The Experts below are selected from a list of 234 Experts worldwide ranked by ideXlab platform

Henrique Madeira - One of the best experts on this subject based on the ideXlab platform.

  • IEEE SCC - Effective Detection of SQL/XPath Injection Vulnerabilities in Web Services
    2009 IEEE International Conference on Services Computing, 2009
    Co-Authors: Nuno Antunes, Nuno Laranjeiro, Marco Vieira, Henrique Madeira
    Abstract:

    This paper proposes a new automatic approach for the detection of SQL Injection and XPath Injection vulnerabilities, two of the most common and most critical types of vulnerabilities in web services. Although there are tools that allow testing web applications against security vulnerabilities, previous research shows that the effectiveness of those tools in web services environments is very poor. In our approach a Representative Workload is used to exercise the web service and a large set of SQL/XPath Injection attacks are applied to disclose vulnerabilities. Vulnerabilities are detected by comparing the structure of the SQL/XPath commands issued in the presence of attacks to the ones previously learned when running the Workload in the absence of attacks. Experimental evaluation shows that our approach performs much better than known tools (including commercial ones), achieving extremely high detection coverage while maintaining the false positives rate very low.

  • Effective Detection of SQL/XPath Injection Vulnerabilities in Web Services
    2009 IEEE International Conference on Services Computing, 2009
    Co-Authors: Nuno Antunes, Nuno Laranjeiro, Marco Vieira, Henrique Madeira
    Abstract:

    This paper proposes a new automatic approach for the detection of SQL Injection and XPath Injection vulnerabilities, two of the most common and most critical types of vulnerabilities in Web services. Although there are tools that allow testing Web applications against security vulnerabilities, previous research shows that the effectiveness of those tools in Web services environments is very poor. In our approach a Representative Workload is used to exercise the Web service and a large set of SQL/XPath injection attacks are applied to disclose vulnerabilities. Vulnerabilities are detected by comparing the structure of the SQL/XPath commands issued in the presence of attacks to the ones previously learned when running the Workload in the absence of attacks. Experimental evaluation shows that our approach performs much better than known tools (including commercial ones), achieving extremely high detection coverage while maintaining the false positives rate very low.

Nuno Antunes - One of the best experts on this subject based on the ideXlab platform.

  • IEEE SCC - Effective Detection of SQL/XPath Injection Vulnerabilities in Web Services
    2009 IEEE International Conference on Services Computing, 2009
    Co-Authors: Nuno Antunes, Nuno Laranjeiro, Marco Vieira, Henrique Madeira
    Abstract:

    This paper proposes a new automatic approach for the detection of SQL Injection and XPath Injection vulnerabilities, two of the most common and most critical types of vulnerabilities in web services. Although there are tools that allow testing web applications against security vulnerabilities, previous research shows that the effectiveness of those tools in web services environments is very poor. In our approach a Representative Workload is used to exercise the web service and a large set of SQL/XPath Injection attacks are applied to disclose vulnerabilities. Vulnerabilities are detected by comparing the structure of the SQL/XPath commands issued in the presence of attacks to the ones previously learned when running the Workload in the absence of attacks. Experimental evaluation shows that our approach performs much better than known tools (including commercial ones), achieving extremely high detection coverage while maintaining the false positives rate very low.

  • Effective Detection of SQL/XPath Injection Vulnerabilities in Web Services
    2009 IEEE International Conference on Services Computing, 2009
    Co-Authors: Nuno Antunes, Nuno Laranjeiro, Marco Vieira, Henrique Madeira
    Abstract:

    This paper proposes a new automatic approach for the detection of SQL Injection and XPath Injection vulnerabilities, two of the most common and most critical types of vulnerabilities in Web services. Although there are tools that allow testing Web applications against security vulnerabilities, previous research shows that the effectiveness of those tools in Web services environments is very poor. In our approach a Representative Workload is used to exercise the Web service and a large set of SQL/XPath injection attacks are applied to disclose vulnerabilities. Vulnerabilities are detected by comparing the structure of the SQL/XPath commands issued in the presence of attacks to the ones previously learned when running the Workload in the absence of attacks. Experimental evaluation shows that our approach performs much better than known tools (including commercial ones), achieving extremely high detection coverage while maintaining the false positives rate very low.

Nuno Laranjeiro - One of the best experts on this subject based on the ideXlab platform.

  • IEEE SCC - Effective Detection of SQL/XPath Injection Vulnerabilities in Web Services
    2009 IEEE International Conference on Services Computing, 2009
    Co-Authors: Nuno Antunes, Nuno Laranjeiro, Marco Vieira, Henrique Madeira
    Abstract:

    This paper proposes a new automatic approach for the detection of SQL Injection and XPath Injection vulnerabilities, two of the most common and most critical types of vulnerabilities in web services. Although there are tools that allow testing web applications against security vulnerabilities, previous research shows that the effectiveness of those tools in web services environments is very poor. In our approach a Representative Workload is used to exercise the web service and a large set of SQL/XPath Injection attacks are applied to disclose vulnerabilities. Vulnerabilities are detected by comparing the structure of the SQL/XPath commands issued in the presence of attacks to the ones previously learned when running the Workload in the absence of attacks. Experimental evaluation shows that our approach performs much better than known tools (including commercial ones), achieving extremely high detection coverage while maintaining the false positives rate very low.

