{"id":"https://openalex.org/W2243132820","doi":"https://doi.org/10.1145/2754933","title":"A Supervised Learning Approach to Protect Client Authentication on the Web","display_name":"A Supervised Learning Approach to Protect Client Authentication on the Web","publication_year":2015,"publication_date":"2015-06-12","ids":{"openalex":"https://openalex.org/W2243132820","doi":"https://doi.org/10.1145/2754933","mag":"2243132820"},"language":"en","primary_location":{"id":"doi:10.1145/2754933","is_oa":false,"landing_page_url":"https://doi.org/10.1145/2754933","pdf_url":null,"source":{"id":"https://openalex.org/S131231701","display_name":"ACM Transactions on the Web","issn_l":"1559-1131","issn":["1559-1131","1559-114X"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on the Web","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"http://hdl.handle.net/10278/3661257","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5084675121","display_name":"Stefano Calzavara","orcid":"https://orcid.org/0000-0001-9179-8270"},"institutions":[{"id":"https://openalex.org/I149461666","display_name":"Ca' Foscari University of Venice","ror":"https://ror.org/04yzxz566","country_code":"IT","type":"education","lineage":["https://openalex.org/I149461666"]}],"countries":["IT"],"is_corresponding":true,"raw_author_name":"Stefano Calzavara","raw_affiliation_strings":["Universit\u00e0 Ca\u2019 Foscari Venezia, Venezia Mestre (Italy)"],"affiliations":[{"raw_affiliation_string":"Universit\u00e0 Ca\u2019 Foscari Venezia, Venezia Mestre (Italy)","institution_ids":["https://openalex.org/I149461666"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5011299100","display_name":"Gabriele Tolomei","orcid":"https://orcid.org/0000-0001-7471-6659"},"institutions":[{"id":"https://openalex.org/I1325784139","display_name":"Yahoo (United Kingdom)","ror":"https://ror.org/038p3gq39","country_code":"GB","type":"company","lineage":["https://openalex.org/I1325784139","https://openalex.org/I4210134091"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Gabriele Tolomei","raw_affiliation_strings":["Universit\u00e0 Ca\u2019 Foscari Venezia; Yahoo Labs, London UK"],"affiliations":[{"raw_affiliation_string":"Universit\u00e0 Ca\u2019 Foscari Venezia; Yahoo Labs, London UK","institution_ids":["https://openalex.org/I1325784139"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103080383","display_name":"Andrea Casini","orcid":"https://orcid.org/0000-0003-3608-9724"},"institutions":[{"id":"https://openalex.org/I149461666","display_name":"Ca' Foscari University of Venice","ror":"https://ror.org/04yzxz566","country_code":"IT","type":"education","lineage":["https://openalex.org/I149461666"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Andrea Casini","raw_affiliation_strings":["Universit\u00e0 Ca\u2019 Foscari Venezia, Venezia Mestre (Italy)"],"affiliations":[{"raw_affiliation_string":"Universit\u00e0 Ca\u2019 Foscari Venezia, Venezia Mestre (Italy)","institution_ids":["https://openalex.org/I149461666"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5077037306","display_name":"Michele Bugliesi","orcid":"https://orcid.org/0000-0002-4567-3351"},"institutions":[{"id":"https://openalex.org/I149461666","display_name":"Ca' Foscari University of Venice","ror":"https://ror.org/04yzxz566","country_code":"IT","type":"education","lineage":["https://openalex.org/I149461666"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Michele Bugliesi","raw_affiliation_strings":["Universit\u00e0 Ca\u2019 Foscari Venezia, Venezia Mestre (Italy)"],"affiliations":[{"raw_affiliation_string":"Universit\u00e0 Ca\u2019 Foscari Venezia, Venezia Mestre (Italy)","institution_ids":["https://openalex.org/I149461666"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5066317336","display_name":"Salvatore Orlando","orcid":"https://orcid.org/0000-0002-4155-9797"},"institutions":[{"id":"https://openalex.org/I149461666","display_name":"Ca' Foscari University of Venice","ror":"https://ror.org/04yzxz566","country_code":"IT","type":"education","lineage":["https://openalex.org/I149461666"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Salvatore Orlando","raw_affiliation_strings":["Universit\u00e0 Ca\u2019 Foscari Venezia, Venezia Mestre (Italy)"],"affiliations":[{"raw_affiliation_string":"Universit\u00e0 Ca\u2019 Foscari Venezia, Venezia Mestre (Italy)","institution_ids":["https://openalex.org/I149461666"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5084675121"],"corresponding_institution_ids":["https://openalex.org/I149461666"],"apc_list":null,"apc_paid":null,"fwci":4.9777,"has_fulltext":false,"cited_by_count":26,"citation_normalized_percentile":{"value":0.95437447,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":"9","issue":"3","first_page":"1","last_page":"30"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.998199999332428,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.842610776424408},{"id":"https://openalex.org/keywords/heuristics","display_name":"Heuristics","score":0.8168339729309082},{"id":"https://openalex.org/keywords/ground-truth","display_name":"Ground