Skip to main content

Showing 1–4 of 4 results for author: Tůma, P

Searching in archive cs. Search in all archives.
.
  1. DjangoChecker: Applying Extended Taint Tracking and Server Side Parsing for Detection of Context-Sensitive XSS Flaws

    Authors: Antonín Steinhauser, Petr Tůma

    Abstract: Cross-site scripting (XSS) flaws are a class of security flaws that permit the injection of malicious code into a web application. In simple situations, these flaws can be caused by missing input sanitizations. Sometimes, however, all application inputs are sanitized, but the sanitizations are not appropriate for the browser contexts of the sanitized values. Using an incorrect sanitizer can make t… ▽ More

    Submitted 14 May, 2020; originally announced May 2020.

    Journal ref: Software: Practice and Experience, 49(1): 130-148, 2019

  2. Database Traffic Interception for Graybox Detection of Stored and Context-Sensitive XSS

    Authors: Antonín Steinhauser, Petr Tůma

    Abstract: XSS is a security vulnerability that permits injecting malicious code into the client side of a web application. In the simplest situations, XSS vulnerabilities arise when a web application includes the user input in the web output without due sanitization. Such simple XSS vulnerabilities can be detected fairly reliably with blackbox scanners, which inject malicious payload into sensitive parts of… ▽ More

    Submitted 7 August, 2020; v1 submitted 7 May, 2020; originally announced May 2020.

    Journal ref: Digital Threats: Research and Practice, 1(3): 1-23, 2020

  3. Duet Benchmarking: Improving Measurement Accuracy in the Cloud

    Authors: Lubomír Bulej, Vojtěch Horký, Petr Tůma, François Farquet, Aleksandar Prokopec

    Abstract: We investigate the duet measurement procedure, which helps improve the accuracy of performance comparison experiments conducted on shared machines by executing the measured artifacts in parallel and evaluating their relative performance together, rather than individually. Specifically, we analyze the behavior of the procedure in multiple cloud environments and use experimental evidence to answer m… ▽ More

    Submitted 17 January, 2020; v1 submitted 16 January, 2020; originally announced January 2020.

  4. arXiv:1903.10267  [pdf, other

    cs.PL

    On Evaluating the Renaissance Benchmarking Suite: Variety, Performance, and Complexity

    Authors: Aleksandar Prokopec, Andrea Rosà, David Leopoldseder, Gilles Duboscq, Petr Tůma, Martin Studener, Lubomír Bulej, Yudi Zheng, Alex Villazón, Doug Simon, Thomas Wuerthinger, Walter Binder

    Abstract: The recently proposed Renaissance suite is composed of modern, real-world, concurrent, and object-oriented workloads that exercise various concurrency primitives of the JVM. Renaissance was used to compare performance of two stateof-the-art, production-quality JIT compilers (HotSpot C2 and Graal), and to show that the performance differences are more significant than on existing suites such as DaC… ▽ More

    Submitted 25 March, 2019; originally announced March 2019.