NISL
清华大学网络与信息安全实验室学术沙龙,欢迎关注~
This is the Paper Reading Seminar of Network and Information Security Lab (NISL) at Tsinghua University. Tune in for more details!
时间:2023年5月25日 14:00 - 16:00
腾讯会议:https://meeting.tencent.com/dm/nat9LS6rjR1w
会议ID:523-1869-1572
会议密码:230525
* 本次分享部分对外公开直播,线上参会者要求实名备注“姓名-单位”
Agenda
1.【论文分享】Web Cache Deception Escalates!
Presenter: 梁越嘉
Conference: USENIX Security'22
Authors: Seyed Ali Mirheidari, Matteo Golinelli, Kaan Onarlioglu, Engin Kirda, Bruno Crispo
Abstract: This paper explores Web Cache Deception (WCD) attacks, proposes a new detection method, and highlights the broader implications of WCD beyond personal information leaks. The authors conducted experiments on various websites, revealing numerous vulnerabilities and demonstrating the damaging effects of WCD on non-authenticated pages.
Link to paper: https://www.usenix.org/conference/usenixsecurity22/presentation/mirheidari
2.【论文分享】Bilingual Problems: Studying the Security Risks Incurred by Native Extensions in Scripting Languages
Presenter: 张书樵
Conference: USENIX Security'23
Authors: Cristian-Alexandru Staicu, Sazzadur Rahaman, Ágnes Kiss, Michael Backes
Abstract: The authors discuss a novel methodology for studying the misuse of the native extension API in scripting languages.
Link to paper: https://www.usenix.org/system/files/sec23fall-prepub-262_staicu.pdf
# 学术沙龙问卷反馈
编辑|许威 高泽豫
来源|NISL实验室
推荐站内搜索:最好用的开发软件、免费开源系统、渗透测试工具云盘下载、最新渗透测试资料、最新黑客工具下载……
还没有评论,来说两句吧...