The Experts below are selected from a list of 20574 Experts worldwide ranked by ideXlab platform

Wouter Joosen - One of the best experts on this subject based on the ideXlab platform.

  • csfire transparent client side mitigation of malicious cross domain requests
    International Conference on Engineering Secure Software and Systems, 2010
    Co-Authors: Philippe De Ryck, Frank Piessens, Thomas Heyman, Lieven Desmet, Wouter Joosen
    Abstract:

    Protecting users in the ubiquitous online world is becoming more and more important, as shown by web application security – or the lack thereof – making the mainstream news. One of the more harmful attacks is cross-site request forgery (CSRF), which allows an attacker to make requests to certain web applications while impersonating the user without their awareness. Existing client-side protection mechanisms do not fully mitigate the problem or have a Degrading Effect on the browsing experience of the user, especially with web 2.0 techniques such as AJAX, mashups and single sign-on. To fill this gap, this paper makes three contributions: first, a thorough traffic analysis on real-world traffic quantifies the amount of cross-domain traffic and identifies its specific properties. Second, a client-side enforcement policy has been constructed and a Firefox extension, named CsFire (CeaseFire), has been implemented to autonomously mitigate CSRF attacks as precise as possible. Evaluation was done using specific CSRF scenarios, as well as in real-life by a group of test users. Third, the granularity of the client-side policy is improved even further by incorporating server-specific policy refinements about intended cross-domain traffic.

  • ESSoS - CsFire: transparent client-side mitigation of malicious cross-domain requests
    Lecture Notes in Computer Science, 2010
    Co-Authors: Philippe De Ryck, Frank Piessens, Thomas Heyman, Lieven Desmet, Wouter Joosen
    Abstract:

    Protecting users in the ubiquitous online world is becoming more and more important, as shown by web application security – or the lack thereof – making the mainstream news. One of the more harmful attacks is cross-site request forgery (CSRF), which allows an attacker to make requests to certain web applications while impersonating the user without their awareness. Existing client-side protection mechanisms do not fully mitigate the problem or have a Degrading Effect on the browsing experience of the user, especially with web 2.0 techniques such as AJAX, mashups and single sign-on. To fill this gap, this paper makes three contributions: first, a thorough traffic analysis on real-world traffic quantifies the amount of cross-domain traffic and identifies its specific properties. Second, a client-side enforcement policy has been constructed and a Firefox extension, named CsFire (CeaseFire), has been implemented to autonomously mitigate CSRF attacks as precise as possible. Evaluation was done using specific CSRF scenarios, as well as in real-life by a group of test users. Third, the granularity of the client-side policy is improved even further by incorporating server-specific policy refinements about intended cross-domain traffic.

  • CsFire: Transparent client-side mitigation of malicious cross-domain requests
    Lecture Notes in Computer Science, 2010
    Co-Authors: Philippe De Ryck, Frank Piessens, Thomas Heyman, Lieven Desmet, Wouter Joosen
    Abstract:

    Protecting users in the ubiquitous online world is becoming more and more important, as shown by web application security -- or the lack thereof -- making the mainstream news. One of the more harmful attacks is cross-site request forgery (CSRF), which allows an attacker to make requests to certain web applications while impersonating the user without their awareness. Existing client-side protection mechanisms do not fully mitigate the problem or have a Degrading Effect on the browsing experience of the user, especially with web 2.0 techniques such as AJAX, mashups and single sign-on. To fill this gap, this paper makes three contributions: first, a thorough traffic analysis on real-world traffic quantifies the amount of cross-domain traffic and identifies its specific properties. Second, a client-side enforcement policy has been constructed and a Firefox extension, named CsFire (CeaseFire), has been implemented to autonomously mitigate CSRF attacks as precise as possible. Evaluation was done using specific CSRF scenarios, as well as in real-life by a group of test users. Third, the granularity of the client-side policy is improved even further by incorporating server-specific policy refinements about intended cross-domain traffic.status: publishe

N. Richard - One of the best experts on this subject based on the ideXlab platform.

  • A comprehensive theoretical picture of E centers in silicon: from optical properties to vacancy-mediated dopant diffusion
    Journal of Applied Physics, 2020
    Co-Authors: G Herrero-saboya, L. Martin-samos, Antoine Jay, Anne Hémeryck, N. Richard
    Abstract:

