Matches in SemOpenAlex for { <https://semopenalex.org/work/W2401831929> ?p ?o ?g. }
- W2401831929 abstract "Worms exploiting JavaScript XSS vulnerabilities rampantly infect millions of web pages, while drawing the ire of helpless users. To date, users across all the popular social networks, including Facebook, MySpace, Orkut and Twitter, have been vulnerable to XSS worms. We propose PathCutter as a new approach to severing the self-propagation path of JavaScript worms. PathCutter works by blocking two critical steps in the propagation path of an XSS worm: (i) DOM access to different views at the client side and (ii) unauthorized HTTP request to the server. As a result, although an XSS vulnerability is successfully exercised at the client, the XSS worm is prevented from successfully propagating to the would-be victim’s own social network page. PathCutter is effective against all the current forms of XSS worms, including those that exploit traditional XSS, DOM-based XSS, and content sniffing XSS vulnerabilities. We present and evaluate both a server-side and proxyside deployment of PathCutter. We implement PathCutter on WordPress and Elgg and demonstrate its resilience against two proof-of-concept attacks. We also evaluate the PathCutter implementation on five real-world worms: Boonana, MySpace Samy, Renren, SpaceFlash, and the Yamanner worm. We show that although the worms themselves exploit different vulnerabilities, at either the client side or server side, they are successfully thwarted by PathCutter as it is vulnerability agnostic and blocks the propagation path of the infection. Our performance evaluation shows that rendering overhead of PathCutter is less than 4%, and memory overhead for one additional view is less than 1%." @default.
- W2401831929 created "2016-06-24" @default.
- W2401831929 creator A5022253423 @default.
- W2401831929 creator A5037458498 @default.
- W2401831929 creator A5070605476 @default.
- W2401831929 creator A5085002486 @default.
- W2401831929 date "2012-01-01" @default.
- W2401831929 modified "2023-09-28" @default.
- W2401831929 title "PathCutter: Severing the Self-Propagation Path of XSS JavaScript Worms in Social Web Networks." @default.
- W2401831929 cites W101838518 @default.
- W2401831929 cites W109951691 @default.
- W2401831929 cites W142308502 @default.
- W2401831929 cites W1488890761 @default.
- W2401831929 cites W1505465226 @default.
- W2401831929 cites W1543478129 @default.
- W2401831929 cites W1561387739 @default.
- W2401831929 cites W1705596515 @default.
- W2401831929 cites W1907897959 @default.
- W2401831929 cites W1975428729 @default.
- W2401831929 cites W1982691206 @default.
- W2401831929 cites W1983142587 @default.
- W2401831929 cites W2049214202 @default.
- W2401831929 cites W2051498836 @default.
- W2401831929 cites W2053739444 @default.
- W2401831929 cites W2072978486 @default.
- W2401831929 cites W2085925880 @default.
- W2401831929 cites W2094568767 @default.
- W2401831929 cites W2110986027 @default.
- W2401831929 cites W2111487235 @default.
- W2401831929 cites W2140409350 @default.
- W2401831929 cites W2149684006 @default.
- W2401831929 cites W2151305689 @default.
- W2401831929 cites W2159079348 @default.
- W2401831929 cites W2162316255 @default.
- W2401831929 cites W2168563136 @default.
- W2401831929 cites W2169768162 @default.
- W2401831929 cites W2170920217 @default.
- W2401831929 hasPublicationYear "2012" @default.
- W2401831929 type Work @default.
- W2401831929 sameAs 2401831929 @default.
- W2401831929 citedByCount "9" @default.
- W2401831929 countsByYear W24018319292013 @default.
- W2401831929 countsByYear W24018319292014 @default.
- W2401831929 countsByYear W24018319292015 @default.
- W2401831929 countsByYear W24018319292016 @default.
- W2401831929 countsByYear W24018319292017 @default.
- W2401831929 countsByYear W24018319292018 @default.
- W2401831929 countsByYear W24018319292020 @default.
- W2401831929 crossrefType "proceedings-article" @default.
- W2401831929 hasAuthorship W2401831929A5022253423 @default.
- W2401831929 hasAuthorship W2401831929A5037458498 @default.
- W2401831929 hasAuthorship W2401831929A5070605476 @default.
- W2401831929 hasAuthorship W2401831929A5085002486 @default.
- W2401831929 hasConcept C108827166 @default.
- W2401831929 hasConcept C110875604 @default.
- W2401831929 hasConcept C118643609 @default.
- W2401831929 hasConcept C136764020 @default.
- W2401831929 hasConcept C14414571 @default.
- W2401831929 hasConcept C165696696 @default.
- W2401831929 hasConcept C38652104 @default.
- W2401831929 hasConcept C39569185 @default.
- W2401831929 hasConcept C41008148 @default.
- W2401831929 hasConcept C544833334 @default.
- W2401831929 hasConcept C59241245 @default.
- W2401831929 hasConcept C79373723 @default.
- W2401831929 hasConceptScore W2401831929C108827166 @default.
- W2401831929 hasConceptScore W2401831929C110875604 @default.
- W2401831929 hasConceptScore W2401831929C118643609 @default.
- W2401831929 hasConceptScore W2401831929C136764020 @default.
- W2401831929 hasConceptScore W2401831929C14414571 @default.
- W2401831929 hasConceptScore W2401831929C165696696 @default.
- W2401831929 hasConceptScore W2401831929C38652104 @default.
- W2401831929 hasConceptScore W2401831929C39569185 @default.
- W2401831929 hasConceptScore W2401831929C41008148 @default.
- W2401831929 hasConceptScore W2401831929C544833334 @default.
- W2401831929 hasConceptScore W2401831929C59241245 @default.
- W2401831929 hasConceptScore W2401831929C79373723 @default.
- W2401831929 hasLocation W24018319291 @default.
- W2401831929 hasOpenAccess W2401831929 @default.
- W2401831929 hasPrimaryLocation W24018319291 @default.
- W2401831929 hasRelatedWork W1543478129 @default.
- W2401831929 hasRelatedWork W1596422334 @default.
- W2401831929 hasRelatedWork W1982691206 @default.
- W2401831929 hasRelatedWork W2007191058 @default.
- W2401831929 hasRelatedWork W2049214202 @default.
- W2401831929 hasRelatedWork W2055564711 @default.
- W2401831929 hasRelatedWork W2102457045 @default.
- W2401831929 hasRelatedWork W2111487235 @default.
- W2401831929 hasRelatedWork W2140409350 @default.
- W2401831929 hasRelatedWork W2151305689 @default.
- W2401831929 hasRelatedWork W2155886640 @default.
- W2401831929 hasRelatedWork W2170920217 @default.
- W2401831929 hasRelatedWork W2222574961 @default.
- W2401831929 hasRelatedWork W2381003505 @default.
- W2401831929 hasRelatedWork W2509796803 @default.
- W2401831929 hasRelatedWork W2547885850 @default.
- W2401831929 hasRelatedWork W2598439922 @default.
- W2401831929 hasRelatedWork W2805790022 @default.
- W2401831929 hasRelatedWork W3151272311 @default.
- W2401831929 hasRelatedWork W3209731134 @default.