Creative Commons Attribution-NonCommercial-NoDerivs 3.0 Unported license
This report documents the program and the outcomes of Dagstuhl Seminar 12401 ``Web Application Security''. The seminar brought 44 web security researchers together, coming from companies and research institutions across Europe and the US. The seminar had a well-filled program, with 3 keynotes, 28 research talks, and 15 5-minute talks. As web application security is a broad research domain, a diverse set of recent research results was presented during the talks, covering the web security vulnerability landscape, information-flow control, JavaScript formalization, JavaScript confinement, and infrastructure and server hardening. In addition to the plenary program, the seminar also featured three parallel break-out sessions on Cross-Site Scripting (XSS), JavaScript and Information-flow control.
@Article{desmet_et_al:DagRep.2.10.1,
author = {Desmet, Lieven and Johns, Martin and Livshits, Benjamin and Sabelfeld, Andrei},
title = {{Web Application Security (Dagstuhl Seminar 12401)}},
pages = {1--37},
journal = {Dagstuhl Reports},
ISSN = {2192-5283},
year = {2013},
volume = {2},
number = {10},
editor = {Desmet, Lieven and Johns, Martin and Livshits, Benjamin and Sabelfeld, Andrei},
publisher = {Schloss Dagstuhl -- Leibniz-Zentrum f{\"u}r Informatik},
address = {Dagstuhl, Germany},
URL = {https://drops.dagstuhl.de/entities/document/10.4230/DagRep.2.10.1},
URN = {urn:nbn:de:0030-drops-39051},
doi = {10.4230/DagRep.2.10.1},
annote = {Keywords: Web application security, JavaScript, Secure interaction, Information flow, Secure composition, Application security, Web 2.0}
}