Overview
The Web Security Group is a part of the Stanford Security Laboratory. Research projects focus on various aspects of browser and web application security.
Publications
Securing the Web Platform
-
In Proc. of Usenix Security. (Usenix 2010)
-
In Proc. of Usenix Workshop on Offensive Technologies. (wOOt 2010)
-
In Proc. of the IEEE Oakland Web 2.0 Security and Privacy Workshop. (W2SP 2010)
-
Technical Report
-
In Proc. of the 25th Annual Computer Security Applications Conference. (ACSAC 2009)
-
In Proc. of the 15th ACM Conference on Computer and Communications Security. (CCS 2008)
-
In Web 2.0 Security and Privacy. (W2SP 2008)
-
In Proc. of the 17th International World Wide Web Conference. (WWW 2008)
-
In Proc. of the 14th ACM Conf. on Computer and Communications Security. (CCS 2007)
Security of web interfaces in embbeded devices
-
In Proc. of the 16th ACM Conf. on Computer and Communications Security. (CCS 2009)
-
In BlackHat USA 2009
Security properties of JavaScript programs
-
In Proc. of the 6th Asian Programming Language Symposium (APLAS 08)
-
In Proc. of the 22nd IEEE Computer Security Foundations Symposium (CSF 09)
-
In 3rd IEEE workshop on Web 2.0 Security and Privacy 2009 (W2SP 09)
Security for Mashups
-
In Proc. of the 17th USENIX Security Symposium. (USENIX Security 2008)
-
In Proc. of the 21st ACM Symposium on Operating Systems Principles (SOSP 2007)
-
In Proc. of the 11th Workshop on Hot Topics in Operating Systems. (HotOS 2007)
-
In Proc. of the 16th International World Wide Web Conference. (WWW 2007)
Evaluation of Web Security Tools
-
Jason Bau, Elie Bursztein, Divij Gupta, and John MitchellIn Proc. of IEEE Symposium on Security and Privacy. (IEEE S&P (Oakland) 2010)
-
Jason Bau, Frank Wang, Elie Bursztein, Patrick Mutchler, and John C. MitchellTechnical Report
Privacy in the Browser
-
In Proc. of the 16th International World Wide Web Conference. (WWW 2007)
-
In Proc. of the 15th International World Wide Web Conference. (WWW 2006)
Authentication and Authorization
-
In Proc. of the 2nd USENIX Workshop on Hot Topics in Security. (HotSec 2007)
-
In Proc. of the 2007 Workshop on Usable Security. (USEC 2007)
-
In Proc. of the 14th USENIX Security Symposium. (USENIX Security 2005)
-
Neil Chou, Robert Ledesma, Yuka Teraguchi, Dan Boneh, and John C. MitchellIn Proc. of the 11th Annual Network and Distributed System Security Symposium (NDSS 2004)
Workshops
White Papers
Browser Extensions
Security Advisories
- CVE-2008-5023
- CVE-2008-4820
- CVE-2008-4818
- CVE-2008-2801
- CVE-2008-1007
- CVE-2008-1006
- CVE-2008-1004
- CVE-2008-1003
- CVE-2007-6244
- CVE-2007-5858
- CVE-2007-5275