Score
Designs, builds, and analyzes defenses for web applications and their HTTP/API interfaces, covering secure architecture, secure coding, authentication/authorization, input validation, session management, and configuration hardening. Implements and configures protective components such as web application firewalls, and performs web-specific security testing, monitoring, and incident response to detect and mitigate web attacks.
This study addresses the security risks in modern web applications—such as cache poisoning and supply chain attacks—stemming from redundant HTTP API requests, missing cache headers, high load, and excessive reliance on third-party services, for which systematic evaluation methods are lacking. The authors present the first empirical baseline of HTTP API quality across diverse production websites, collecting 108 HAR traces from 18 sites using Playwright automation. They design eight heuristic-based anti-pattern detectors to quantify API quality on a 0–100 scale and correlate it with security implications. Findings reveal that minimal server-rendered sites achieve a perfect score of 100, while content-heavy commercial sites score as low as 56.8; 67% of sites exhibit redundant requests or cache misconfigurations, and 72% have over 20% third-party requests, with one page issuing up to 2,684 such calls. The open-sourced framework enables reproducible, systematic linkage between performance anti-patterns and security risks.
Tight coupling between security logic and business code in web applications degrades maintainability and weakens security assurance. Method: This paper proposes an aspect-oriented programming (AOP)-based modularization approach for security concerns, decoupling and encapsulating cross-cutting security mechanisms—including authentication, authorization, and input validation—into reusable aspects. We conduct a multi-scenario case study, complemented by ISO/IEC 25010–compliant code quality assessment, performance benchmarking (response time, throughput, memory consumption), and an empirical developer survey. Contribution/Results: Results demonstrate that AOP significantly improves cohesion and reusability of security modules, reduces code coupling, and enhances maintainability. The incurred runtime overhead is negligible (<2% across all metrics). This work establishes a reproducible, quantifiable AOP practice paradigm for security-driven software architecture, grounded in rigorous empirical evidence.
This study addresses the security risks arising from binary-level vulnerabilities—such as buffer overflows and use-after-free—in WebAssembly (WASM) modules, demonstrating how they can be exploited to manifest as high-level web vulnerabilities including SQL injection, XS-Leaks, and server-side template injection (SSTI), thereby evading existing web defense mechanisms. It is the first to systematically uncover the mapping relationship between low-level WASM binary flaws and web-layer security issues, filling a critical gap in the understanding of this threat surface. Through comprehensive vulnerability analysis, attack scenario modeling, and evaluation of current defenses, the work proposes targeted mitigation strategies and development best practices, offering both theoretical foundations and practical guidance for building more secure WASM applications.
This study addresses the inconsistent quality of freely available online web security tutorials, which often lack executable code and authoritative resource references, thereby limiting their practical utility for developers. The authors systematically evaluate 132 such tutorials and propose, for the first time, “executable code” and “citations to official resources” as key indicators of tutorial effectiveness. Through manual content analysis, they assess and categorize the tutorials across multiple dimensions—including topic coverage, author background, technical depth, and use of authoritative standards such as OWASP, CWE, and CVE. Findings reveal that most tutorials are vendor-provided and focus primarily on conceptual explanations, with only a minority offering complete, runnable code or linking to established security standards. This work provides developers with an evidence-based framework for identifying high-quality learning materials in web security.
Modern web browsers have evolved into critical business platforms, yet their client-side security posture lacks systematic assessment. This paper introduces the first purely frontend, in-browser security assessment framework, implemented in JavaScript and WebAssembly. It integrates over 120 fine-grained checks covering core mechanisms—including the Same-Origin Policy, Content Security Policy (CSP), sandboxing, and XSS protections—and uniquely incorporates previously unobservable OS- and network-layer dimensions such as WeakRef interference, SharedArrayBuffer availability, and internal network reachability. Leveraging dynamic policy injection and coordinated multi-API observation (e.g., Permissions, Crypto, and Reporting APIs), our empirical evaluation across enterprise environments reveals widespread policy degradation: CSP bypass rates reach 63% on legacy browsers, and SSL certificate validation is omitted in 41% of cases. The framework establishes a practical, evidence-based diagnostic paradigm for precise security hardening.
为解决LLM编码代理可能执行恶意请求的问题,提出SkillShield系统,通过在会话开始时注入安全技能来定义执行时的安全策略,有效减少恶意软件生成和攻击成功率。
本文探讨了大型语言模型在Web应用中的安全问题,通过提出一种结合语义输入验证、提示完整性保护等方法的监控和控制框架来解决这些问题。
This study addresses the limited understanding of how security features are implemented at the code level by conducting an empirical analysis of 561 security features across nine open-source Java systems, employing a combination of code mining and manual inspection. The research systematically examines the size, distribution, and coupling patterns of these features, revealing that their implementation extends far beyond simple library invocations. Furthermore, it uncovers pervasive large-scale code scattering and tight coupling throughout the analyzed systems. By quantifying the substantial code complexity required to integrate external security libraries, this work deepens the understanding of software security implementation mechanisms and provides critical evidence for advancing more secure software engineering practices.
研究通过在自然语言提示中添加安全要求,使用大语言模型生成的六种功能不同的Web应用程序,并比较了基线和安全意识版本的安全性。
本文针对现代Web应用的动态性和交互性,提出SpiderSapien,一种客户端中心的爬虫和安全扫描器,通过沉浸式交互提高代码覆盖率和漏洞检测率。