scispace - formally typeset
M

Martin Johns

Researcher at Braunschweig University of Technology

Publications -  93
Citations -  2244

Martin Johns is an academic researcher from Braunschweig University of Technology. The author has contributed to research in topics: Web application & Cross-site scripting. The author has an hindex of 24, co-authored 88 publications receiving 1902 citations. Previous affiliations of Martin Johns include University of Passau & Karlsruhe Institute of Technology.

Papers
More filters
Proceedings ArticleDOI

25 million flows later: large-scale detection of DOM-based XSS

TL;DR: This paper presents a fully automated system to detect and validate DOM-based XSS vulnerabilities, consisting of a taint-aware JavaScript engine and corresponding DOM implementation as well as a context-sensitive exploit generation approach.
Book ChapterDOI

Plug-in privacy for smart metering billing

TL;DR: In this paper, a plug-in privacy component is put into the communication link between a smart meter and a supplier's back-end system to enable billing with time-of-use tariffs without disclosing the actual consumption profile to the supplier.
Proceedings ArticleDOI

XSSDS: Server-Side Detection of Cross-Site Scripting Attacks

TL;DR: This paper proposes a passive detection system to identify successful XSS attacks, and based on a prototypical implementation, examines the approach's accuracy and verify its detection capabilities.
Book ChapterDOI

Security Testing: A Survey

TL;DR: The required background of testing and security engineering is summarized and recent developments of security testing techniques applied during the secure software development lifecycle, i.e., model-based security testing, code-based testing and static analysis, penetration testing and dynamic analysis, as well as security regression testing are discussed.
Posted Content

Plug-in privacy for Smart Metering billing

TL;DR: A privacy-preserving protocol that enables billing with time-of-use tariffs without disclosing the actual consumption profile to the supplier and a performance evaluation of a prototypical implementation is given.