    Among the common vacancy-related point defects in silicon, the E center is one of the most prominent due to its Degrading Effect in silicon-based technology. Even though it has been the subject of extensive experimental and theoretical studies, a comprehensive theoretical model capable of reproducing the experimental evidence for all three dopants (P, As and Sb) is still missing. Guided by a Jahn-Teller model, we are able to reproduce the absorption bands and the transition probability between equivalent geometries of the defect at low temperatures by including many-body-perturbation corrections based on the GW approximation on top of DFT. At higher temperatures, vacancies become mobile centers, allowing the reorientation of the whole defect and contributing to the dopant diffusion. The underlying mechanisms of vacancy-mediated dopant diffusion are revisited, characterizing the activation energies of such technologically relevant processes, obtaining quantitative results in good agreement with experiment.

Philippe De Ryck - One of the best experts on this subject based on the ideXlab platform.

  • csfire transparent client side mitigation of malicious cross domain requests
    International Conference on Engineering Secure Software and Systems, 2010
    Co-Authors: Philippe De Ryck, Frank Piessens, Thomas Heyman, Lieven Desmet, Wouter Joosen
    Abstract:

    Protecting users in the ubiquitous online world is becoming more and more important, as shown by web application security – or the lack thereof – making the mainstream news. One of the more harmful attacks is cross-site request forgery (CSRF), which allows an attacker to make requests to certain web applications while impersonating the user without their awareness. Existing client-side protection mechanisms do not fully mitigate the problem or have a Degrading Effect on the browsing experience of the user, especially with web 2.0 techniques such as AJAX, mashups and single sign-on. To fill this gap, this paper makes three contributions: first, a thorough traffic analysis on real-world traffic quantifies the amount of cross-domain traffic and identifies its specific properties. Second, a client-side enforcement policy has been constructed and a Firefox extension, named CsFire (CeaseFire), has been implemented to autonomously mitigate CSRF attacks as precise as possible. Evaluation was done using specific CSRF scenarios, as well as in real-life by a group of test users. Third, the granularity of the client-side policy is improved even further by incorporating server-specific policy refinements about intended cross-domain traffic.

  • ESSoS - CsFire: transparent client-side mitigation of malicious cross-domain requests
    Lecture Notes in Computer Science, 2010
    Co-Authors: Philippe De Ryck, Frank Piessens, Thomas Heyman, Lieven Desmet, Wouter Joosen
    Abstract:

    Protecting users in the ubiquitous online world is becoming more and more important, as shown by web application security – or the lack thereof – making the mainstream news. One of the more harmful attacks is cross-site request forgery (CSRF), which allows an attacker to make requests to certain web applications while impersonating the user without their awareness. Existing client-side protection mechanisms do not fully mitigate the problem or have a Degrading Effect on the browsing experience of the user, especially with web 2.0 techniques such as AJAX, mashups and single sign-on. To fill this gap, this paper makes three contributions: first, a thorough traffic analysis on real-world traffic quantifies the amount of cross-domain traffic and identifies its specific properties. Second, a client-side enforcement policy has been constructed and a Firefox extension, named CsFire (CeaseFire), has been implemented to autonomously mitigate CSRF attacks as precise as possible. Evaluation was done using specific CSRF scenarios, as well as in real-life by a group of test users. Third, the granularity of the client-side policy is improved even further by incorporating server-specific policy refinements about intended cross-domain traffic.

  • CsFire: Transparent client-side mitigation of malicious cross-domain requests
    Lecture Notes in Computer Science, 2010
    Co-Authors: Philippe De Ryck, Frank Piessens, Thomas Heyman, Lieven Desmet, Wouter Joosen
    Abstract:

    Protecting users in the ubiquitous online world is becoming more and more important, as shown by web application security -- or the lack thereof -- making the mainstream news. One of the more harmful attacks is cross-site request forgery (CSRF), which allows an attacker to make requests to certain web applications while impersonating the user without their awareness. Existing client-side protection mechanisms do not fully mitigate the problem or have a Degrading Effect on the browsing experience of the user, especially with web 2.0 techniques such as AJAX, mashups and single sign-on. To fill this gap, this paper makes three contributions: first, a thorough traffic analysis on real-world traffic quantifies the amount of cross-domain traffic and identifies its specific properties. Second, a client-side enforcement policy has been constructed and a Firefox extension, named CsFire (CeaseFire), has been implemented to autonomously mitigate CSRF attacks as precise as possible. Evaluation was done using specific CSRF scenarios, as well as in real-life by a group of test users. Third, the granularity of the client-side policy is improved even further by incorporating server-specific policy refinements about intended cross-domain traffic.status: publishe

Xiaosheng Tang - One of the best experts on this subject based on the ideXlab platform.

