课题基金 / 基金详情

TC: Small: Plugging Logic Loopholes in Hybrid Web Applications to Secure Web Commerce

TC: Small: Plugging Logic Loopholes in Hybrid Web Applications to Secure Web Commerce
TC:小:堵塞混合 Web 应用程序中的逻辑漏洞以保护 Web 商务
批准号:
1117106
负责人:
XiaoFeng Wang
金额:
$50.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2011
资助国家:
美国
项目状态:
已结题
起止时间:
2011-09-01 至 2015-08-31

项目摘要

项目成果

XiaoFeng Wang的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
With the increasing popularity of third-party services integrated in hybrid web applications, come new security challenges posed by the complexity in coordinating these individual services and the web client. Such complexity often brings in program logic flaws that can be exploited to induce inconsistencies among different services' internal states, causing the security control within these applications to fail. A preliminary study of this research investigated the security implications of the problem to online merchants that accept payments through third-party cashiers (e.g., PayPal, Amazon Payments and Google Checkout). It revealed stunning logic loopholes within leading merchant applications, popular online stores and a prestigious payment service provider, which can be exploited to purchase an item at an arbitrarily low price, shop for free after paying for one item, or even completely avoid payment. These findings point to a disturbing lack of understanding of the logic flaws within the integrations of web services, and an urgent need for significant research efforts on this important problem. This project endeavors to gain an in-depth understanding about the scope and the magnitude of the security threat posed by the logic flaws in hybrid web applications and the common design pitfalls that lead to such vulnerability. Based upon this understanding, it will study novel technologies to facilitate detection and patching of these flaws when developing merchant software, security analysis of other parties' applications and black-box testing of merchant websites. New techniques will also be developed to enable web-service providers to better support secure integrations of their services into merchant systems, and to automatically detect the attempts to exploit these logic flaws in web transactions. This research involves industry collaborators and will also contribute to the improvement of security protection in other domains that utilize hybrid web applications.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Medium: Audacity of Exploration: Toward Automated Discovery of Security Flaws in Networked Systems through Intelligent Documentation Analysis
  • 批准号:
    2154199
  • 项目类别:
    Standard Grant
  • 资助金额:
    $55.0万
  • 财政年份:
    2022
  • 负责人:
    XiaoFeng Wang
  • 依托单位:
Collaborative Proposal: SaTC: Frontiers: Center for Distributed Confidential Computing (CDCC)
  • 批准号:
    2207231
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $294.0万
  • 财政年份:
    2022
  • 负责人:
    XiaoFeng Wang
  • 依托单位:
BIGDATA: IA: Enabling Large-Scale, Privacy-Preserving Genomic Computing with a Hardware-Assisted Secure Big-Data Analytics Framework
  • 批准号:
    1838083
  • 项目类别:
    Standard Grant
  • 资助金额:
    $100.0万
  • 财政年份:
    2019
  • 负责人:
    XiaoFeng Wang
  • 依托单位:
SaTC: CORE: Medium: Collaborative: Understanding and Discovering Illicit Online Business Through Automatic Analysis of Online Text Traces
  • 批准号:
    1801432
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $46.97万
  • 财政年份:
    2018
  • 负责人:
    XiaoFeng Wang
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: