This report documents the program and the outcomes of Dagstuhl Seminar 12401 ``Web Application Security''. The seminar brought 44 web security researchers together, coming from companies and research institutions across Europe and the US. The seminar had a well-filled program, with 3 keynotes, 28 research talks, and 15 5-minute talks. As web application security is a broad research domain, a diverse set of recent research results was presented during the talks, covering the web security vulnerability landscape, information-flow control, JavaScript formalization, JavaScript confinement, and infrastructure and server hardening. In addition to the plenary program, the seminar also featured three parallel break-out sessions on Cross-Site Scripting (XSS), JavaScript and Information-flow control.
@Article{desmet_et_al:DagRep.2.10.1, author = {Desmet, Lieven and Johns, Martin and Livshits, Benjamin and Sabelfeld, Andrei}, title = {{Web Application Security (Dagstuhl Seminar 12401)}}, pages = {1--37}, journal = {Dagstuhl Reports}, ISSN = {2192-5283}, year = {2013}, volume = {2}, number = {10}, editor = {Desmet, Lieven and Johns, Martin and Livshits, Benjamin and Sabelfeld, Andrei}, publisher = {Schloss Dagstuhl -- Leibniz-Zentrum f{\"u}r Informatik}, address = {Dagstuhl, Germany}, URL = {https://drops.dagstuhl.de/entities/document/10.4230/DagRep.2.10.1}, URN = {urn:nbn:de:0030-drops-39051}, doi = {10.4230/DagRep.2.10.1}, annote = {Keywords: Web application security, JavaScript, Secure interaction, Information flow, Secure composition, Application security, Web 2.0} }
Feedback for Dagstuhl Publishing