cispa / http-conformanceLinks
Code for our 2024 ACM AsiaCCS Paper "Who's Breaking the Rules? Studying Conformance to the HTTP Specifications and its Security Impact"
☆16Updated last year
Alternatives and similar repositories for http-conformance
Users that are interested in http-conformance are comparing it to the libraries listed below
Sorting:
- ☆25Updated 3 years ago
- Holistic Concolic Execution for Dynamic Web Applications via Symbolic Interpreter Analysis (IEEE S&P 2024)☆12Updated last year
- FuzzCache: Optimizing Web Application Fuzzing Through Software-Based Data Cache (ACM CCS 2024)☆17Updated 11 months ago
- YuraScanner☆54Updated 8 months ago
- Collection of community-driven CodeQL query, library and extension packs☆187Updated last month
- ☆42Updated 2 years ago
- 一个搜索网络安全领域顶会论文的小工具☆91Updated 2 months ago
- ☆191Updated this week
- Atropos: Effective Fuzzing of Web Applications for Server-Side Vulnerabilities☆73Updated last year
- ☆27Updated last year
- QUICforge is an experimental python tool for request forgery attacks with QUIC☆23Updated 3 years ago
- A neurosymbolic framework for vulnerability detection in code☆245Updated 2 weeks ago
- ☆20Updated last month
- Effective ReDoS Detection by Principled Vulnerability Modeling and Exploit Generation☆14Updated 2 months ago
- Grammar-based HTTP/2 fuzzer with mutation ability☆47Updated 3 years ago
- ☆29Updated 3 years ago
- [NDSS 2024] ReqsMiner is an innovative fuzzing framework developed to discover previously unexamined inconsistencies in CDN forwarding re…☆23Updated last year
- Corax for Java: A general static analysis framework for java code checking.☆253Updated 10 months ago
- YASA is an open-source static program analysis project. Its core innovation lies in a unified intermediate representation called UAST, d…☆144Updated this week
- A semantic-based tool to detect credential leakage in mini-apps.☆13Updated last year
- CodeQL zero to hero blog post series challenges☆145Updated 3 weeks ago
- 《深入理解Semgrep》Finding vulnerabilities with Semgrep.☆55Updated 2 years ago
- A structure-aware grey box fuzzer based on modeling the input processing logic.☆171Updated last year
- 静态分析基础教程☆170Updated last month
- ☆29Updated 5 months ago
- A benchmark to evaluate taint analysis☆29Updated 3 years ago
- ☆172Updated last month
- ☆14Updated 2 years ago
- MCPCorpus is a comprehensive dataset for analyzing the Model Context Protocol (MCP) ecosystem, containing ~14K MCP servers and 300 MCP cl…☆24Updated last month
- 用来将Tai-e改造为开箱即用的静态代码安全分析框架的一些demo☆37Updated last year