IS542: Web Service Security and Privacy
The course provides in-depth studies of numerous web attacks and defenses. The course covers comprehensive security vulnerabilities and privacy risks that exist on the Web. We will also discuss how to detect those vulnerabilities and alleviate the privacy risks.
Basic Information
- Lecture: Monday/Wednesday 10:30 - 12:00, Room 1217 E3-2
- Instructor: Sooel Son
- Email: sl.son (at) kaist.ac.kr
- Homepage: https://sites.google.com/site/ssonkaist/
- Office hours: TBD
- T.A.:
- Dongwon Shin: dongwon.shin (at) kaist.ac.kr
- Seongho Keum: keum07 (at) kaist.ac.kr
- Junkyu Kang: jkkang130 (at) kaist.ac.kr
Evaluation
- Attendance/Participation: 10%
- Midterm exam: 20%
- HW: Paper Critique: 10%
- Presentation: 20%
- Project: 40%
Schedule
-
8/31 Course Introduction
- 9/2 Web programming
- Group project announced
- 9/7 Server-side Web attacks(1)
- Reading materials
N. Jovanovic et al. Pixy: a static analysis tool for detecting Web application vulnerabilities (S&P 2006) S. Bandhakavi et al. CANDID: preventing sql injection attacks using dynamic candidate evaluations (CCS 2007) Son et al. "Diglossia: Detecting Code-Injection Attacks with Precision and Efficiency" (CCS 2013) Ray et al. "Defining Code-injection Attacks" (POPL 2012)
- Reading materials
- 9/9 Server-side Web attacks(2)
- Team selection due 9/16 (2 persons for one team)
- 9/14 Cross-site Scripting (1)
- Reading materials
Zalewski. "Postcards from the Post-XSS World" (2011) S. Lekis et al. 25 million flows later: large-scale detection of DOM-based XSS (CCS 2013)
- Reading materials
-
9/16 Cross-site Scripting (2)
- 9/21 Content Security Policy
- Reading materials
L. Weichselbaum et al. CSP Is Dead, Long Live CSP! On the Insecurity of Whitelists and the Future of Content Security Policy, (CCS 2016) A. Doupe et al. deDacota: Toward Preventing Server-Side XSS via Automatic Code and Data Separation (CCS 2013)
- Reading materials
-
9/23 Holiday(Chusuk)
- 9/28 CSRF
- Reading materials
A. Barth et al. Robust Defenses for Cross-Site Request Forgery, (CCS 2008)
- Reading materials
- 9/30 Clickjacking & Browser extensions
- Reading materials
Huang et al. Clickjacking: Attacks and Defenses (Usenix Security 2012) Rydstedt et al. Busting frame busting: a study of clickjacking vulnerabilities at popular sites (W2SP 2010) A. Kapravelos et al. Hulk: Eliciting Malicious Behavior in Browser Extensions, (USENIX 2014) Thomas et al. Ad Injection at Scale: Assessing Deceptive Advertisement Modifications (S&P 2015) Jagpal et al. Trends and Lessons from Three Years Fighting Malicious Extensions (USENIX 2015)
- Reading materials
-
10/5 [No class] Holiday
- 10/7 Phishing & Spam
- Reading materials
Jagatic et al. Social Phishing, (Communication of ACM, 2007)
- Reading materials
- 10/12 Password & Two-factor Auth
- Reading materials
Bonneau et al. The Quest to Replace Passwords: A Framework for Comparative Evaluation of Web Authentication Schemes (S&P 2012). Bonneau. The Science of Guessing: Analyzing an Anonymized Corpus of 70 Million Passwords (S&P 2012) Universal 2nd Factor (U2F) Overview (FIDO Alliance Proposed Standard, 2015)
- Reading materials
-
10/14 HTTPS
-
10/19 [No class] Midterm season
- 10/21 Midterm exam
- Room E3-2 1217
- 09:00 A.M. ~ 11:45 A.M.
- 10/26 Student Presentation - Web application vulnerabilities
- Presenter 1:
Khodayari et al. It's (DOM) Clobbering Time: Attack Techniques, Prevalence, and Defenses. (S&P 2023) - Presenter 2:
Stafeev et al. YuraScanner: Leveraging LLMs for Task-driven Web App Scanning (NDSS 2024)
- Presenter 1:
- 10/28 Student Presentation - Web service vulnerabilities
- Presenter 1:
Khodayari et al. The Great Request Robbery: An Empirical Study of Client-side Request Hijacking Vulnerabilities on the Web (S&P 2024) - Presenter 2:
Lee et al. Connecting the Dots: An Investigative Study on Linking Private User Data Across Messaging App. (NDSS 2026)
- Presenter 1:
- 11/2 Student Presentation - Emerging web attacks
- Presenter 1:
Beer et al. TapTrap: Animation-Driven Tapjacking on Android (Security 2025) - Presenter 2:
Vlummens et al. Bridges to Self: Silent Web-to-App Tracking on Mobile via Localhost (Security 2025)
- Presenter 1:
- 11/4 Student Presentation - Phishing
- Presenter 1:
Oest et al. Sunrise to Sunset: Analyzing the End-to-end Life Cycle and Effectiveness of Phishing Attacks at Scale (USENIX 2020) - Presenter 2:
Lee et al. 7 Days Later: Analyzing Phishing-Site Lifespan After Detected (WWW 2025)
- Presenter 1:
- 11/9 Student Presentation - Agent vulnerabilities
- Presenter 1:
Son et al. AgentBreaker: Evaluating Context-Aware Indirect Prompt Injection Risks in Modern Web Agents (ISSTA 2026) - Presenter 2:
Xu et al. AdvAgent: Controllable Blackbox Red-teaming on Web Agents (ICML 2025)
- Presenter 1:
- 11/11 Student Presentation - Browser security
- Presenter 1:
Lee et al. Site Isolation is Dead: How Site Isolation is Broken in Agentic Browsers and Extensions (S&P 2026) - Presenter 2:
Jung et al. BUIzz: Finding Policy Enforcement Bugs via Interaction Simulation on the Browser User Interface (Security 2026)
- Presenter 1:
-
11/16 [No class] (CCS)
- 11/18 Student Presentation - Web attacks
- Presenter 1:
Drescher et al. In the DOM We Trust: Exploring the Hidden Dangers of Reading from the DOM on the Web. (CCS 2025) - Presenter 2:
Kirchner et al. Dancer in the dark: Synthesizing and evaluating polyglots for blind {Cross-Site} scripting (Security 2024)
- Presenter 1:
- 11/23 Student Presentation - Web measurements
- Presenter 1:
Mustafa et al. LeakyLinks: Measuring the Security and Privacy Risks of URL Scanning Services (S&P 2026) - Presenter 2:
Fernandez-de-Retana et al. A Permissions Odyssey: A Systematic Study of Browser Permissions on Modern Websites (IMC 2025)
- Presenter 1:
- 11/25 Student Presentation - Tracking
- Presenter 1:
Munir et al. CookieGraph: Understanding and Detecting First-Party Tracking Cookies (CCS 2023) - Presenter 2:
Oest et al. PhishTime: Continuous Longitudinal Measurement of the Effectiveness of Anti-phishing Blacklists (USENIX 2020)
- Presenter 1:
-
12/7 Project Presentation
- 12/9 Project Presentation