{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,29]],"date-time":"2025-08-29T10:23:51Z","timestamp":1756463031025,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":32,"publisher":"ACM","license":[{"start":{"date-parts":[[2015,4,13]],"date-time":"2015-04-13T00:00:00Z","timestamp":1428883200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2015,4,13]]},"DOI":"10.1145\/2695664.2695946","type":"proceedings-article","created":{"date-parts":[[2015,7,20]],"date-time":"2015-07-20T19:10:09Z","timestamp":1437419409000},"page":"791-797","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Security assessment of clickjacking risks in web applications"],"prefix":"10.1145","author":[{"given":"Hossain","family":"Shahriar","sequence":"first","affiliation":[{"name":"Kennesaw State University, Kennesaw, GA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hisham","family":"Haddad","sequence":"additional","affiliation":[{"name":"Kennesaw State University, Kennesaw, GA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2015,4,13]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"www.owasp.org\/index.php\/Top_10_2010-Main","author":"Web Application Security The Open","year":"2010","unstructured":"The Open Web Application Security Project (OWASP) Top 10 , www.owasp.org\/index.php\/Top_10_2010-Main , 2010 . The Open Web Application Security Project (OWASP) Top 10, www.owasp.org\/index.php\/Top_10_2010-Main, 2010."},{"key":"e_1_3_2_1_2_1","volume-title":"www.owasp.org\/index.php\/Top_10_2013-Top_10","author":"Web Application Security The Open","year":"2013","unstructured":"The Open Web Application Security Project (OWASP) Top 10 , www.owasp.org\/index.php\/Top_10_2013-Top_10 , 2013 . The Open Web Application Security Project (OWASP) Top 10, www.owasp.org\/index.php\/Top_10_2013-Top_10, 2013."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/2643134"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2009.5070521"},{"key":"e_1_3_2_1_5_1","first-page":"107","volume-title":"Miami","author":"Kosuga Y.","year":"2007","unstructured":"Y. Kosuga , K. Kono , M. Hanaoka , M. Hishiyama , Y. Takahama , \"Sania : Syntactic and Semantic Analysis for Automated Testing against SQL Injection,\" Proc. of the 23rd Annual Computer Security Applications Conference (ACSAC) , Miami , Dec 2007 , pp. 107 -- 117 . Y. Kosuga, K. Kono, M. Hanaoka, M. Hishiyama, Y. Takahama, \"Sania: Syntactic and Semantic Analysis for Automated Testing against SQL Injection,\" Proc. of the 23rd Annual Computer Security Applications Conference (ACSAC), Miami, Dec 2007, pp. 107--117."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/ITNG.2012.167"},{"key":"e_1_3_2_1_7_1","first-page":"1","volume-title":"Proc. of the International Conference on Information Science and Applications (ICISA)","author":"Kim J.","year":"2011","unstructured":"J. Kim , \" Injection Attack Detection Using the Removal of SQL Query Attribute Values ,\" Proc. of the International Conference on Information Science and Applications (ICISA) , Jeju Island, Korea , May 2011 , pp. 1 -- 7 . J. Kim, \"Injection Attack Detection Using the Removal of SQL Query Attribute Values,\" Proc. of the International Conference on Information Science and Applications (ICISA), Jeju Island, Korea, May 2011, pp. 1--7."},{"key":"e_1_3_2_1_8_1","volume-title":"Accessed from http:\/\/www.sectheory.com\/clickjacking.htm","author":"Hansen R.","year":"2008","unstructured":"R. Hansen and J. Grossman , Clickjacking , Accessed from http:\/\/www.sectheory.com\/clickjacking.htm , 2008 . R. Hansen and J. Grossman, Clickjacking, Accessed from http:\/\/www.sectheory.com\/clickjacking.htm, 2008."