  • Effective Detection of SQL/XPath Injection Vulnerabilities in Web Services
    2009 IEEE International Conference on Services Computing, 2009
    Co-Authors: Nuno Antunes, Nuno Laranjeiro, Marco Vieira, Henrique Madeira
    Abstract:

    This paper proposes a new automatic approach for the detection of SQL Injection and XPath Injection vulnerabilities, two of the most common and most critical types of vulnerabilities in Web services. Although there are tools that allow testing Web applications against security vulnerabilities, previous research shows that the effectiveness of those tools in Web services environments is very poor. In our approach a Representative Workload is used to exercise the Web service and a large set of SQL/XPath injection attacks are applied to disclose vulnerabilities. Vulnerabilities are detected by comparing the structure of the SQL/XPath commands issued in the presence of attacks to the ones previously learned when running the Workload in the absence of attacks. Experimental evaluation shows that our approach performs much better than known tools (including commercial ones), achieving extremely high detection coverage while maintaining the false positives rate very low.

Marco Vieira - One of the best experts on this subject based on the ideXlab platform.

  • IEEE SCC - Effective Detection of SQL/XPath Injection Vulnerabilities in Web Services
    2009 IEEE International Conference on Services Computing, 2009
    Co-Authors: Nuno Antunes, Nuno Laranjeiro, Marco Vieira, Henrique Madeira
    Abstract:

    This paper proposes a new automatic approach for the detection of SQL Injection and XPath Injection vulnerabilities, two of the most common and most critical types of vulnerabilities in web services. Although there are tools that allow testing web applications against security vulnerabilities, previous research shows that the effectiveness of those tools in web services environments is very poor. In our approach a Representative Workload is used to exercise the web service and a large set of SQL/XPath Injection attacks are applied to disclose vulnerabilities. Vulnerabilities are detected by comparing the structure of the SQL/XPath commands issued in the presence of attacks to the ones previously learned when running the Workload in the absence of attacks. Experimental evaluation shows that our approach performs much better than known tools (including commercial ones), achieving extremely high detection coverage while maintaining the false positives rate very low.

  • Effective Detection of SQL/XPath Injection Vulnerabilities in Web Services
    2009 IEEE International Conference on Services Computing, 2009
    Co-Authors: Nuno Antunes, Nuno Laranjeiro, Marco Vieira, Henrique Madeira
    Abstract:

    This paper proposes a new automatic approach for the detection of SQL Injection and XPath Injection vulnerabilities, two of the most common and most critical types of vulnerabilities in Web services. Although there are tools that allow testing Web applications against security vulnerabilities, previous research shows that the effectiveness of those tools in Web services environments is very poor. In our approach a Representative Workload is used to exercise the Web service and a large set of SQL/XPath injection attacks are applied to disclose vulnerabilities. Vulnerabilities are detected by comparing the structure of the SQL/XPath commands issued in the presence of attacks to the ones previously learned when running the Workload in the absence of attacks. Experimental evaluation shows that our approach performs much better than known tools (including commercial ones), achieving extremely high detection coverage while maintaining the false positives rate very low.

Vincent W Freeh - One of the best experts on this subject based on the ideXlab platform.

  • boosting data center performance through non uniform power allocation
    International Conference on Autonomic Computing, 2005
    Co-Authors: Mark E Femal, Vincent W Freeh
    Abstract:

    Data center power management is evolving from ad hoc methods based on maximum node power usage to systematic methods that employ power-scalable components. In addition, it is possible to exploit the power and throughput relationship to increase the total work performed and safely overprovision the rack space while staying below an aggregate power limit. This research describes a general framework for boosting throughput at a local level while load-balancing the available aggregate power under a set of operating constraints. Our solution is useful for those data centers that cannot expand the number of power circuits or seek effective usage of their available power budget due to unplanned power fluctuations. The framework is particularly well suited for environments with a heterogeneous Workload and hence, a non-uniform power allocation requirement. Based on a Representative Workload for a two minute period, this paper shows a non-uniform power allocation scheme increases throughput by over 16% versus a uniform power allocation mechanism

  • ICAC - Boosting Data Center Performance Through Non-Uniform Power Allocation
    Second International Conference on Autonomic Computing (ICAC'05), 2005
    Co-Authors: Mark E Femal, Vincent W Freeh
    Abstract:

    Data center power management is evolving from ad hoc methods based on maximum node power usage to systematic methods that employ power-scalable components. In addition, it is possible to exploit the power and throughput relationship to increase the total work performed and safely overprovision the rack space while staying below an aggregate power limit. This research describes a general framework for boosting throughput at a local level while load-balancing the available aggregate power under a set of operating constraints. Our solution is useful for those data centers that cannot expand the number of power circuits or seek effective usage of their available power budget due to unplanned power fluctuations. The framework is particularly well suited for environments with a heterogeneous Workload and hence, a non-uniform power allocation requirement. Based on a Representative Workload for a two minute period, this paper shows a non-uniform power allocation scheme increases throughput by over 16% versus a uniform power allocation mechanism