
Ben Stock
Person information
- affiliation: CISPA, Saarbrücken, Germany
- affiliation: Saarland University, Saarbrücken, Germany
Refine list

refinements active!
zoomed in on ?? of ?? records
view refined list in
export refined list as
2020 – today
- 2020
- [c25]Sebastian Roth, Michael Backes, Ben Stock:
Assessing the Impact of Script Gadgets on CSP at Scale. AsiaCCS 2020: 420-431 - [c24]Marius Steffens, Ben Stock:
PMForce: Systematically Analyzing postMessage Handlers at Scale. CCS 2020: 493-505 - [c23]Stefano Calzavara
, Ben Stock:
SecWeb 2020 Preface. EuroS&P Workshops 2020: 645 - [c22]Sebastian Roth, Timothy Barron, Stefano Calzavara, Nick Nikiforakis, Ben Stock:
Complex Security Policy? A Longitudinal Analysis of Deployed Content Security Policies. NDSS 2020 - [c21]Stefano Calzavara, Sebastian Roth, Alvise Rabitti, Michael Backes, Ben Stock:
A Tale of Two Headers: A Formal Analysis of Inconsistent Click-Jacking Protection on the Web. USENIX Security Symposium 2020: 683-697
2010 – 2019
- 2019
- [c20]Aurore Fass, Michael Backes, Ben Stock:
JStap: a static pre-filter for malicious JavaScript detection. ACSAC 2019: 257-269 - [c19]Marius Musch, Marius Steffens, Sebastian Roth, Ben Stock, Martin Johns:
ScriptProtect: Mitigating Unsafe Third-Party JavaScript Practices. AsiaCCS 2019: 391-402 - [c18]Aurore Fass, Michael Backes, Ben Stock:
HideNoSeek: Camouflaging Malicious JavaScript in Benign ASTs. CCS 2019: 1899-1913 - [c17]Marius Steffens, Christian Rossow, Martin Johns, Ben Stock:
Don't Trust The Locals: Investigating the Prevalence of Persistent Client-Side Cross-Site Scripting in the Wild. NDSS 2019 - 2018
- [c16]Aurore Fass, Robert P. Krawczyk, Michael Backes, Ben Stock:
JaSt: Fully Syntactic Detection of Malicious (Obfuscated) JavaScript. DIMVA 2018: 303-325 - [c15]Ben Stock, Giancarlo Pellegrino, Frank Li, Michael Backes, Christian Rossow:
Didn't You Hear Me? - Towards More Successful Web Vulnerability Notifications. NDSS 2018 - 2017
- [c14]Michael Backes, Konrad Rieck, Malte Skoruppa, Ben Stock, Fabian Yamaguchi:
Efficient and Flexible Discovery of PHP Application Vulnerabilities. EuroS&P 2017: 334-349 - [c13]Ben Stock, Martin Johns, Marius Steffens, Michael Backes:
How the Web Tangled Itself: Uncovering the History of Client-Side Web (In)Security. USENIX Security Symposium 2017: 971-987 - 2016
- [j1]Ben Stock, Martin Johns:
Client-Side XSS in Theorie und Praxis. Datenschutz und Datensicherheit 40(11): 707-712 (2016) - [c12]Ben Stock, Giancarlo Pellegrino, Christian Rossow, Martin Johns, Michael Backes:
POSTER: Mapping the Landscape of Large-Scale Vulnerability Notifications. CCS 2016: 1787-1789 - [c11]Ben Stock, Benjamin Livshits, Benjamin G. Zorn:
Kizzle: A Signature Compiler for Detecting Exploit Kits. DSN 2016: 455-466 - [c10]Michael Backes, Thorsten Holz, Christian Rossow, Teemu Rytilahti, Milivoj Simeonovski, Ben Stock:
On the Feasibility of TTL-Based Filtering for DRDoS Mitigation. RAID 2016: 303-322 - [c9]Ben Stock, Giancarlo Pellegrino, Christian Rossow, Martin Johns, Michael Backes:
Hey, You Have a Problem: On the Feasibility of Large-Scale Web Vulnerability Notification. USENIX Security Symposium 2016: 1015-1032 - 2015
- [b1]Benjamin Stock:
Untangling the Web of Client-Side Cross-Site Scripting. University of Erlangen-Nuremberg, 2015 - [c8]Ben Stock, Stephan Pfistner, Bernd Kaiser, Sebastian Lekies, Martin Johns:
From Facepalm to Brain Bender: Exploring Client-Side Cross-Site Scripting. CCS 2015: 1419-1430 - [c7]Sebastian Lekies, Ben Stock, Martin Wentzel, Martin Johns:
The Unexpected Dangers of Dynamic JavaScript. USENIX Security Symposium 2015: 723-735 - 2014
- [c6]Ben Stock, Martin Johns:
Protecting users against XSS-based password manager abuse. AsiaCCS 2014: 183-194 - [c5]Ben Stock, Sebastian Lekies, Martin Johns:
DOM-basiertes Cross-Site Scripting im Web: Reise in ein unerforschtes Land. Sicherheit 2014: 53-64 - [c4]Ben Stock, Sebastian Lekies, Tobias Mueller, Patrick Spiegel, Martin Johns:
