...
首页> 外文期刊>Computer Languages, Systems & Structures >Model-based analysis of Java EE web security misconfigurations
【24h】

Model-based analysis of Java EE web security misconfigurations

机译:基于模型的Java EE Web安全配置错误分析

获取原文
获取原文并翻译 | 示例
           

摘要

The Java EE framework, a popular technology of choice for the development of web applications, provides developers with the means to define access-control policies to protect application resources from unauthorized disclosures and manipulations. Unfortunately, the definition and manipulation of such security policies remains a complex and error prone task, requiring expert-level knowledge on the syntax and semantics of the Java EE access-control mechanisms. Thus, misconfigurations that may lead to unintentional security and/or availability problems can be easily introduced. In response to this problem, we Present a (model-based) reverse engineering approach that automatically evaluates a set of security properties on reverse engineered Java EE security configurations, helping to detect the presence of anomalies. We evaluate the efficacy and pertinence of our approach by applying our prototype tool on a sample of real Java EE applications extracted from GitHub. (C) 2017 Elsevier Ltd. All rights reserved.
机译:Java EE框架是Web应用程序开发的一种流行的选择技术,它为开发人员提供了定义访问控制策略的方法,以保护应用程序资源免遭未经授权的披露和操纵。不幸的是,此类安全策略的定义和操作仍然是一项复杂且容易出错的任务,需要有关Java EE访问控制机制的语法和语义的专家级知识。因此,可以容易地引入可能导致意外的安全性和/或可用性问题的错误配置。针对此问题,我们提出了一种(基于模型的)逆向工程方法,该方法可以自动评估逆向工程Java EE安全配置上的一组安全属性,从而帮助检测异常的存在。通过将原型工具应用于从GitHub提取的真实Java EE应用程序样本中,我们评估了该方法的有效性和相关性。 (C)2017 Elsevier Ltd.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号