Using static analysis for Ajax intrusion detection

118Citations
Citations of this article
123Readers
Mendeley users who have this article in their library.
Get full text

Abstract

We present a static control-flow analysis for JavaScript programs running in a web browser. Our analysis tackles numerous challenges posed by modern web applications including asynchronous communication, frameworks, and dynamic code generation. We use our analysis to extract a model of expected client behavior as seen from the server, and build an intrusion-prevention proxy for the server: the proxy intercepts client requests and disables those that do not meet the expected behavior. We insert random asynchronous requests to foil mimicry attacks. Finally, we evaluate our technique against several real applications and show that it protects against an attack in a widely-used web application. Copyright is held by the International World Wide Web Conference Committee (IW3C2).

Cite

CITATION STYLE

APA

Guha, A., Krishnamurthi, S., & Jim, T. (2009). Using static analysis for Ajax intrusion detection. In WWW’09 - Proceedings of the 18th International World Wide Web Conference (pp. 561–570). https://doi.org/10.1145/1526709.1526785

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free