The Experts below are selected from a list of 20574 Experts worldwide ranked by ideXlab platform
Wouter Joosen - One of the best experts on this subject based on the ideXlab platform.
-
csfire transparent client side mitigation of malicious cross domain requests
International Conference on Engineering Secure Software and Systems, 2010Co-Authors: Philippe De Ryck, Frank Piessens, Thomas Heyman, Lieven Desmet, Wouter JoosenAbstract:Protecting users in the ubiquitous online world is becoming more and more important, as shown by web application security – or the lack thereof – making the mainstream news. One of the more harmful attacks is cross-site request forgery (CSRF), which allows an attacker to make requests to certain web applications while impersonating the user without their awareness. Existing client-side protection mechanisms do not fully mitigate the problem or have a Degrading Effect on the browsing experience of the user, especially with web 2.0 techniques such as AJAX, mashups and single sign-on. To fill this gap, this paper makes three contributions: first, a thorough traffic analysis on real-world traffic quantifies the amount of cross-domain traffic and identifies its specific properties. Second, a client-side enforcement policy has been constructed and a Firefox extension, named CsFire (CeaseFire), has been implemented to autonomously mitigate CSRF attacks as precise as possible. Evaluation was done using specific CSRF scenarios, as well as in real-life by a group of test users. Third, the granularity of the client-side policy is improved even further by incorporating server-specific policy refinements about intended cross-domain traffic.
-
ESSoS - CsFire: transparent client-side mitigation of malicious cross-domain requests
Lecture Notes in Computer Science, 2010Co-Authors: Philippe De Ryck, Frank Piessens, Thomas Heyman, Lieven Desmet, Wouter JoosenAbstract:Protecting users in the ubiquitous online world is becoming more and more important, as shown by web application security – or the lack thereof – making the mainstream news. One of the more harmful attacks is cross-site request forgery (CSRF), which allows an attacker to make requests to certain web applications while impersonating the user without their awareness. Existing client-side protection mechanisms do not fully mitigate the problem or have a Degrading Effect on the browsing experience of the user, especially with web 2.0 techniques such as AJAX, mashups and single sign-on. To fill this gap, this paper makes three contributions: first, a thorough traffic analysis on real-world traffic quantifies the amount of cross-domain traffic and identifies its specific properties. Second, a client-side enforcement policy has been constructed and a Firefox extension, named CsFire (CeaseFire), has been implemented to autonomously mitigate CSRF attacks as precise as possible. Evaluation was done using specific CSRF scenarios, as well as in real-life by a group of test users. Third, the granularity of the client-side policy is improved even further by incorporating server-specific policy refinements about intended cross-domain traffic.
-
CsFire: Transparent client-side mitigation of malicious cross-domain requests
Lecture Notes in Computer Science, 2010Co-Authors: Philippe De Ryck, Frank Piessens, Thomas Heyman, Lieven Desmet, Wouter JoosenAbstract:Protecting users in the ubiquitous online world is becoming more and more important, as shown by web application security -- or the lack thereof -- making the mainstream news. One of the more harmful attacks is cross-site request forgery (CSRF), which allows an attacker to make requests to certain web applications while impersonating the user without their awareness. Existing client-side protection mechanisms do not fully mitigate the problem or have a Degrading Effect on the browsing experience of the user, especially with web 2.0 techniques such as AJAX, mashups and single sign-on. To fill this gap, this paper makes three contributions: first, a thorough traffic analysis on real-world traffic quantifies the amount of cross-domain traffic and identifies its specific properties. Second, a client-side enforcement policy has been constructed and a Firefox extension, named CsFire (CeaseFire), has been implemented to autonomously mitigate CSRF attacks as precise as possible. Evaluation was done using specific CSRF scenarios, as well as in real-life by a group of test users. Third, the granularity of the client-side policy is improved even further by incorporating server-specific policy refinements about intended cross-domain traffic.status: publishe
N. Richard - One of the best experts on this subject based on the ideXlab platform.
-
A comprehensive theoretical picture of E centers in silicon: from optical properties to vacancy-mediated dopant diffusion
Journal of Applied Physics, 2020Co-Authors: G Herrero-saboya, L. Martin-samos, Antoine Jay, Anne Hémeryck, N. RichardAbstract:Among the common vacancy-related point defects in silicon, the E center is one of the most prominent due to its Degrading Effect in silicon-based technology. Even though it has been the subject of extensive experimental and theoretical studies, a comprehensive theoretical model capable of reproducing the experimental evidence for all three dopants (P, As and Sb) is still missing. Guided by a Jahn-Teller model, we are able to reproduce the absorption bands and the transition probability between equivalent geometries of the defect at low temperatures by including many-body-perturbation corrections based on the GW approximation on top of DFT. At higher temperatures, vacancies become mobile centers, allowing the reorientation of the whole defect and contributing to the dopant diffusion. The underlying mechanisms of vacancy-mediated dopant diffusion are revisited, characterizing the activation energies of such technologically relevant processes, obtaining quantitative results in good agreement with experiment.
