{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/117547"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/117547","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"URL location ambiguity","abstract":"Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2024-12-01","abstract_html":"Submission published under a 24 month embargo labeled &#x27;Closed Access&#x27;, the embargo will last until 2024-12-01","abstract_has_math":false,"creators":["Reynolds, Joshua"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"Ph.D.","degree_level":"Dissertation","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Bailey, Michael D","Gunter, Carl","Bates, Adam","Seamons, Kent"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2022,"date_issued":"2022-12","date_published":"2022-12","updated_at":"2026-07-22T22:24:56Z","subjects":["Uniform Resource Locators","Http","Security","Parsing Ambiguity","Network Security","Usable Security"],"languages":["en","eng"],"rights":["©2022 Joshua Reynolds"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/2142/117547","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Bailey, Michael D","Gunter, Carl","Bates, Adam","Seamons, Kent"]},{"key":"dc:creator","label":"Author","values":["Reynolds, Joshua"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2022-12","2022-11-14"]},{"key":"dc:type","label":"Dc Type","values":["text","Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Uniform Resource Locators","Http","Security","Parsing Ambiguity","Network Security","Usable Security"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en","eng"]},{"key":"dc:rights","label":"Dc Rights","values":["©2022 Joshua Reynolds"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://hdl.handle.net/2142/117547"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2024-12-01","The student, Joshua Reynolds, accepted the attached license on 2022-11-10 at 10:47.","The student, Joshua Reynolds, submitted this Dissertation for approval on 2022-11-10 at 10:55.","This Dissertation was approved for publication on 2022-11-14 at 11:42.","DSpace SAF Submission Ingestion Package generated from Vireo submission #18563 on 2023-04-12 at 11:34:51","The Web is a ubiquitous tool for a wide range of stakeholders–all of whom rely on the ability to reliably locate remote resources. Uniform Resource Locators (URLs) guide the tens of trillions of HyperText Transfer Protocol (HTTP) requests in the Internet every day. If URLs are ambiguously understood, then the Web loses the ability to reliably locate resources. Attackers can take advantage of the ambiguity to misdirect both humans and their computers to untrustworthy resources. We show that for both humans and machines, URL complexity causes parsing inconsistencies that undermine security assumptions of HTTP. The processes users use to parse identity from URLs are insufficient to handle complex URLs – leaving Web users vulnerable to misdirection. We identify and categorize nine differences in URL parsing across more than a dozen URL parsers that enable us to engineer “equivocal URLs.” These equivocal URLs can cause false positives in malicious URL classifiers when the classifier’s URL parser is different from the URL parser of the client it is protecting. We measure added URL complexity stemming from the fact that both users and back-end systems share reliance on URLs. We evaluate the feasibility of reducing URL complexity by moving humans away from direct URL interaction."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["URL location ambiguity"]}]}],"canonical_facts":{"dc:contributor":["Bailey, Michael D","Gunter, Carl","Bates, Adam","Seamons, Kent"],"dc:creator":["Reynolds, Joshua"],"dc:date":["2022-12","2022-11-14"],"dc:description":["Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2024-12-01","The student, Joshua Reynolds, accepted the attached license on 2022-11-10 at 10:47.","The student, Joshua Reynolds, submitted this Dissertation for approval on 2022-11-10 at 10:55.","This Dissertation was approved for publication on 2022-11-14 at 11:42.","DSpace SAF Submission Ingestion Package generated from Vireo submission #18563 on 2023-04-12 at 11:34:51","The Web is a ubiquitous tool for a wide range of stakeholders–all of whom rely on the ability to reliably locate remote resources. Uniform Resource Locators (URLs) guide the tens of trillions of HyperText Transfer Protocol (HTTP) requests in the Internet every day. If URLs are ambiguously understood, then the Web loses the ability to reliably locate resources. Attackers can take advantage of the ambiguity to misdirect both humans and their computers to untrustworthy resources. We show that for both humans and machines, URL complexity causes parsing inconsistencies that undermine security assumptions of HTTP. The processes users use to parse identity from URLs are insufficient to handle complex URLs – leaving Web users vulnerable to misdirection. We identify and categorize nine differences in URL parsing across more than a dozen URL parsers that enable us to engineer “equivocal URLs.” These equivocal URLs can cause false positives in malicious URL classifiers when the classifier’s URL parser is different from the URL parser of the client it is protecting. We measure added URL complexity stemming from the fact that both users and back-end systems share reliance on URLs. We evaluate the feasibility of reducing URL complexity by moving humans away from direct URL interaction."],"dc:format":["application/pdf"],"dc:identifier":["https://hdl.handle.net/2142/117547"],"dc:language":["en","eng"],"dc:rights":["©2022 Joshua Reynolds"],"dc:subject":["Uniform Resource Locators","Http","Security","Parsing Ambiguity","Network Security","Usable Security"],"dc:title":["URL location ambiguity"],"dc:type":["text","Thesis"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Ph.D."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:24:56Z"}