HornDroid: Practical and sound static analysis of Android applications by SMT solving S Calzavara, I Grishchenko, M Maffei 2016 IEEE European Symposium on Security and Privacy (EuroS&P), 47-62, 2016 | 89 | 2016 |
Surviving the web: A journey into web session security S Calzavara, R Focardi, M Squarcina, M Tempesta ACM Computing Surveys (CSUR) 50 (1), 1-34, 2017 | 78 | 2017 |
Content security problems? evaluating the effectiveness of content security policy in the wild S Calzavara, A Rabitti, M Bugliesi Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications …, 2016 | 78 | 2016 |
CookiExt: Patching the browser against session hijacking attacks M Bugliesi, S Calzavara, R Focardi, W Khan Journal of Computer Security 23 (4), 509-537, 2015 | 59 | 2015 |
Complex security policy? a longitudinal analysis of deployed content security policies S Roth, T Barron, S Calzavara, N Nikiforakis, B Stock Proceedings of the 27th Network and Distributed System Security Symposium (NDSS), 2020 | 56 | 2020 |
Formal methods for web security M Bugliesi, S Calzavara, R Focardi Journal of Logical and Algebraic Methods in Programming 87, 110-126, 2017 | 55 | 2017 |
Semantics-based analysis of content security policy deployment S Calzavara, A Rabitti, M Bugliesi ACM Transactions on the Web (TWEB) 12 (2), 1-36, 2018 | 54 | 2018 |
Treant: training evasion-aware decision trees S Calzavara, C Lucchese, G Tolomei, SA Abebe, S Orlando Data Mining and Knowledge Discovery 34 (5), 1390-1420, 2020 | 52 | 2020 |
Mitch: A machine learning approach to the black-box detection of CSRF vulnerabilities S Calzavara, M Conti, R Focardi, A Rabitti, G Tolomei 2019 IEEE European Symposium on Security and Privacy (EuroS&P), 528-543, 2019 | 47 | 2019 |
On compliance of cookie purposes with the purpose specification principle I Fouad, C Santos, F Al Kassar, N Bielova, S Calzavara 2020 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW …, 2020 | 43 | 2020 |
Lintent: Towards security type-checking of Android applications M Bugliesi, S Calzavara, A Spanò International Conference on Formal Methods for Open Object-Based Distributed …, 2013 | 41 | 2013 |
Adversarial training of gradient-boosted decision trees S Calzavara, C Lucchese, G Tolomei Proceedings of the 28th ACM international conference on information and …, 2019 | 39 | 2019 |
Postcards from the post-http world: Amplification of https vulnerabilities in the web ecosystem S Calzavara, R Focardi, M Nemec, A Rabitti, M Squarcina 2019 IEEE Symposium on Security and Privacy (SP), 281-298, 2019 | 38 | 2019 |
Quite a mess in my cookie jar! Leveraging machine learning to protect web authentication S Calzavara, G Tolomei, M Bugliesi, S Orlando Proceedings of the 23rd international conference on World wide web, 189-200, 2014 | 38 | 2014 |
A supervised learning approach to protect client authentication on the web S Calzavara, G Tolomei, A Casini, M Bugliesi, S Orlando ACM Transactions on the Web (TWEB) 9 (3), 1-30, 2015 | 36 | 2015 |
Automatic and robust client-side protection for cookie-based sessions M Bugliesi, S Calzavara, R Focardi, W Khan Engineering Secure Software and Systems: 6th International Symposium, ESSoS …, 2014 | 32 | 2014 |
A tale of two headers: a formal analysis of inconsistent {Click-Jacking} protection on the web S Calzavara, S Roth, A Rabitti, M Backes, B Stock 29th USENIX Security Symposium (USENIX Security 20), 683-697, 2020 | 30 | 2020 |
Reining in the web's inconsistencies with site policy S Calzavara, T Urban, D Tatang, M Steffens, B Stock Proceedings of the Network and Distributed System Security Symposium 2021, 2021 | 29 | 2021 |
Provably sound browser-based enforcement of web session integrity M Bugliesi, S Calzavara, R Focardi, W Khan, M Tempesta 2014 IEEE 27th Computer Security Foundations Symposium, 366-380, 2014 | 28 | 2014 |
Can i take your subdomain? exploring {Same-Site} attacks in the modern web M Squarcina, M Tempesta, L Veronese, S Calzavara, M Maffei 30th USENIX Security Symposium (USENIX Security 21), 2917-2934, 2021 | 27* | 2021 |