CANDID: Dynamic candidate evaluations for automatic prevention of SQL injection attacks P Bisht, P Madhusudan, VN Venkatakrishnan ACM Transactions on Information and System Security (TISSEC) 13 (2), 14, 2010 | 397* | 2010 |
XSS-GUARD: precise dynamic prevention of cross-site scripting attacks P Bisht, V Venkatakrishnan Detection of Intrusions and Malware, and Vulnerability Assessment, 23-43, 2008 | 266 | 2008 |
Notamper: automatic blackbox detection of parameter tampering opportunities in web applications P Bisht, T Hinrichs, N Skrupsky, R Bobrowicz, VN Venkatakrishnan Proceedings of the 17th ACM conference on Computer and communications …, 2010 | 121 | 2010 |
Waptec: whitebox analysis of web applications for parameter tampering exploit construction P Bisht, T Hinrichs, N Skrupsky, VN Venkatakrishnan Proceedings of the 18th ACM conference on Computer and communications …, 2011 | 95 | 2011 |
System and a method for automatically detecting security vulnerabilities in client-server applications P Bisht, T Hinrichs, VN Venkatakrishnan US Patent 9,118,713, 2015 | 51 | 2015 |
Automatically preparing safe SQL queries P Bisht, AP Sistla, VN Venkatakrishnan Financial Cryptography and Data Security: 14th International Conference, FC …, 2010 | 34 | 2010 |
TamperProof: a server-agnostic defense for parameter tampering attacks on web applications N Skrupsky, P Bisht, T Hinrichs, VN Venkatakrishnan, L Zuck Proceedings of the third ACM conference on Data and application security and …, 2013 | 26 | 2013 |
Analysis of hypertext isolation techniques for XSS prevention M Ter Louw, P Bisht, V Venkatakrishnan Web 2.0 Security and Privacy 2008, 2008 | 18* | 2008 |
Waves: Automatic synthesis of client-side validation code for web applications N Skrupsky, M Monshizadeh, P Bisht, T Hinrichs, VN Venkatakrishnan, ... 2012 International Conference on Cyber Security, 46-53, 2012 | 15 | 2012 |
Apparatus for enhancing web application security and method therefor VN Venkatakrishnan, P Bisht, AP Sistla US Patent App. 13/351,853, 2012 | 14 | 2012 |
Strengthening XSRF defenses for legacy web applications using whitebox analysis and transformation M Zhou, P Bisht, VN Venkatakrishnan Information Systems Security: 6th International Conference, ICISS 2010 …, 2010 | 13 | 2010 |
Swipe: eager erasure of sensitive data in large scale systems software K Gondi, P Bisht, P Venkatachari, AP Sistla, VN Venkatakrishnan Proceedings of the second ACM conference on Data and Application Security …, 2012 | 11 | 2012 |
Taps: Automatically preparing safe sql queries P Bisht, AP Sistla, VN Venkatakrishnan Proceedings of the 17th ACM conference on Computer and communications …, 2010 | 11 | 2010 |
Webapparmor: a framework for robust prevention of attacks on web applications VN Venkatakrishnan, P Bisht, M Ter Louw, M Zhou, K Gondi, KT Ganesh Information Systems Security: 6th International Conference, ICISS 2010 …, 2010 | 11 | 2010 |
Notamper: Automatically detecting parameter tampering vulnerabilities in web applications P Bisht, T Hinrichs, N Skrupsky, R Bobrowicz, VN Venkatakrishnan ACM Conf. on Computer and Communications Security 10 (1866307.1866375), 2010 | 8 | 2010 |
Automated detection of parameter tampering opportunities and vulnerabilities in web applications P Bisht, T Hinrichs, N Skrupsky, VN Venkatakrishnan Journal of computer security 22 (3), 415-465, 2014 | 7 | 2014 |
CANDID: Preventing SQL Injection Attacks using Dynamic Candidate Evaluations, 2007 S Bandhakavi, P Bisht, P Madhusudan USA, ACM, 0 | 5 | |
CANDID: Preventing SQL injection attacks using dynamic candidate evaluations P Bisht, P Madhusudan, V Venkatakrishnan TISSEC, 2008 | 3 | 2008 |
Improving Web Security by Automated Extraction of Web Application Intent PPS Bisht University of Illinois at Chicago, 2011 | 1 | 2011 |
Analysis of Hypertext Markup Isolation Techniques for XSS Prevention M Ter Louw, P Bisht, VN Venkatakrishnan W2SP, 0 | 1 | |