Currently, no news are available
The Web Security Seminar
For registration, please apply for this seminar through the central seminar assignment system.
The Web Security Seminar will teach students to present, analyze, discuss, and summarize papers in different areas of Web security. The seminar combines a reading group with (almost) weekly meetings and a regular seminar, where students will write a seminar paper.
Each student will get a topic assigned, consisting of a lead and a follow-up paper. The student will present the follow-up paper in a 20-minute presentation followed by a 10-minute Q&A. Afterwards we will all discuss the lead paper as a reading group. All students must read the lead paper and, before each session, must submit a summary with strengths and weaknesses.
Finally, each student will write a seminar paper on the topic assigned to them, for which the two papers serve as the starting point.
- Kickoff on Monday, 30.10.2023, 10:15-12:00, CISPA main building, room (TBD)
- (Semi) Regular seminar sessions on Wednesdays. First session is on Monday, 13.11.2023, 10:15-12:00
- Each Sunday at 23:59 before each session, submit the paper summary (one page max) with discussion points: three items for the strengths, three items for the weaknesses, and future work
- Optional feedback round before your session (arrange exact time with your supervisor)
- Attendance in all meetings and submission of summary and discussion points for each topic is mandatory. For exceptional cases, contact the teaching staff.
Note that we will not offer a hybrid solution. We plan to have in-person meetings as long as possible and switch to fully online if the need arises.
Seminar Paper Details
We will cover the different types of seminar paper during the kickoff session.
All seminar papers are due on (see below). Based on your submission, you will receive feedback within one week and have until (see below) to improve your paper. The paper grading will be on the final version. Note that the first submission must already be sufficient to pass. If you submit a half-baked version of the paper, you will likely fail the course.
Each paper must use the provided template. It must not be longer than 8 pages, not counting references and appendices. Note that appendices are not meant to provide information that is absolutely necessary to understand the paper, but rather to provide auxiliary material. Papers can be shorter, but in general the provided page limit is a good indicator of how long a paper should be.
Schedule, List of Topics, and Papers
|20.11.23||10:15-12:00||Topic 2: Obtaining and Selling User Profiles on Cybercriminal Markets||Giada|
|04.12.23||10:15-12:00||Topic 3: Prototype Pollution||Cris|
|11.12.23||10:15-12:00||Topic 4: User Browsing Behavior vs. Top Lists||
|18.12.23||10:15-12:00||Topic 5: Phished and 2FA'd: Stolen Credentials and Forged Fingerprints||Giada|
|08.01.24||10:15-12:00||Topic 6: Software Supply Chain Security||Cris|
|15.01.24||10:15-12:00||Topic 7: XS-Leaks||Jannis|
|22.01.24||10:15-12:00||Topic 8: Browser Extensions & Client-Side Security||Shubham|
|29.01.24||10:15-12:00||Topic 9: Web Application Scanners||Alex|
|05.02.24||10:15-12:00||Topic 10: Cross-language Interaction in the Web||Cris|
|12.02.24||10:15-12:00||Topic 11: Beyond Malicious Extensions: How can Extensions put User Security & Privacy at Risk?||Aurore|
|19.02.24||10:15-12:00||Topic 12: Reproducibility in Web Measurements||Florian|