":"Gyeongju Republic of Korea","acronym":"SAC 2014"},"container-title":["Proceedings of the 29th Annual ACM Symposium on Applied Computing"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2554850.2555071","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2554850.2555071","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T07:34:48Z","timestamp":1750232088000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2554850.2555071"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,3,24]]},"references-count":37,"alternative-id":["10.1145\/2554850.2555071","10.1145\/2554850"],"URL":"https:\/\/doi.org\/10.1145\/2554850.2555071","relation":{},"subject":[],"published":{"date-parts":[[2014,3,24]]},"assertion":[{"value":"2014-03-24","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}