{"id":"https://openalex.org/W2141926088","doi":"https://doi.org/10.1109/ecrime.2008.4696969","title":"Practice &amp;#x00026; prevention of home-router mid-stream injection attacks","display_name":"Practice &amp;#x00026; prevention of home-router mid-stream injection attacks","publication_year":2008,"publication_date":"2008-10-01","ids":{"openalex":"https://openalex.org/W2141926088","doi":"https://doi.org/10.1109/ecrime.2008.4696969","mag":"2141926088"},"language":"en","primary_location":{"id":"doi:10.1109/ecrime.2008.4696969","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ecrime.2008.4696969","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2008 eCrime Researchers Summit","raw_type":"proceedings-article"},"type":"conference-paper","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5048005614","display_name":"Steve Myers","orcid":"https://orcid.org/0000-0002-7855-4033"},"institutions":[{"id":"https://openalex.org/I4210119109","display_name":"Indiana University Bloomington","ror":"https://ror.org/02k40bc56","country_code":"US","type":"education","lineage":["https://openalex.org/I4210119109","https://openalex.org/I592451"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Steven Myers","raw_affiliation_strings":["School of Informatics, Indiana University, Bloomington, IN, USA","Sch. of Inf., Indiana Univ., Bloomington, IN"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Informatics, Indiana University, Bloomington, IN, USA","institution_ids":["https://openalex.org/I4210119109"]},{"raw_affiliation_string":"Sch. of Inf., Indiana Univ., Bloomington, IN","institution_ids":["https://openalex.org/I4210119109"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5000041357","display_name":"Sid Stamm","orcid":"https://orcid.org/0000-0001-8556-5980"},"institutions":[{"id":"https://openalex.org/I4210119109","display_name":"Indiana University Bloomington","ror":"https://ror.org/02k40bc56","country_code":"US","type":"education","lineage":["https://openalex.org/I4210119109","https://openalex.org/I592451"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Sid Stamm","raw_affiliation_strings":["School of Informatics, Indiana University, Bloomington, IN, USA","Sch. of Inf., Indiana Univ., Bloomington, IN"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Informatics, Indiana University, Bloomington, IN, USA","institution_ids":["https://openalex.org/I4210119109"]},{"raw_affiliation_string":"Sch. of Inf., Indiana Univ., Bloomington, IN","institution_ids":["https://openalex.org/I4210119109"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I4210119109"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.19755289,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":94},"biblio":{"volume":"2139","issue":null,"first_page":"1","last_page":"14"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7370467185974121},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.7330056428909302},{"id":"https://openalex.org/keywords/router","display_name":"Router","score":0.6066607236862183},{"id":"https://openalex.org/keywords/cross-site-scripting","display_name":"Cross-site scripting","score":0.519428014755249},{"id":"https://openalex.org/keywords/password","display_name":"Password","score":0.5073391795158386},{"id":"https://openalex.org/keywords/cryptography","display_name":"Cryptography","score":0.47805503010749817},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.47712254524230957},{"id":"https://openalex.org/keywords/denial-of-service-attack","display_name":"Denial-of-service attack","score":0.437470018863678},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.42348620295524597},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.3526943325996399},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.32983237504959106},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.1714569628238678},{"id":"https://openalex.org/keywords/web-application-security","display_name":"Web application security","score":0.10764816403388977},{"id":"https://openalex.org/keywords/web-development","display_name":"Web development","score":0.09144023060798645}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7370467185974121},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.7330056428909302},{"id":"https://openalex.org/C2775896111","wikidata":"https://www.wikidata.org/wiki/Q642560","display_name":"Router","level":2,"score":0.6066607236862183},{"id":"https://openalex.org/C39569185","wikidata":"https://www.wikidata.org/wiki/Q371199","display_name":"Cross-site scripting","level":5,"score":0.519428014755249},{"id":"https://openalex.org/C109297577","wikidata":"https://www.wikidata.org/wiki/Q161157","display_name":"Password","level":2,"score":0.5073391795158386},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.47805503010749817},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.47712254524230957},{"id":"https://openalex.org/C38822068","wikidata":"https://www.wikidata.org/wiki/Q131406","display_name":"Denial-of-service attack","level":3,"score":0.437470018863678},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.42348620295524597},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.3526943325996399},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.32983237504959106},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.1714569628238678},{"id":"https://openalex.org/C59241245","wikidata":"https://www.wikidata.org/wiki/Q4781497","display_name":"Web application security","level":4,"score":0.10764816403388977},{"id":"https://openalex.org/C79373723","wikidata":"https://www.wikidata.org/wiki/Q386275","display_name":"Web