Radoslaw Bobrowicz

dblp:53/8735 · DBLP profile ↗
← Back
1ranked-venue papers
0as first author
0since 2021 · last 2010
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Web and mobile security · 50% Systems and software security · 50%

Topics — the 2 heaviest of 2, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security
vulnerability discovery
0.112010
NoTamper: automatic blackbox detection of parameter tampering opportunities in web applications · CCS 2010
Web and mobile security
web application vulnerability
0.112010
NoTamper: automatic blackbox detection of parameter tampering opportunities in web applications · CCS 2010

Methods — techniques the papers use, named apart from their topics

input validation analysis · 0.1black-box testing · 0.1
YearPublicationVenuePosition
2010 NoTamper: automatic blackbox detection of parameter tampering opportunities in web applications
abstract
Web applications rely heavily on client-side computation to examine and validate form inputs that are supplied by a user (e.g., "credit card expiration date must be valid"). This is typically done for two reasons: to reduce burden on the server and to avoid latencies in communicating with the server. However, when a server fails to replicate the validation performed on the client, it is potentially vulnerable to attack. In this paper, we present a novel approach for automatically detecting potential server-side vulnerabilities of this kind in existing (legacy) web applications through blackbox analysis. We discuss the design and implementation of NoTamper, a tool that realizes this approach. NoTamper has been employed to discover several previously unknown vulnerabilities in a number of open-source web applications and live web sites.
Prithvi Bisht, Timothy L. Hinrichs, Nazari Skrupsky, Radoslaw Bobrowicz, V. N. Venkatakrishnan
CCS4