Philippe De Ryck - One of the best experts on this subject based on the ideXlab platform.
-
csfire transparent client side mitigation of malicious cross domain requests
International Conference on Engineering Secure Software and Systems, 2010Co-Authors: Philippe De Ryck, Frank Piessens, Thomas Heyman, Lieven Desmet, Wouter JoosenAbstract:Protecting users in the ubiquitous online world is becoming more and more important, as shown by web application security – or the lack thereof – making the mainstream news. One of the more harmful attacks is cross-site request forgery (CSRF), which allows an attacker to make requests to certain web applications while impersonating the user without their awareness. Existing client-side protection mechanisms do not fully mitigate the problem or have a Degrading Effect on the browsing experience of the user, especially with web 2.0 techniques such as AJAX, mashups and single sign-on. To fill this gap, this paper makes three contributions: first, a thorough traffic analysis on real-world traffic quantifies the amount of cross-domain traffic and identifies its specific properties. Second, a client-side enforcement policy has been constructed and a Firefox extension, named CsFire (CeaseFire), has been implemented to autonomously mitigate CSRF attacks as precise as possible. Evaluation was done using specific CSRF scenarios, as well as in real-life by a group of test users. Third, the granularity of the client-side policy is improved even further by incorporating server-specific policy refinements about intended cross-domain traffic.
-
ESSoS - CsFire: transparent client-side mitigation of malicious cross-domain requests
Lecture Notes in Computer Science, 2010Co-Authors: Philippe De Ryck, Frank Piessens, Thomas Heyman, Lieven Desmet, Wouter JoosenAbstract:Protecting users in the ubiquitous online world is becoming more and more important, as shown by web application security – or the lack thereof – making the mainstream news. One of the more harmful attacks is cross-site request forgery (CSRF), which allows an attacker to make requests to certain web applications while impersonating the user without their awareness. Existing client-side protection mechanisms do not fully mitigate the problem or have a Degrading Effect on the browsing experience of the user, especially with web 2.0 techniques such as AJAX, mashups and single sign-on. To fill this gap, this paper makes three contributions: first, a thorough traffic analysis on real-world traffic quantifies the amount of cross-domain traffic and identifies its specific properties. Second, a client-side enforcement policy has been constructed and a Firefox extension, named CsFire (CeaseFire), has been implemented to autonomously mitigate CSRF attacks as precise as possible. Evaluation was done using specific CSRF scenarios, as well as in real-life by a group of test users. Third, the granularity of the client-side policy is improved even further by incorporating server-specific policy refinements about intended cross-domain traffic.
-
CsFire: Transparent client-side mitigation of malicious cross-domain requests
Lecture Notes in Computer Science, 2010Co-Authors: Philippe De Ryck, Frank Piessens, Thomas Heyman, Lieven Desmet, Wouter JoosenAbstract:Protecting users in the ubiquitous online world is becoming more and more important, as shown by web application security -- or the lack thereof -- making the mainstream news. One of the more harmful attacks is cross-site request forgery (CSRF), which allows an attacker to make requests to certain web applications while impersonating the user without their awareness. Existing client-side protection mechanisms do not fully mitigate the problem or have a Degrading Effect on the browsing experience of the user, especially with web 2.0 techniques such as AJAX, mashups and single sign-on. To fill this gap, this paper makes three contributions: first, a thorough traffic analysis on real-world traffic quantifies the amount of cross-domain traffic and identifies its specific properties. Second, a client-side enforcement policy has been constructed and a Firefox extension, named CsFire (CeaseFire), has been implemented to autonomously mitigate CSRF attacks as precise as possible. Evaluation was done using specific CSRF scenarios, as well as in real-life by a group of test users. Third, the granularity of the client-side policy is improved even further by incorporating server-specific policy refinements about intended cross-domain traffic.status: publishe
Xiaosheng Tang - One of the best experts on this subject based on the ideXlab platform.
-
femtosecond laser direct writing of microholes on roughened zno for output power enhancement of ingan light emitting diodes
Optics Letters, 2016Co-Authors: Zhigang Zang, Xiaofeng Zeng, Jihe Du, Ming Wang, Xiaosheng TangAbstract:A significant enhancement of light extraction efficiency from InGaN light-emitting diodes (LEDs) with microhole arrays and roughened ZnO was experimentally demonstrated. The roughened ZnO was fabricated using an Ar and H2 plasma treatment of ZnO films pre-coated on a p-GaN layer. When followed by a femtosecond laser direct writing technique, a periodic array of microholes could be added to the surface. The diameter of the microhole was varied by changing the output power of the femtosecond laser. Compared to conventional LEDs on the same wafer, the output power of LEDs with roughened ZnOs and a microhole (diameter of 2 μm) array was increased by 58.4% when operated with an injection current of 220 mA. Moreover, it was found that LEDs fabricated with roughened ZnO and the microhole array had similar current–voltage (I–V) characteristics to those of conventional LEDs and no Degrading Effect was observed.
