1 of 37

Introduction

CSE 598 Advanced Security of the Web

Fish Wang

Fall 2026

2 of 37

Classroom Policy

  • You can bring food and drinks and eat while you listen
    • No alcoholic drink
    • Please clean after yourself
  • This is a discussion-heavy course!
  • You can ask questions at any time
    • If I don’t see you raising your hand, call my name
  • No laptops or phones during lectures
    • I will ask you to leave the classroom

​

2

3 of 37

Who am I?

  • Associate Professor at Arizona State University
    • Publish papers on top-tier security venues
    • Build open-source tools (e.g., angr)
    • Enjoy debugging programs and understanding why

​

  • Core member of Shellphish
    • Longest running team at DEF CON CTF

​

  • Member of Nautilus Institute
    • Ran DEF CON CTF from 2022 to 2025

3

4 of 37

What is this course?

  • This course helps you develop a holistic and systematic understanding of web security

​

  • We will dive deep into the world of web than ever!

​

​

  • You are supposed to know a lot about web (in)security
    • Two weeks of this course are enough for you to get familiar (again)

​

4

5 of 37

Communication & Office Hours

  • (We are still setting things up)

​

  • The pwn.college Discord, CSE598-web f2026

​

  • Office Hours
    • Every Friday 1 PM – 2 PM, over Discord voice channel

5

6 of 37

Homework Assignments

  • This course is mainly challenge-based
    • The first module is ready for you hack on!
    • No AI usage allowed except for pwn.college SENSAI
  • In-person written exams
    • Mid-term & Final
  • Attendance
    • I DO NOT take attendance, but you must be in-person to take the exams
  • An optional project (more details after mid-term)
    • Reinventing the web
    • AI usage + agentic programming is a must

6

7 of 37

What is security?

  • Integrity, Confidentiality, and Availability

7

8 of 37

What is web?

  • Web: World Wide Web (WWW)
  • Enables content sharing over the Internet via HTTP

8

9 of 37

9

10 of 37

10

11 of 37

11

12 of 37

12

13 of 37

Sir Tim Berners-Lee

13

14 of 37

Birth of the Web

  • Created by Sir Tim Berners-Lee while he was working at CERN
    • First CERN proposal in 1989
    • Finished first website end of 1990

​

  • Weaving the Web: The Original Design and Ultimate Destiny of the World Wide Web, Tim Berners-Lee

14

15 of 37

What happens when …?

15

16 of 37

Step by step!

16

https://www.google.com

17 of 37

Step by step!

17

Request

Response

GET / HTTP/1.1

Host: www.google.com

HTTP/1.1 200 OK

Content-Length: xx

Processing

DNS Lookup:

www.google.com -> 142.251.151.119

HTTPS (encrypted communication)

18 of 37

What did we miss?

  • URL parsing
  • Sessions & Cookies
  • Proxies
  • CDNs
  • Remote cache
  • Local cache
  • HTML parsing
  • HTML rendering
  • CSS parsing
  • CSS rendering
  • JavaScript parsing
  • JavaScript execution
  • DOM
  • Data downloading
  • Image rendering
  • Browsing history
  • Video playing
  • PDF rendering
  • Certificate checking and verification
  • Source maps
  • Web application frameworks
  • Generative AI
  • …

18

19 of 37

Things that you (rightfully) ignored

  • Browser: Upon start
    • Home page
    • User profile
    • Browser plugins & extensions
    • Multiple processes (main, worker, GPU, renderer)
    • Single-page applications (SPAs)
    • Embedded browsers

19

20 of 37

Things that you (rightfully) ignored

  • Browser: When browsing
    • Authentication
      • User credentials
      • Client-side certificates
      • Hardware-based authentication
    • Encoding & Decoding
    • Domain name, URL, and content filtering
    • Local storage
    • Background queries (as you type, hover, or idle)
    • Prefetches
    • HSTS
    • Web fonts

20

21 of 37

Things that you (rightfully) ignored

  • Traffic: In transit
    • DNS requests and responses between DNS servers
    • DNSSEC
    • CRL & OCSP
    • Middleboxes (routers, firewalls, DPI devices)
    • Routing
    • (Server-side) Load balancers
    • (Server-side) content filtering
    • (Server-side) logging & log processing

21

22 of 37

Things that you (rightfully) ignored

  • Other protocols that are frequently served via web
    • Emails (SMTP, POP3, DKIM, etc.)
    • Many RESTful APIs

​

22

23 of 37

Is that all?

  • The 7 network layers�Physical -> Link -> Network -> Transport -> … -> Application

​

  • The application layer is where HTTP resides

23

24 of 37

Things that you (rightfully) ignored

  • Link layer, network layer, and transport layer
    • TCP connections
    • UDP packets
    • ARP
    • IPv4 & IPv6
  • Display
    • GPU rendering and acceleration
  • Storage
    • Files & file systems
    • Operating system drivers

​

24

25 of 37

Things that you (rightfully) ignored

  • Above the application layer
    • Client-side frameworks
    • Server-side runtime and frameworks
      • Node.js
      • Java Spring
      • .Net
      • Python (Django, Flask, etc.)
      • PHP
      • Go
    • Server-side middleware and supporting software
    • LLM inferencing capabilities

​

25

26 of 37

Step by step (again)!

26

https://www.google.com

27 of 37

Step by step (again)!

27

Request

Response

GET / HTTP/1.1

Host: www.google.com

HTTP/1.1 200 OK

Content-Length: xx

Processing

DNS Lookup:

www.google.com -> 142.251.151.119

HTTPS (encrypted communication)

28 of 37

Insanity…

  • “Wow, I never knew web was so complex!”
  • Abstraction & encapsulation
    • … allow users to focus on what they really care about
    • … allow users to ignore what do not matter
  • Anything you ignore may lead to your security problems

28

User: Please create a personal website for me and deploy it. Here is my AWS API key: xxxxxx

Claude: Clauding...

​

(20 minutes later)

Here is the URL for your website: ...

29 of 37

Now let’s think like an attacker

29

30 of 37

The Threat Model of Web Security

  • Integrity
    • “The web page I see should be in the exactly form the developers intended”
    • “The email that I read should be in the exact form the senders intended”
    • “The love letter I sent should reach my bf in the exact form I intended”

30

31 of 37

The Threat Model of Web Security

  • Confidentiality
    • “No one should see what websites I browsed”
    • “No one should know what emails I just sent”
    • “No one should know or track my location”
    • “No one should know when I got home last night”
    • “No one should know what I had for lunch two weeks ago”

31

32 of 37

The Threat Model of Web Security

  • Availability
    • “The browser should pop up within a few seconds when open it”
    • “I should see the web page rendered within a few seconds after I requested it”
    • “I should be able to access this HTTPS site without being downgraded to HTTP”

32

33 of 37

Step by step and think like an attacker!

33

https://www.google.com

34 of 37

Attacker!

34

Request

Response

GET / HTTP/1.1

Host: www.google.com

HTTP/1.1 200 OK

Content-Length: xx

Processing

DNS Lookup:

www.google.com -> 142.251.151.119

HTTPS (encrypted communication)

35 of 37

What is this course?

  • This course helps you develop a holistic and systematic understanding of web security

​

  • We will dive deep into the world of web than ever!
    • … and drill through all abstraction layers
    • … and think like an attacker
  • You are supposed to know a lot about web (in)security
    • Two weeks of this course are enough for you to get familiar (again)

​

35

36 of 37

Recordings

  • Lectures are recorded, but I cannot guarantee their quality
  • I post my recordings online
    • … but you do not have permissions to share or reuse them

36

37 of 37

Questions?

37