29.11.2012 Views

2nd USENIX Conference on Web Application Development ...

2nd USENIX Conference on Web Application Development ...

2nd USENIX Conference on Web Application Development ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Web</strong>Apps ’11: <str<strong>on</strong>g>2nd</str<strong>on</strong>g> <str<strong>on</strong>g>USENIX</str<strong>on</strong>g> <str<strong>on</strong>g>C<strong>on</strong>ference</str<strong>on</strong>g> <strong>on</strong> <strong>Web</strong> Applicati<strong>on</strong> <strong>Development</strong><br />

June 15–16, 2011<br />

Portland, OR, USA<br />

Message from the Program Chair . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . v<br />

Wednesday, June 15<br />

10:30–No<strong>on</strong><br />

GuardRails: A Data-Centric <strong>Web</strong> Applicati<strong>on</strong> Security Framework . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .1<br />

J<strong>on</strong>athan Burket, Patrick Mutchler, Michael Weaver, Muzzammil Zaveri, and David Evans, University of<br />

Virginia<br />

PHP Aspis: Using Partial Taint Tracking to Protect Against Injecti<strong>on</strong> Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . .13<br />

Ioannis Papagiannis, Matteo Migliavacca, and Peter Pietzuch, Imperial College L<strong>on</strong>d<strong>on</strong><br />

Secure Data Preservers for <strong>Web</strong> Services . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .25<br />

Jayanthkumar Kannan, Google Inc.; Petros Maniatis, Intel Labs; Byung-G<strong>on</strong> Chun, Yahoo! Research<br />

1:00–2:30<br />

BenchLab: An Open Testbed for Realistic Benchmarking of <strong>Web</strong> Applicati<strong>on</strong>s . . . . . . . . . . . . . . . . . . . . . . . . . . . .37<br />

Emmanuel Cecchet, Veena Udayabhanu, Timothy Wood, and Prashant Shenoy, University of Massachusetts<br />

Amherst<br />

Resource Provisi<strong>on</strong>ing of <strong>Web</strong> Applicati<strong>on</strong>s in Heterogeneous Clouds . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .49<br />

Jiang Dejun, VU University Amsterdam and Tsinghua University Beijing; Guillaume Pierre, VU University<br />

Amsterdam; Chi-Hung Chi, Tsinghua University Beijing<br />

C3: An Experimental, Extensible, Rec<strong>on</strong>figurable Platform for HTML-based Applicati<strong>on</strong>s . . . . . . . . . . . . . . . . . .61<br />

Benjamin S. Lerner and Brian Burg, University of Washingt<strong>on</strong>; Herman Venter and Wolfram Schulte, Microsoft<br />

Research<br />

3:00–4:30<br />

The Effectiveness of Applicati<strong>on</strong> Permissi<strong>on</strong>s . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .75<br />

Adrienne Porter Felt, Kate Greenwood, and David Wagner, University of California, Berkeley<br />

Experiences <strong>on</strong> a Design Approach for Interactive <strong>Web</strong> Applicati<strong>on</strong>s . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .87<br />

Janne Kuuskeri, Tampere University of Technology<br />

Exploring the Relati<strong>on</strong>ship Between <strong>Web</strong> Applicati<strong>on</strong> <strong>Development</strong> Tools and Security . . . . . . . . . . . . . . . . . . . . .99<br />

Matthew Finifter and David Wagner, University of California, Berkeley<br />

Thursday, June 16<br />

1:00–2:30<br />

Integrating L<strong>on</strong>g Polling with an MVC <strong>Web</strong> Framework . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .113<br />

Eric Stratmann, John Ousterhout, and Sameer Madan, Stanford University<br />

Detecting Malicious <strong>Web</strong> Links and Identifying Their Attack Types . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .125<br />

Hyunsang Choi, Korea University; Bin B. Zhu, Microsoft Research Asia; Heejo Lee, Korea University<br />

Maverick: Providing <strong>Web</strong> Applicati<strong>on</strong>s with Safe and Flexible Access to Local Devices . . . . . . . . . . . . . . . . . . . .137<br />

David W. Richards<strong>on</strong> and Steven D. Gribble, University of Washingt<strong>on</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!