| 2026 | SP | LEAKYLINKS: Measuring the Security and Privacy Risks of URL Scanning Services. | Ali Mustafa, Jannis Rautenstrauch, Florian Hantke, Shubham Agarwal, Stefano Calzavara, Ben Stock |
| 2025 | AsiaCCS | Open Access Alert: Studying the Privacy Risks in Android WebView's Web Permission Enforcement. | Trung Tin Nguyen, Ben Stock |
| 2025 | CCS | Head(er)s Up! Detecting Security Header Inconsistencies in Browsers. | Jannis Rautenstrauch, Trung Tin Nguyen, Karthik Ramakrishnan, Ben Stock |
| 2025 | IMC | A Permissions Odyssey: A Systematic Study of Browser Permissions on Modern Websites. | Alberto Fernndez de Retana, Jannis Rautenstrauch, Igor Santos-Grueiro, Ben Stock |
| 2025 | NDSS | The (Un)usual Suspects - Studying Reasons for Lacking Updates in WordPress. | Maria Hellenthal, Lena Gotsche, Rafael Mrowczynski, Sarah Kugel, Michael Schilling, Ben Stock |
| 2025 | SP | 403 Forbidden? Ethically Evaluating Broken Access Control in the Wild. | Saiid El Hajj Chehade, Florian Hantke, Ben Stock |
| 2024 | AsiaCCS | Who's Breaking the Rules? Studying Conformance to the HTTP Specifications and its Security Impact. | Jannis Rautenstrauch, Ben Stock |
| 2024 | CCS | Peeking through the window: Fingerprinting Browser Extensions through Page-Visible Execution Traces and Interactions. | Shubham Agarwal, Aurore Fass, Ben Stock |
| 2024 | SP | Where Are the Red Lines? Towards Ethical Server-Side Scans in Security and Privacy Research. | Florian Hantke, Sebastian Roth, Rafael Mrowczynski, Christine Utz, Ben Stock |
| 2024 | SP | To Auth or Not To Auth? A Comparative Analysis of the Pre- and Post-Login Security Landscape. | Jannis Rautenstrauch, Metodi Mitkov, Thomas Helbrecht, Lorenz Hetterich, Ben Stock |
| 2023 | CCS | You Call This Archaeology? Evaluating Web Archives for Reproducible Web Security Measurements. | Florian Hantke, Stefano Calzavara, Moritz Wilhelm, Alvise Rabitti, Ben Stock |
| 2023 | NDSS | DiffCSP: Finding Browser Bugs in Content Security Policy Enforcement through Differential Testing. | Seongil Wi, Trung Tin Nguyen, Jihwan Kim, Ben Stock, Sooel Son |
| 2023 | RAID | Honey, I Cached our Security Tokens Re-usage of Security Tokens in the Wild. | Leon Trampert, Ben Stock, Sebastian Roth |
| 2023 | SP | The Leaky Web: Automated Discovery of Cross-Site Information Leaks in Browsers and the Web. | Jannis Rautenstrauch, Giancarlo Pellegrino, Ben Stock |
| 2022 | CCS | Freely Given Consent?: Studying Consent Notice of Third-Party Tracking and Its Violations of GDPR in Android Apps. | Trung Tin Nguyen, Michael Backes, Ben Stock |
| 2022 | IMC | HTML violations and where to find them: a longitudinal analysis of specification violations in HTML. | Florian Hantke, Ben Stock |
| 2022 | SP | To hash or not to hash: A security assessment of CSP's unsafe-hashes expression. | Peter Stolz, Sebastian Roth, Ben Stock |
| 2021 | AsiaCCS | Careful Who You Trust: Studying the Pitfalls of Cross-Origin Communication. | Gordon Meiser, Pierre Laperdrix, Ben Stock |
| 2021 | CCS | DoubleX: Statically Detecting Vulnerable Data Flows in Browser Extensions at Scale. | Aurore Fass, Dolire Francis Som, Michael Backes, Ben Stock |
| 2021 | CCS | 12 Angry Developers - A Qualitative Study on Developers' Struggles with CSP. | Sebastian Roth, Lea Grber, Michael Backes, Katharina Krombholz, Ben Stock |
| 2021 | NDSS | Reining in the Web's Inconsistencies with Site Policy. | Stefano Calzavara, Tobias Urban, Dennis Tatang, Marius Steffens, Ben Stock |
| 2021 | NDSS | Who's Hosting the Block Party? Studying Third-Party Blockage of CSP and SRI. | Marius Steffens, Marius Musch, Martin Johns, Ben Stock |
| 2020 | CCS | Assessing the Impact of Script Gadgets on CSP at Scale. | Sebastian Roth, Michael Backes, Ben Stock |
| 2020 | CCS | PMForce: Systematically Analyzing postMessage Handlers at Scale. | Marius Steffens, Ben Stock |
| 2020 | NDSS | Complex Security Policy? A Longitudinal Analysis of Deployed Content Security Policies. | Sebastian Roth, Timothy Barron, Stefano Calzavara, Nick Nikiforakis, Ben Stock |
| 2019 | ACSAC | JStap: a static pre-filter for malicious JavaScript detection. | Aurore Fass, Michael Backes, Ben Stock |
| 2019 | CCS | HideNoSeek: Camouflaging Malicious JavaScript in Benign ASTs. | Aurore Fass, Michael Backes, Ben Stock |
| 2019 | CCS | ScriptProtect: Mitigating Unsafe Third-Party JavaScript Practices. | Marius Musch, Marius Steffens, Sebastian Roth, Ben Stock, Martin Johns |
| 2019 | NDSS | Don't Trust The Locals: Investigating the Prevalence of Persistent Client-Side Cross-Site Scripting in the Wild. | Marius Steffens, Christian Rossow, Martin Johns, Ben Stock |
| 2018 | DIMVA | JaSt: Fully Syntactic Detection of Malicious (Obfuscated) JavaScript. | Aurore Fass, Robert P. Krawczyk, Michael Backes, Ben Stock |
| 2018 | NDSS | Didn't You Hear Me? - Towards More Successful Web Vulnerability Notifications. | Ben Stock, Giancarlo Pellegrino, Frank Li, Michael Backes, Christian Rossow |
| 2016 | CCS | POSTER: Mapping the Landscape of Large-Scale Vulnerability Notifications. | Ben Stock, Giancarlo Pellegrino, Christian Rossow, Martin Johns, Michael Backes |
| 2016 | DSN | Kizzle: A Signature Compiler for Detecting Exploit Kits. | Ben Stock, Benjamin Livshits, Benjamin G. Zorn |
| 2016 | RAID | On the Feasibility of TTL-Based Filtering for DRDoS Mitigation. | Michael Backes, Thorsten Holz, Christian Rossow, Teemu Rytilahti, Milivoj Simeonovski, Ben Stock |
| 2015 | CCS | From Facepalm to Brain Bender: Exploring Client-Side Cross-Site Scripting. | Ben Stock, Stephan Pfistner, Bernd Kaiser, Sebastian Lekies, Martin Johns |
| 2014 | CCS | Protecting users against XSS-based password manager abuse. | Ben Stock, Martin Johns |
| 2013 | CCS | 25 million flows later: large-scale detection of DOM-based XSS. | Sebastian Lekies, Ben Stock, Martin Johns |
| 2011 | DIMVA | Exploring the Landscape of Cybercrime. | Zinaida Benenson, Andreas Dewald, Hans-Georg Eer, Felix C. Freiling, Tilo Mller, Christian Moch, Stefan Vmel, Sebastian Schinzel, Michael Spreitzenbarth, Ben Stock, Johannes Stttgen |