Igor Serikov

dblp:76/4910 · DBLP profile ↗
← Back
3ranked-venue papers
0as first author
0since 2021 · last 2008
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 2Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
2 papers
Programming languages and type systems · 61% Program analysis · 39%
Network and information security
2 papers
Web and mobile security · 100%

Topics — the 7 heaviest of 7, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Web and mobile security
web application security
0.112008
Better abstractions for secure server-side scripting · WWW 2008
Programming languages and type systems
language design
0.112008
Better abstractions for secure server-side scripting · WWW 2008
Web and mobile security
browser security
0.112007
JavaScript instrumentation for browser security · POPL 2007
Program analysis
dynamic analysis
0.112007
JavaScript instrumentation for browser security · POPL 2007
Programming languages and type systems
language semantics
0.112007
JavaScript instrumentation for browser security · POPL 2007
Programming languages and type systems › language semantics › formal semantics
operational semantics
0.112007
JavaScript instrumentation for browser security · POPL 2007
Program analysis
program rewriting
0.112007
JavaScript instrumentation for browser security · POPL 2007

Methods — techniques the papers use, named apart from their topics

rewriting · 0.1program instrumentation · 0.1
YearPublicationVenuePosition
2008 JavaScript Instrumentation in Practice
Haruka Kikuchi, Dachuan Yu, Ajay Chander, Hiroshi Inamura, Igor Serikov
APLAS5
2008 Better abstractions for secure server-side scripting
abstract
It is notoriously difficult to program a solid web application. Besides addressing web interactions, state maintenance, and whimsical user navigation behaviors, programmers must also avoid a minefield of security vulnerabilities. The problem is twofold. First, we lack a clear understanding of the new computation model underlying web applications. Second, we lack proper abstractions for hiding common and subtle coding details that are orthogonal to the business functionalities of specific web applications.
Dachuan Yu, Ajay Chander, Hiroshi Inamura, Igor Serikov
WWW4
2007 JavaScript instrumentation for browser security
abstract
It is well recognized that JavaScript can be exploited to launch browser-based security attacks. We propose to battle such attacks using program instrumentation. Untrusted JavaScript code goes through a rewriting process which identifies relevant operations, modifies questionable behaviors, and prompts the user (a web page viewer) for decisions on how to proceed when appropriate. Our solution is parametric with respect to the security policy-the policy is implemented separately from the rewriting, and the same rewriting process is carried out regardless of which policy is in use. Be-sides providing a rigorous account of the correctness of our solution, we also discuss practical issues including policy management and prototype experiments. A useful by-product of our work is an operational semantics of a core subset of JavaScript, where code embedded in (HTML) documents may generate further document pieces (with new code embedded) at runtime, yielding a form of self-modifying code.
Dachuan Yu, Ajay Chander, Nayeem Islam, Igor Serikov
POPL4