web application security

Designs, builds, and analyzes defenses for web applications and their HTTP/API interfaces, covering secure architecture, secure coding, authentication/authorization, input validation, session management, and configuration hardening. Implements and configures protective components such as web application firewalls, and performs web-specific security testing, monitoring, and incident response to detect and mitigate web attacks.

webapplicationsecurity

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
-0.04
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$193K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

This study addresses the security risks in modern web applications—such as cache poisoning and supply chain attacks—stemming from redundant HTTP API requests, missing cache headers, high load, and excessive reliance on third-party services, for which systematic evaluation methods are lacking. The authors present the first empirical baseline of HTTP API quality across diverse production websites, collecting 108 HAR traces from 18 sites using Playwright automation. They design eight heuristic-based anti-pattern detectors to quantify API quality on a 0–100 scale and correlate it with security implications. Findings reveal that minimal server-rendered sites achieve a perfect score of 100, while content-heavy commercial sites score as low as 56.8; 67% of sites exhibit redundant requests or cache misconfigurations, and 72% have over 20% third-party requests, with one page issuing up to 2,684 such calls. The open-sourced framework enables reproducible, systematic linkage between performance anti-patterns and security risks.

anti-patternsHTTP APInetwork layer quality

Tight coupling between security logic and business code in web applications degrades maintainability and weakens security assurance. Method: This paper proposes an aspect-oriented programming (AOP)-based modularization approach for security concerns, decoupling and encapsulating cross-cutting security mechanisms—including authentication, authorization, and input validation—into reusable aspects. We conduct a multi-scenario case study, complemented by ISO/IEC 25010–compliant code quality assessment, performance benchmarking (response time, throughput, memory consumption), and an empirical developer survey. Contribution/Results: Results demonstrate that AOP significantly improves cohesion and reusability of security modules, reduces code coupling, and enhances maintainability. The incurred runtime overhead is negligible (<2% across all metrics). This work establishes a reproducible, quantifiable AOP practice paradigm for security-driven software architecture, grounded in rigorous empirical evidence.

Comparing AOP and OOP approaches for security feature implementationEvaluating impact on code quality, performance, and maintainabilityModularizing cross-cutting security concerns in web applications

This study addresses the security risks arising from binary-level vulnerabilities—such as buffer overflows and use-after-free—in WebAssembly (WASM) modules, demonstrating how they can be exploited to manifest as high-level web vulnerabilities including SQL injection, XS-Leaks, and server-side template injection (SSTI), thereby evading existing web defense mechanisms. It is the first to systematically uncover the mapping relationship between low-level WASM binary flaws and web-layer security issues, filling a critical gap in the understanding of this threat surface. Through comprehensive vulnerability analysis, attack scenario modeling, and evaluation of current defenses, the work proposes targeted mitigation strategies and development best practices, offering both theoretical foundations and practical guidance for building more secure WASM applications.

Binary VulnerabilitiesBuffer OverflowUse After Free

This study addresses the inconsistent quality of freely available online web security tutorials, which often lack executable code and authoritative resource references, thereby limiting their practical utility for developers. The authors systematically evaluate 132 such tutorials and propose, for the first time, “executable code” and “citations to official resources” as key indicators of tutorial effectiveness. Through manual content analysis, they assess and categorize the tutorials across multiple dimensions—including topic coverage, author background, technical depth, and use of authoritative standards such as OWASP, CWE, and CVE. Findings reveal that most tutorials are vendor-provided and focus primarily on conceptual explanations, with only a minority offering complete, runnable code or linking to established security standards. This work provides developers with an evidence-based framework for identifying high-quality learning materials in web security.

code examplesOWASPsecurity education

Browser Security Posture Analysis: A Client-Side Security Assessment Framework

May 12, 2025
AC
Avihay Cohen
🏛️ Seraphic Algorithms

Modern web browsers have evolved into critical business platforms, yet their client-side security posture lacks systematic assessment. This paper introduces the first purely frontend, in-browser security assessment framework, implemented in JavaScript and WebAssembly. It integrates over 120 fine-grained checks covering core mechanisms—including the Same-Origin Policy, Content Security Policy (CSP), sandboxing, and XSS protections—and uniquely incorporates previously unobservable OS- and network-layer dimensions such as WeakRef interference, SharedArrayBuffer availability, and internal network reachability. Leveraging dynamic policy injection and coordinated multi-API observation (e.g., Permissions, Crypto, and Reporting APIs), our empirical evaluation across enterprise environments reveals widespread policy degradation: CSP bypass rates reach 63% on legacy browsers, and SSL certificate validation is omitted in 41% of cases. The framework establishes a practical, evidence-based diagnostic paradigm for precise security hardening.

Assessing client-side browser security policies and featuresEvaluating advanced web platform security features and vulnerabilitiesIdentifying gaps in browser security enforcement and misconfigurations

Latest Papers

What's happening recently
View more

This study addresses the limited understanding of how security features are implemented at the code level by conducting an empirical analysis of 561 security features across nine open-source Java systems, employing a combination of code mining and manual inspection. The research systematically examines the size, distribution, and coupling patterns of these features, revealing that their implementation extends far beyond simple library invocations. Furthermore, it uncovers pervasive large-scale code scattering and tight coupling throughout the analyzed systems. By quantifying the substantial code complexity required to integrate external security libraries, this work deepens the understanding of software security implementation mechanisms and provides critical evidence for advancing more secure software engineering practices.

access controlcode-level implementationopen-source systems

Hot Scholars

AS

Ashkan Sami

Professor of Computer Science, Edinburgh Napier University
Applied Data MiningSoftware EngineeringITCyber Security
RS

Rifat Shahriyar

Professor, Department of CSE, BUET
Memory ManagementProgramming LanguagesSoftware EngineeringNatural Language Processing
RD

Ran Dubin

Senior Lecturer, Department of Computer and Software Engineering, Ariel Cyber Innovation Center
Video StreamingMachine LearningMalware ResearchSNDBOX
TV

Tom Van Cutsem

KU Leuven | Nokia Bell Labs
Distributed SystemsProgramming LanguagesSoftware EngineeringBlockchain
AD

Amit Dvir

Associate Professor, Department of Computer and Software Eng. Ariel Cyber Innovation Center
Encrypted Traffic Classification. Malicious TrafficMANET