Fetching the paper…
Reading the bibliography…
Broken access control is one of the most common security vulnerabilities in web applications.
Protection
Butler W Lampson. 1974 · 1974
Earlier work this paper cites.
Recovery-oriented computing (ROC): Motivation, definition, techniques, and case studies
David Patterson, Aaron Brown, Pete Broadwell, George Candea, Mike Chen, James Cutler, Patricia Enriquez, Armando Fox, Emre Kiciman, Matthew Merzbacher, et al · 2002
Earlier work this paper cites.
Grand research challenges in information systems. In A Conference Series on Grand Research Challenges in Computer Science and Engineering
Computing Research Association et al · 2003
Earlier work this paper cites.
Limiting disclosure in hippocratic databases. In 30th Int. Conf. on Very Large Databases, VLDB Endowment, Toronto, Canada . 108–119
David DeWitt. 2004 · 2004
Earlier work this paper cites.
Building Secure High-Performance Web Services with OKWS.. In USENIX Annual Technical Conference, General Track . 185–198
Maxwell N Krohn. 2004 · 2004
Earlier work this paper cites.
Extending query rewriting techniques for fine-grained access control. In Proceedings of the 2004 ACM SIGMOD international conference on Management of data . 551–562
Shariq Rizvi, Alberto Mendelzon, Sundararajarao Sudarshan, and Prasan Roy. 2004 · 2004
Earlier work this paper cites.
AOL Proudly Releases Massive Amounts of Private Data
2006 · 2006
Earlier work this paper cites.
Using positive tainting and syntax-aware evaluation to counter SQL injection attacks. In Proceedings of the 14th ACM SIGSOFT international symposium on Foundations of software engineering . 175–185
William GJ Halfond, Alessandro Orso, and Panagiotis Manolios. 2006 · 2006
Earlier work this paper cites.
A world wide web without walls. In 6th ACM Workshop on Hot Topics in Networking (Hotnets)
Maxwell Krohn, Alex Yip, Micah Brodsky, Robert Morris, Michael Walfish, et al · 2007
Earlier work this paper cites.
The clark-wilson security model
Sonya Q Blake. 2000 · 2009
Earlier work this paper cites.
Nemesis: Preventing Authentication & [and] Access Control Vulnerabilities in Web Applications
Michael Dalton, Christos Kozyrakis, and Nickolai Zeldovich. 2009 · 2009
Earlier work this paper cites.
Model-view-controller (mvc) architecture
John Deacon. 2009 · 2009
Earlier work this paper cites.
CLAMP: Practical prevention of large-scale data leaks. In 2009 30th IEEE Symposium on Security and Privacy . IEEE, 154–169
Bryan Parno, Jonathan M McCune, Dan Wendlandt, David G Andersen, and Adrian Perrig. 2009 · 2009
Earlier work this paper cites.
Improving application security with data flow assertions. In Proceedings of the ACM SIGOPS 22nd symposium on Operating systems principles . 291–304
Alexander Yip, Xi Wang, Nickolai Zeldovich, and M Frans Kaashoek. 2009 · 2009
Earlier work this paper cites.
Static Checking of { \{ Dynamically-Varying } \} Security Policies in { \{ Database-Backed } \} Applications. In 9th USENIX Symposium on Operating Systems Design and Implementation (OSDI 10)
Adam Chlipala. 2010 · 2010
Earlier work this paper cites.
Toward automated detection of logic vulnerabilities in web applications. In 19th USENIX Security Symposium (USENIX Security 10)
Viktoria Felmetsger, Ludovico Cavedon, Christopher Kruegel, and Giovanni Vigna. 2010 · 2010
Earlier work this paper cites.
Mitre top 25
2011 · 2011
Earlier work this paper cites.
Oops, I did it again: Mitigating repeated access control errors on Facebook. In Proceedings of the SIGCHI conference on Human Factors in Computing Systems . 2295–2304
Serge Egelman, Andrew Oates, and Shriram Krishnamurthi. 2011 · 2011
Earlier work this paper cites.
Diesel: Applying privilege separation to database access. In Proceedings of the 6th ACM symposium on information, computer and communications security . 416–422
Adrienne Porter Felt, Matthew Finifter, Joel Weinberger, and David Wagner. 2011 · 2011
Earlier work this paper cites.
Improving the usability of privacy settings in facebook
Thomas Paul, Daniel Puscher, and Thorsten Strufe. 2011 · 2011
Earlier work this paper cites.
Rolecast: finding missing security checks when you do not know what checks are. In Proceedings of the 2011 ACM international conference on Object oriented programming systems languages and applications . 1069–1084
Sooel Son, Kathryn S McKinley, and Vitaly Shmatikov. 2011 · 2011
Earlier work this paper cites.
Static detection of access control vulnerabilities in web applications. In 20th USENIX Security Symposium (USENIX Security 11)
Fangqi Sun, Liang Xu, and Zhendong Su. 2011 · 2011
Earlier work this paper cites.
Hails: Protecting data privacy in untrusted web applications. In 10th USENIX Symposium on Operating Systems Design and Implementation (OSDI 12) . 47–60
Daniel B Giffin, Amit Levy, Deian Stefan, David Terei, David Mazieres, John C Mitchell, and Alejandro Russo. 2012 · 2012
Earlier work this paper cites.
Mining input sanitization patterns for predicting SQL injection and cross site scripting vulnerabilities. In 2012 34th International Conference on Software Engineering (ICSE) . IEEE, 1293–1296
Lwin Khin Shar and Hee Beng Kuan Tan. 2012 · 2012
Cited alongside, same era.
A language for automatically enforcing privacy policies
Jean Yang, Kuat Yessenov, and Armando Solar-Lezama. 2012 · 2012
Cited alongside, same era.