truth","score":0.6139135360717773},{"id":"https://openalex.org/keywords/session","display_name":"Session (web analytics)","score":0.5349764823913574},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.49280717968940735},{"id":"https://openalex.org/keywords/authentication","display_name":"Authentication (law)","score":0.49105358123779297},{"id":"https://openalex.org/keywords/security-token","display_name":"Security token","score":0.4543253481388092},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.4151153266429901},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.36981433629989624},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.365444540977478},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.35677555203437805}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.842610776424408},{"id":"https://openalex.org/C127705205","wikidata":"https://www.wikidata.org/wiki/Q5748245","display_name":"Heuristics","level":2,"score":0.8168339729309082},{"id":"https://openalex.org/C146849305","wikidata":"https://www.wikidata.org/wiki/Q370766","display_name":"Ground truth","level":2,"score":0.6139135360717773},{"id":"https://openalex.org/C2779182362","wikidata":"https://www.wikidata.org/wiki/Q17126187","display_name":"Session (web analytics)","level":2,"score":0.5349764823913574},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.49280717968940735},{"id":"https://openalex.org/C148417208","wikidata":"https://www.wikidata.org/wiki/Q4825882","display_name":"Authentication (law)","level":2,"score":0.49105358123779297},{"id":"https://openalex.org/C48145219","wikidata":"https://www.wikidata.org/wiki/Q1335365","display_name":"Security token","level":2,"score":0.4543253481388092},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.4151153266429901},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.36981433629989624},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.365444540977478},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.35677555203437805},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0}],"mesh":[],"locations_count":4,"locations":[{"id":"doi:10.1145/2754933","is_oa":false,"landing_page_url":"https://doi.org/10.1145/2754933","pdf_url":null,"source":{"id":"https://openalex.org/S131231701","display_name":"ACM Transactions on the Web","issn_l":"1559-1131","issn":["1559-1131","1559-114X"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on the Web","raw_type":"journal-article"},{"id":"pmh:oai:iris.uniroma1.it:11573/1382659","is_oa":false,"landing_page_url":"http://hdl.handle.net/11573/1382659","pdf_url":null,"source":{"id":"https://openalex.org/S4377196107","display_name":"IRIS Research product catalog (Sapienza University of Rome)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"info:eu-repo/semantics/article"},{"id":"pmh:oai:iris.unive.it:10278/3661257","is_oa":true,"landing_page_url":"http://hdl.handle.net/10278/3661257","pdf_url":null,"source":{"id":"https://openalex.org/S4306402336","display_name":"ARCA (Universit\u00e0 Ca' Foscari Venezia)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I149461666","host_organization_name":"Ca' Foscari University of Venice","host_organization_lineage":["https://openalex.org/I149461666"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"info:eu-repo/semantics/article"},{"id":"pmh:oai:www.research.unipd.it:11577/3262033","is_oa":false,"landing_page_url":"http://hdl.handle.net/11577/3262033","pdf_url":null,"source":{"id":"https://openalex.org/S4377196283","display_name":"Research Padua  Archive (University of Padua)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I138689650","host_organization_name":"University of Padua","host_organization_lineage":["https://openalex.org/I138689650"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"info:eu-repo/semantics/article"}],"best_oa_location":{"id":"pmh:oai:iris.unive.it:10278/3661257","is_oa":true,"landing_page_url":"http://hdl.handle.net/10278/3661257","pdf_url":null,"source":{"id":"https://openalex.org/S4306402336","display_name":"ARCA (Universit\u00e0 Ca' Foscari Venezia)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I149461666","host_organization_name":"Ca' Foscari University of