},{"key":"e_1_3_2_1_9_1","unstructured":"Clickjacking https:\/\/www.owasp.org\/index.php\/Clickjacking  Clickjacking https:\/\/www.owasp.org\/index.php\/Clickjacking"},{"key":"e_1_3_2_1_10_1","unstructured":"F. Aboukhadijeh. HOW TO: Spy on the Webcams of Your Website Visitors. http:\/\/www.feross.org\/webcam-spy October 2011.  F. Aboukhadijeh. HOW TO: Spy on the Webcams of Your Website Visitors. http:\/\/www.feross.org\/webcam-spy October 2011."},{"key":"e_1_3_2_1_11_1","volume-title":"Trend Micro Report","author":"McCarthy-Kaplan S.","year":"2013","unstructured":"S. McCarthy-Kaplan , How I Got Clickjacked , Trend Micro Report , February 2013 . Accessed from http:\/\/blog.trendmicro.com\/how-igot-clickjacked S. McCarthy-Kaplan, How I Got Clickjacked, Trend Micro Report, February 2013. Accessed from http:\/\/blog.trendmicro.com\/how-igot-clickjacked"},{"key":"e_1_3_2_1_12_1","volume-title":"Feb","author":"Mills E.","year":"2009","unstructured":"E. Mills , Twitter Hit With Don't Click Clickjacking Attack , Feb 2009 , Accessed from http:\/\/www.cnet.com\/news\/twitter-hit-with-dont-click-clickjacking-attack\/ E. Mills, Twitter Hit With Don't Click Clickjacking Attack, Feb 2009, Accessed from http:\/\/www.cnet.com\/news\/twitter-hit-with-dont-click-clickjacking-attack\/"},{"volume-title":"August","year":"2013","key":"e_1_3_2_1_13_1","unstructured":"ZoneAlarm , FaceBook Clickjacking Scams , August 2013 , http:\/\/www.zonealarm.com\/blog\/2013\/08\/facebook-clickjackingscams\/ ZoneAlarm, FaceBook Clickjacking Scams, August 2013, http:\/\/www.zonealarm.com\/blog\/2013\/08\/facebook-clickjackingscams\/"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/1755688.1755706"},{"key":"e_1_3_2_1_15_1","volume-title":"USA","author":"Huang L.","year":"2012","unstructured":"L. Huang , A. Moshchuk , H. Wang , S. Schechter , and C. Jackson , \" Clickjacking: Attacks and Defenses,\" Proc. of USENIX Security 2012, Bellevue, WA , USA , August 2012 . L. Huang, A. Moshchuk, H. Wang, S. Schechter, and C. Jackson, \"Clickjacking: Attacks and Defenses,\" Proc. of USENIX Security 2012, Bellevue, WA, USA, August 2012."},{"key":"e_1_3_2_1_16_1","volume-title":"Busting frame busting: a study of clickjacking vulnerabilities at popular sites,\" Proc. of the Web 2.0 Security and Privacy","author":"Rydstedt G.","year":"2010","unstructured":"G. Rydstedt , E. Bursztein , D. Boneh , and C. Jackson , \" Busting frame busting: a study of clickjacking vulnerabilities at popular sites,\" Proc. of the Web 2.0 Security and Privacy , 2010 . G. Rydstedt, E. Bursztein, D. Boneh, and C. Jackson, \"Busting frame busting: a study of clickjacking vulnerabilities at popular sites,\" Proc. of the Web 2.0 Security and Privacy, 2010."},{"key":"e_1_3_2_1_17_1","volume-title":"USA","author":"Lekies S.","year":"2012","unstructured":"S. Lekies , M. Heiderich , D. Appelt , T. Holz and M. Johns , \" On the fragility and limitations of current Browser-provided Clickjacking protection schemes\" Proc. of the 6th USENIX Workshop on Offensive Technologies (WOOT'12), Bellevue, WA , USA , August 2012 . S. Lekies, M. Heiderich, D. Appelt, T. Holz and M. Johns, \"On the fragility and limitations of current Browser-provided Clickjacking protection schemes\" Proc. of the 6th USENIX Workshop on Offensive Technologies (WOOT'12), Bellevue, WA, USA, August 2012."},{"key":"e_1_3_2_1_18_1","volume-title":"Quantifying Software Security Risk,\" Proc. of Workshop on Software Security Assurance Tools, Techniques, and Metrics","author":"Chess B.","year":"2006","unstructured":"B. Chess , \" Metrics That Matter : Quantifying Software Security Risk,\" Proc. of Workshop on Software Security Assurance Tools, Techniques, and Metrics , National Institute of Standards And Technology , February 2006 . B. Chess, \"Metrics That Matter: Quantifying Software Security Risk,\" Proc. of Workshop on Software Security Assurance Tools, Techniques, and Metrics, National Institute of Standards And Technology, February 2006."