Fine-grained disclosure control for app ecosystems. In Proceedings of the 2013 ACM SIGMOD International Conference on Management of Data . 869–880
Gabriel M Bender, Lucja Kot, Johannes Gehrke, and Christoph Koch. 2013 · 2013
Cited alongside, same era.
Practical information flow for legacy web applications. In Proceedings of the 8th Workshop on Implementation, Compilation, Optimization of Object-Oriented Languages, Programs and Systems . 17–28
Georgios Chinis, Polyvios Pratikakis, Sotiris Ioannidis, and Elias Athanasopoulos. 2013 · 2013
Cited alongside, same era.
Jared, Kay Jewelers Parent Fixes Data Leak
2018 · 2018
Later among the works it cites.
LifeLock Bug Exposed Millions of Customer Email Addresses
2018 · 2018
Later among the works it cites.
Panera Bread blew off breach report for 8 months, leaked millions of customer records
2018 · 2018
Later among the works it cites.
Data breach at JustDial leaks 100 million user details
2019 · 2019
Later among the works it cites.
Lerhan: Bypassing IDOR protection with URL shorteners
2019 · 2019
Later among the works it cites.
LWeb: Information flow security for multi-tier web applications
James Parker, Niki Vazou, and Michael Hicks. 2019 · 2019
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
LogicScope: Automatic discovery of logic vulnerabilities within web applications. In Proceedings of the 8th ACM SIGSAC symposium on Information, computer and communications security . 481–486
Xiaowei Li and Yuan Xue. 2013 · 2013
Cited alongside, same era.
IFDB: decentralized information flow control for databases. In Proceedings of the 8th ACM European Conference on Computer Systems . 43–56
David Schultz and Barbara Liskov. 2013 · 2013
Cited alongside, same era.
Fix Me Up: Repairing Access-Control Bugs in Web Applications.. In NDSS . Citeseer
Sooel Son, Kathryn S McKinley, and Vitaly Shmatikov. 2013 · 2013
Cited alongside, same era.
Explicating { \{ SDKs } \} : Uncovering Assumptions Underlying Secure Authentication and Authorization. In 22nd USENIX Security Symposium (USENIX Security 13) . 399–314
Rui Wang, Yuchen Zhou, Shuo Chen, Shaz Qadeer, David Evans, and Yuri Gurevich. 2013 · 2013
Cited alongside, same era.
Automating isolation and least privilege in web services. In 2014 IEEE Symposium on Security and Privacy . IEEE, 133–148
Aaron Blankstein and Michael J Freedman. 2014 · 2014
Cited alongside, same era.
Mace: Detecting privilege escalation vulnerabilities in web applications. In Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security . 690–701
Maliheh Monshizadeh, Prasad Naldurg, and VN Venkatakrishnan. 2014 · 2014
Cited alongside, same era.
Jif: language-based information-flow security in Java
Kyle Pullicino. 2014 · 2014
Cited alongside, same era.
This Facebook Bug Allowed Anyone To Delete Your Photos
2015 · 2015
Cited alongside, same era.
A machine learning based approach to identify SQL injection vulnerabilities. In 2019 34th IEEE/ACM International Conference on Automated Software Engineering (ASE) . IEEE, 1286–1288
Kevin Zhang. 2019 · 2019
Later among the works it cites.
Why does your data leak? uncovering the data leakage in cloud from mobile apps. In 2019 IEEE Symposium on Security and Privacy (SP) . IEEE, 1296–1310
Chaoshun Zuo, Zhiqiang Lin, and Yinqian Zhang. 2019 · 2019
Later among the works it cites.
#1065041 Google API key leaked to Public
2020 · 2020
Later among the works it cites.
A first look at the deprecation of restful apis: An empirical study. In 2020 IEEE International Conference on Software Maintenance and Evolution (ICSME) . IEEE, 151–161
Jerin Yasmin, Yuan Tian, and Jinqiu Yang. 2020 · 2020
Later among the works it cites.
First American Financial Pays Farcical $500K Fine
2021 · 2021
Later among the works it cites.
Model–view–presenter - Wikipedia
2021 · 2021
Later among the works it cites.
OWASP Top 10:2021
2021 · 2021
Later among the works it cites.
ryanb/cancan: Authorization Gem for Ruby on Rails
2021 · 2021
Later among the works it cites.
{ \{ STORM } \} : Refinement Types for Secure Web Applications. In 15th { \{ USENIX } \} Symposium on Operating Systems Design and Implementation ( { \{ OSDI } \} 21) . 441–459
Nico Lehmann, Rose Kunkel, Jordan Brown, Jean Yang, Niki Vazou, Nadia Polikarpova, Deian Stefan, and Ranjit Jhala. 2021 · 2021
Later among the works it cites.
Out of Sight, Out of Mind: Detecting Orphaned Web Pages at Internet-Scale. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security . 21–35
Stijn Pletinckx, Kevin Borgolte, and Tobias Fiebig. 2021 · 2021
Later among the works it cites.
CanCanCommunity/cancancan: The authorization Gem for Ruby on Rails
2022 · 2022
Later among the works it cites.
Forced browsing | OWASP Foundation
2022 · 2022
Later among the works it cites.
LiquidHaskell
2022 · 2022
Later among the works it cites.
Model–view–viewmodel - Wikipedia
2022 · 2022
Later among the works it cites.
php-casbin/php-casbin: An authorization library that supports access control models like ACL, RBAC, ABAC in PHP
2022 · 2022
Later among the works it cites.
Ruby on Rails — A web-app framework that includes everything needed to create database-backed web applications according to the Model-View-Controller (MVC) pattern
2022 · 2022
Later among the works it cites.
The web framework for perfectionists with deadlines | Django
2022 · 2022
Later among the works it cites.