development","level":3,"score":0.09144023060798645}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/ecrime.2008.4696969","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ecrime.2008.4696969","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2008 eCrime Researchers Summit","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","score":0.6899999976158142,"id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":39,"referenced_works":["https://openalex.org/W51761525","https://openalex.org/W99502526","https://openalex.org/W192852914","https://openalex.org/W1489922337","https://openalex.org/W1509316335","https://openalex.org/W1511560695","https://openalex.org/W1567046609","https://openalex.org/W1568881000","https://openalex.org/W1570296326","https://openalex.org/W1594550369","https://openalex.org/W1595564425","https://openalex.org/W1607915502","https://openalex.org/W1791023610","https://openalex.org/W1983523456","https://openalex.org/W1993702489","https://openalex.org/W2012307997","https://openalex.org/W2084641398","https://openalex.org/W2108254973","https://openalex.org/W2118123121","https://openalex.org/W2121655131","https://openalex.org/W2131523719","https://openalex.org/W2138194734","https://openalex.org/W2143156479","https://openalex.org/W2144696387","https://openalex.org/W2146567535","https://openalex.org/W2148888468","https://openalex.org/W2150477710","https://openalex.org/W2159460804","https://openalex.org/W2167036677","https://openalex.org/W2168563136","https://openalex.org/W2169177434","https://openalex.org/W2335888457","https://openalex.org/W2463752017","https://openalex.org/W6602115512","https://openalex.org/W6630353393","https://openalex.org/W6634033044","https://openalex.org/W6636250284","https://openalex.org/W6671777941","https://openalex.org/W6684770248"],"related_works":["https://openalex.org/W4366502726","https://openalex.org/W2023038964","https://openalex.org/W2075358766","https://openalex.org/W2981036578","https://openalex.org/W4289527657","https://openalex.org/W2578193553","https://openalex.org/W3127702456","https://openalex.org/W1985998952","https://openalex.org/W2987138895","https://openalex.org/W4400973582"],"abstract_inverted_index":{"The":[0,115,171],"vulnerability":[1],"of":[2,21,71,93,102,176,188,206,214,247,262,286],"home":[3,50,127,142],"routers":[4],"has":[5,11],"been":[6,12],"widely":[7],"discussed,":[8],"but":[9,244],"there":[10],"significant":[13],"skepticism":[14],"in":[15,227],"many":[16,69,289],"quarters":[17],"about":[18],"the":[19,84,96,130,136,189,204,212,215,223,228,248,252,255,260,283],"viability":[20],"using":[22],"them":[23],"to":[24,55,108,144,157,217,225,251,294],"perform":[25,56],"damaging":[26],"attacks.":[27,170],"Others":[28],"have":[29],"argued":[30],"that":[31,191],"traditional":[32],"malware":[33,122],"prevention":[34],"technologies":[35],"will":[36],"function":[37],"for":[38,282],"routers.":[39],"In":[40],"this":[41],"paper":[42],"we":[43,151],"show":[44],"how":[45],"easily":[46,110],"and":[47,65,81,132,148,153,164,182,197,235],"effectively":[48],"a":[49,57,90,99,105,139,174,279],"router":[51,143],"can":[52,86],"be":[53,109],"repurposed":[54],"mid-stream":[58],"script":[59,116,168],"injection":[60,117,169],"attack.":[61],"This":[62],"attack":[63,85,118,137,163,207,216,226],"transparently":[64],"indiscriminately":[66],"siphons":[67],"off":[68],"cases":[70],"user":[72,97],"entered":[73],"form-data":[74],"from":[75],"arbitrary":[76],"(non-encrypted)":[77],"Web-sites,":[78],"including":[79],"usernames":[80],"passwords.":[82],"Additionally,":[83],"take":[87],"place":[88],"over":[89],"long":[91],"period":[92],"time":[94],"affecting":[95],"at":[98],"large":[100],"number":[101],"sites":[103],"allowing":[104],"userpsilas":[106],"information":[107],"correlated":[111],"by":[112,292],"one":[113],"attacker.":[114],"is":[119],"performed":[120],"through":[121],"placed":[123],"on":[124,138,180,199,288],"an":[125],"insecure":[126],"router,":[128],"between":[129],"client":[131],"server.":[133],"We":[134],"implemented":[135],"commonly":[140],"deployed":[141,242],"demonstrate":[145],"its":[146],"realizability":[147],"potential.":[149],"Next,":[150],"propose":[152],"implement":[154],"efficient":[155],"countermeasures":[156,172,232,256],"discourage":[158],"or":[159,264,274],"prevent":[160],"both":[161,195],"our":[162],"other":[165],"Web":[166,192],"targeted":[167],"are":[173,194,233,241],"form":[175],"short-term":[177],"tamper-prevention":[178],"based":[179],"obfuscation":[181],"cryptographic":[183,272,277],"hashing.":[184],"It":[185],"takes":[186],"advantage":[187],"fact":[190],"scripts":[193],"delivered":[196],"interpreted":[198],"demand.":[200],"Rather":[201],"than":[202],"preventing":[203],"possibility":[205],"altogether,":[208],"they":[209,238,268],"simply":[210],"raise":[211],"cost":[213],"make":[218],"it":[219],"non-profitable":[220],"thus":[221],"removing":[222],"incentive":[224],"first":[229],"place.":[230],"These":[231],"robust":[234],"practically":[236],"deployable:":[237],"permit":[239],"caching,":[240],"server-side,":[243],"push":[245],"most":[246],"computational":[249],"effort":[250],"client.":[253],"Further,":[254,267],"do":[257,269],"not":[258,270],"require":[259,271],"modification":[261],"browsers":[263],"Internet":[265],"standards.":[266],"certificates":[273],"frequent":[275],"expensive":[276],"operations,":[278],"stumbling":[280],"block":[281],"proper":[284],"deployment":[285],"SSL":[287],"Web-servers":[290],"run":[291],"small":[293],"medium-sized":[295],"businesses.":[296]},"counts_by_year":[{"year":2016,"cited_by_count":1}],"updated_date":"2026-07-29T14:22:42.915294","created_date":"2025-10-10T00:00:00"}