Lieven Desmet - One of the best experts on this subject based on the ideXlab platform.

  • csfire transparent client side mitigation of malicious cross domain requests
    International Conference on Engineering Secure Software and Systems, 2010
    Co-Authors: Philippe De Ryck, Frank Piessens, Thomas Heyman, Lieven Desmet, Wouter Joosen
    Abstract:

    Protecting users in the ubiquitous online world is becoming more and more important, as shown by web application security – or the lack thereof – making the mainstream news. One of the more harmful attacks is cross-site request forgery (CSRF), which allows an attacker to make requests to certain web applications while impersonating the user without their awareness. Existing client-side protection mechanisms do not fully mitigate the problem or have a Degrading Effect on the browsing experience of the user, especially with web 2.0 techniques such as AJAX, mashups and single sign-on. To fill this gap, this paper makes three contributions: first, a thorough traffic analysis on real-world traffic quantifies the amount of cross-domain traffic and identifies its specific properties. Second, a client-side enforcement policy has been constructed and a Firefox extension, named CsFire (CeaseFire), has been implemented to autonomously mitigate CSRF attacks as precise as possible. Evaluation was done using specific CSRF scenarios, as well as in real-life by a group of test users. Third, the granularity of the client-side policy is improved even further by incorporating server-specific policy refinements about intended cross-domain traffic.

  • ESSoS - CsFire: transparent client-side mitigation of malicious cross-domain requests
    Lecture Notes in Computer Science, 2010
    Co-Authors: Philippe De Ryck, Frank Piessens, Thomas Heyman, Lieven Desmet, Wouter Joosen
    Abstract:

    Protecting users in the ubiquitous online world is becoming more and more important, as shown by web application security – or the lack thereof – making the mainstream news. One of the more harmful attacks is cross-site request forgery (CSRF), which allows an attacker to make requests to certain web applications while impersonating the user without their awareness. Existing client-side protection mechanisms do not fully mitigate the problem or have a Degrading Effect on the browsing experience of the user, especially with web 2.0 techniques such as AJAX, mashups and single sign-on. To fill this gap, this paper makes three contributions: first, a thorough traffic analysis on real-world traffic quantifies the amount of cross-domain traffic and identifies its specific properties. Second, a client-side enforcement policy has been constructed and a Firefox extension, named CsFire (CeaseFire), has been implemented to autonomously mitigate CSRF attacks as precise as possible. Evaluation was done using specific CSRF scenarios, as well as in real-life by a group of test users. Third, the granularity of the client-side policy is improved even further by incorporating server-specific policy refinements about intended cross-domain traffic.

  • CsFire: Transparent client-side mitigation of malicious cross-domain requests
    Lecture Notes in Computer Science, 2010
    Co-Authors: Philippe De Ryck, Frank Piessens, Thomas Heyman, Lieven Desmet, Wouter Joosen
    Abstract:

    Protecting users in the ubiquitous online world is becoming more and more important, as shown by web application security -- or the lack thereof -- making the mainstream news. One of the more harmful attacks is cross-site request forgery (CSRF), which allows an attacker to make requests to certain web applications while impersonating the user without their awareness. Existing client-side protection mechanisms do not fully mitigate the problem or have a Degrading Effect on the browsing experience of the user, especially with web 2.0 techniques such as AJAX, mashups and single sign-on. To fill this gap, this paper makes three contributions: first, a thorough traffic analysis on real-world traffic quantifies the amount of cross-domain traffic and identifies its specific properties. Second, a client-side enforcement policy has been constructed and a Firefox extension, named CsFire (CeaseFire), has been implemented to autonomously mitigate CSRF attacks as precise as possible. Evaluation was done using specific CSRF scenarios, as well as in real-life by a group of test users. Third, the granularity of the client-side policy is improved even further by incorporating server-specific policy refinements about intended cross-domain traffic.status: publishe