Precise Client-side Protection against DOM-based Cross-Site Scripting. USENIX Security Symposium 2014: 655-670 - 2013
- [c3]Sebastian Lekies, Ben Stock, Martin Johns:
25 million flows later: large-scale detection of DOM-based XSS. CCS 2013: 1193-1204 - [c2]Martin Johns, Sebastian Lekies, Ben Stock:
Eradicating DNS Rebinding with the Extended Same-origin Policy. USENIX Security Symposium 2013: 621-636 - 2011
- [c1]Zinaida Benenson, Andreas Dewald, Hans-Georg Eßer, Felix C. Freiling, Tilo Müller, Christian Moch, Stefan Vömel, Sebastian Schinzel, Michael Spreitzenbarth, Ben Stock, Johannes Stüttgen:
Exploring the Landscape of Cybercrime. SysSec@DIMVA 2011: 71-74
Coauthor Index

manage site settings
To protect your privacy, all features that rely on external API calls from your browser are turned off by default. You need to opt-in for them to become active. All settings here will be stored as cookies with your web browser. For more information see our F.A.Q.
Unpaywalled article links
Add open access links from to the list of external document links (if available).
Privacy notice: By enabling the option above, your browser will contact the API of unpaywall.org to load hyperlinks to open access articles. Although we do not have any reason to believe that your call will be tracked, we do not have any control over how the remote server uses your data. So please proceed with care and consider checking the Unpaywall privacy policy.
Archived links via Wayback Machine
For web page which are no longer available, try to retrieve content from the of the Internet Archive (if available).
load content from web.archive.org
Privacy notice: By enabling the option above, your browser will contact the API of web.archive.org to check for archived content of web pages that are no longer available. Although we do not have any reason to believe that your call will be tracked, we do not have any control over how the remote server uses your data. So please proceed with care and consider checking the Internet Archive privacy policy.
Reference lists
Add a list of references from ,
, and
to record detail pages.
load references from crossref.org and opencitations.net
Privacy notice: By enabling the option above, your browser will contact the APIs of crossref.org, opencitations.net, and semanticscholar.org to load article reference information. Although we do not have any reason to believe that your call will be tracked, we do not have any control over how the remote server uses your data. So please proceed with care and consider checking the Crossref privacy policy and the OpenCitations privacy policy, as well as the AI2 Privacy Policy covering Semantic Scholar.
Citation data
Add a list of citing articles from and
to record detail pages.
load citations from opencitations.net
Privacy notice: By enabling the option above, your browser will contact the API of opencitations.net and semanticscholar.org to load citation information. Although we do not have any reason to believe that your call will be tracked, we do not have any control over how the remote server uses your data. So please proceed with care and consider checking the OpenCitations privacy policy as well as the AI2 Privacy Policy covering Semantic Scholar.
Tweets on dblp homepage
Show tweets from on the dblp homepage.
Privacy notice: By enabling the option above, your browser will contact twitter.com and twimg.com to load tweets curated by our Twitter account. At the same time, Twitter will persistently store several cookies with your web browser. While we did signal Twitter to not track our users by setting the "dnt" flag, we do not have any control over how Twitter uses your data. So please proceed with care and consider checking the Twitter privacy policy.
last updated on 2021-01-14 21:31 CET by the dblp team
all metadata released as open data under CC0 1.0 license
see also: Terms of Use | Privacy Policy | Imprint