-
enhancement of light extraction efficiency of ingan light emitting diodes with microholes array and nano roughened zno structure
International Conference on Photonics in Switching, 2016Co-Authors: Ming Wang, Zhigang Zang, Xiaosheng TangAbstract:The light extraction efficiency of InGaN LEDs with microholes array and nano-roughened ZnO was increased, which resulted in the maximum output power enhancement of 58.4%. No Degrading Effect on the current-voltage (I–V) characteristics were observed.
Lieven Desmet - One of the best experts on this subject based on the ideXlab platform.
-
csfire transparent client side mitigation of malicious cross domain requests
International Conference on Engineering Secure Software and Systems, 2010Co-Authors: Philippe De Ryck, Frank Piessens, Thomas Heyman, Lieven Desmet, Wouter JoosenAbstract:Protecting users in the ubiquitous online world is becoming more and more important, as shown by web application security – or the lack thereof – making the mainstream news. One of the more harmful attacks is cross-site request forgery (CSRF), which allows an attacker to make requests to certain web applications while impersonating the user without their awareness. Existing client-side protection mechanisms do not fully mitigate the problem or have a Degrading Effect on the browsing experience of the user, especially with web 2.0 techniques such as AJAX, mashups and single sign-on. To fill this gap, this paper makes three contributions: first, a thorough traffic analysis on real-world traffic quantifies the amount of cross-domain traffic and identifies its specific properties. Second, a client-side enforcement policy has been constructed and a Firefox extension, named CsFire (CeaseFire), has been implemented to autonomously mitigate CSRF attacks as precise as possible. Evaluation was done using specific CSRF scenarios, as well as in real-life by a group of test users. Third, the granularity of the client-side policy is improved even further by incorporating server-specific policy refinements about intended cross-domain traffic.
-
ESSoS - CsFire: transparent client-side mitigation of malicious cross-domain requests
Lecture Notes in Computer Science, 2010Co-Authors: Philippe De Ryck, Frank Piessens, Thomas Heyman, Lieven Desmet, Wouter JoosenAbstract:Protecting users in the ubiquitous online world is becoming more and more important, as shown by web application security – or the lack thereof – making the mainstream news. One of the more harmful attacks is cross-site request forgery (CSRF), which allows an attacker to make requests to certain web applications while impersonating the user without their awareness. Existing client-side protection mechanisms do not fully mitigate the problem or have a Degrading Effect on the browsing experience of the user, especially with web 2.0 techniques such as AJAX, mashups and single sign-on. To fill this gap, this paper makes three contributions: first, a thorough traffic analysis on real-world traffic quantifies the amount of cross-domain traffic and identifies its specific properties. Second, a client-side enforcement policy has been constructed and a Firefox extension, named CsFire (CeaseFire), has been implemented to autonomously mitigate CSRF attacks as precise as possible. Evaluation was done using specific CSRF scenarios, as well as in real-life by a group of test users. Third, the granularity of the client-side policy is improved even further by incorporating server-specific policy refinements about intended cross-domain traffic.
-
CsFire: Transparent client-side mitigation of malicious cross-domain requests
Lecture Notes in Computer Science, 2010Co-Authors: Philippe De Ryck, Frank Piessens, Thomas Heyman, Lieven Desmet, Wouter JoosenAbstract:Protecting users in the ubiquitous online world is becoming more and more important, as shown by web application security -- or the lack thereof -- making the mainstream news. One of the more harmful attacks is cross-site request forgery (CSRF), which allows an attacker to make requests to certain web applications while impersonating the user without their awareness. Existing client-side protection mechanisms do not fully mitigate the problem or have a Degrading Effect on the browsing experience of the user, especially with web 2.0 techniques such as AJAX, mashups and single sign-on. To fill this gap, this paper makes three contributions: first, a thorough traffic analysis on real-world traffic quantifies the amount of cross-domain traffic and identifies its specific properties. Second, a client-side enforcement policy has been constructed and a Firefox extension, named CsFire (CeaseFire), has been implemented to autonomously mitigate CSRF attacks as precise as possible. Evaluation was done using specific CSRF scenarios, as well as in real-life by a group of test users. Third, the granularity of the client-side policy is improved even further by incorporating server-specific policy refinements about intended cross-domain traffic.status: publishe