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/1566445.1566509"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/1314257.1314266"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/1774088.1774478"},{"key":"e_1_3_2_1_22_1","unstructured":"J. Li Clickjacking Defense October 2010 Accessed from https:\/\/www.codemagi.com\/blog\/post\/194  J. Li Clickjacking Defense October 2010 Accessed from https:\/\/www.codemagi.com\/blog\/post\/194"},{"key":"e_1_3_2_1_23_1","unstructured":"Noscript http:\/\/noscript.net  Noscript http:\/\/noscript.net"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/2523514.2523538"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/2435349.2435394"},{"key":"e_1_3_2_1_26_1","unstructured":"P. Mell K. Scarfone and S. Romanosky \"A Complete Guide to the Common Vulnerability Scoring System (CVSS) \" Version 2.0 Forum of Incident Response and Security Teams http:\/\/www.first.org\/cvss\/cvss-guide.html.  P. Mell K. Scarfone and S. Romanosky \"A Complete Guide to the Common Vulnerability Scoring System (CVSS) \" Version 2.0 Forum of Incident Response and Security Teams http:\/\/www.first.org\/cvss\/cvss-guide.html."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/1413140.1413191"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/2523501.2523507"},{"key":"e_1_3_2_1_29_1","unstructured":"Clickjacking Defense CheatSheet Accessed from https:\/\/www.owasp.org\/index.php\/Clickjacking_Defense_Cheat_Sheet.  Clickjacking Defense CheatSheet Accessed from https:\/\/www.owasp.org\/index.php\/Clickjacking_Defense_Cheat_Sheet."},{"key":"e_1_3_2_1_30_1","unstructured":"XSS Filter Evasion CheatSheet Accessed from https:\/\/www.owasp.org\/index.php\/XSS_Filter_Evasion_Cheat_Sheet#No_Filter_Evasion  XSS Filter Evasion CheatSheet Accessed from https:\/\/www.owasp.org\/index.php\/XSS_Filter_Evasion_Cheat_Sheet#No_Filter_Evasion"},{"key":"e_1_3_2_1_31_1","unstructured":"Understanding Stacking Context Accessed from https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/Guide\/CSS\/Understanding_z_index\/Stacking_context_example_1  Understanding Stacking Context Accessed from https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/Guide\/CSS\/Understanding_z_index\/Stacking_context_example_1"},{"key":"e_1_3_2_1_32_1","unstructured":"Marcus Niemietz UI Redressing: Attacks and Countermeasures Revisited http:\/\/ui-redressing.mniemietz.de\/uiRedressing.pdf  Marcus Niemietz UI Redressing: Attacks and Countermeasures Revisited http:\/\/ui-redressing.mniemietz.de\/uiRedressing.pdf"}],"event":{"name":"SAC 2015: Symposium on Applied Computing","sponsor":["SIGAPP ACM Special Interest Group on Applied Computing"],"location":"Salamanca Spain","acronym":"SAC 2015"},"container-title":["Proceedings of the 30th Annual ACM Symposium on Applied Computing"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2695664.2695946","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2695664.2695946","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T06:12:27Z","timestamp":1750227147000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2695664.2695946"}},"subtitle":["metrics based approach"],"short-title":[],"issued":{"date-parts":[[2015,4,13]]},"references-count":32,"alternative-id":["10.1145\/2695664.2695946","10.1145\/2695664"],"URL":"https:\/\/doi.org\/10.1145\/2695664.2695946","relation":{},"subject":[],"published":{"date-parts":[[2015,4,13]]},"assertion":[{"value":"2015-04-13","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}