Venice","host_organization_lineage":["https://openalex.org/I149461666"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"info:eu-repo/semantics/article"},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.8199999928474426}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":46,"referenced_works":["https://openalex.org/W39495240","https://openalex.org/W134409196","https://openalex.org/W167016754","https://openalex.org/W170811313","https://openalex.org/W197713628","https://openalex.org/W218853445","https://openalex.org/W219436511","https://openalex.org/W327991062","https://openalex.org/W1224296734","https://openalex.org/W1491243518","https://openalex.org/W1492815834","https://openalex.org/W1500117362","https://openalex.org/W1506285740","https://openalex.org/W1587362683","https://openalex.org/W1605786385","https://openalex.org/W1766594731","https://openalex.org/W1888717584","https://openalex.org/W1941659294","https://openalex.org/W1956559956","https://openalex.org/W1985544318","https://openalex.org/W1985987493","https://openalex.org/W1995875735","https://openalex.org/W1996031526","https://openalex.org/W1996474511","https://openalex.org/W2006235059","https://openalex.org/W2008251338","https://openalex.org/W2035055162","https://openalex.org/W2076118331","https://openalex.org/W2079029214","https://openalex.org/W2093077836","https://openalex.org/W2099474262","https://openalex.org/W2146595241","https://openalex.org/W2148939418","https://openalex.org/W2171920515","https://openalex.org/W2229919479","https://openalex.org/W2300554752","https://openalex.org/W2334028018","https://openalex.org/W2752929869","https://openalex.org/W2911964244","https://openalex.org/W2913153438","https://openalex.org/W2917439412","https://openalex.org/W2985511986","https://openalex.org/W2999549716","https://openalex.org/W3125903163","https://openalex.org/W4254601238","https://openalex.org/W4285719527"],"related_works":["https://openalex.org/W4296749040","https://openalex.org/W4230197055","https://openalex.org/W2280422768","https://openalex.org/W3143197806","https://openalex.org/W621808327","https://openalex.org/W4252555497","https://openalex.org/W644007644","https://openalex.org/W3012257603","https://openalex.org/W3177475962","https://openalex.org/W2137529864"],"abstract_inverted_index":{"Browser-based":[0],"defenses":[1,31,139],"have":[2,67],"recently":[3],"been":[4],"advocated":[5],"as":[6,69],"an":[7],"effective":[8],"mechanism":[9],"to":[10,37,44,57,129,160,181],"protect":[11,46],"potentially":[12],"insecure":[13],"web":[14,132,220],"applications":[15],"against":[16,48,143],"the":[17,58,61,83,103,108,119,141,152,157,200,209,212],"threats":[18],"of":[19,60,75,93,102,122,185,211],"session":[20,42],"hijacking,":[21],"fixation,":[22],"and":[23,155,188],"related":[24],"attacks.":[25],"In":[26,78],"existing":[27,137,197],"approaches,":[28],"all":[29],"such":[30,85],"ultimately":[32],"rely":[33],"on":[34,89,118,171,190,218],"client-side":[35],"heuristics":[36,66,153],"automatically":[38],"detect":[39],"cookies":[40,95],"containing":[41],"information,":[43],"then":[45,164],"them":[47],"theft":[49],"or":[50],"otherwise":[51],"unintended":[52],"use.":[53],"While":[54],"clearly":[55],"crucial":[56],"effectiveness":[59],"resulting":[62,201],"defense":[63],"mechanisms,":[64],"these":[65],"not,":[68],"yet,":[70],"undergone":[71],"any":[72],"rigorous":[73],"assessment":[74],"their":[76],"adequacy.":[77],"this":[79],"article,":[80],"we":[81,96,111,127],"conduct":[82],"first":[84],"formal":[86],"assessment,":[87],"based":[88,170],"a":[90,113,166,183],"ground":[91,109,145,177,213],"truth":[92,178],"2,464":[94],"collect":[97],"from":[98],"215":[99],"popular":[100],"websites":[101],"Alexa":[104],"ranking.":[105],"To":[106],"obtain":[107],"truth,":[110,146,214],"devise":[112],"semiautomatic":[114],"procedure":[115],"that":[116,193],"draws":[117],"novel":[120],"notion":[121],"authentication":[123,133,221],"token":[124],",":[125,174],"which":[126],"introduce":[128],"capture":[130],"multiple":[131],"schemes.":[134],"We":[135,163],"test":[136],"browser-based":[138],"in":[140,151,156,208,225],"literature":[142],"our":[144,176,194,205],"unveiling":[147],"several":[148],"pitfalls":[149],"both":[150],"adopted":[154],"methods":[158],"used":[159,180],"assess":[161],"them.":[162],"propose":[165],"new":[167,216],"detection":[168],"method":[169,195],"supervised":[172],"learning":[173],"where":[175],"is":[179,222],"train":[182],"set":[184],"binary":[186],"classifiers,":[187,202],"report":[189],"experimental":[191],"evidence":[192],"outperforms":[196],"proposals.":[198],"Interestingly,":[199],"together":[203],"with":[204],"hands-on":[206],"experience":[207],"construction":[210],"provide":[215],"insight":[217],"how":[219],"actually":[223],"implemented":[224],"practice.":[226]},"counts_by_year":[{"year":2025,"cited_by_count":4},{"year":2023,"cited_by_count":2},{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":2},{"year":2020,"cited_by_count":5},{"year":2019,"cited_by_count":6},{"year":2018,"cited_by_count":3},{"year":2016,"cited_by_count":3}],"updated_date":"2026-03-20T23:20:44.827607","created_date":"2025-10-10T00:00:00"}
