首页> 外文会议>Component-Based Software Engineering >Classification of Component Vulnerabilities in Java Service Oriented Programming (SOP) Platforms
【24h】

Classification of Component Vulnerabilities in Java Service Oriented Programming (SOP) Platforms

机译:Java Service Oriented Programming(SOP)平台中组件漏洞的分类

获取原文
获取原文并翻译 | 示例

摘要

Java-based systems have evolved from stand-alone applications to multi-component to Service Oriented Programming (SOP) platforms. Each step of this evolution makes a set of Java vulnerabilities directly exploitable by malicious code: access to classes in multi-component platforms, and access to object in SOP, is granted to them with often no control. This paper defines two taxonomies that characterize vulnerabilities in Java components: the vulnerability categories, and the goals of the attacks that are based on these vulnerabilities. The 'vulnerability category' taxonomy is based on three application types: stand-alone, class sharing, and SOP. Entries express the absence of proper security features at places they are required to build secure component-based systems. The 'goal' taxonomy is based on the distinction between undue access, which encompasses the traditional integrity and confidentiality security properties, and denial-of-service. It provides a matching between the vulnerability categories and their consequences. The exploitability of each vulnerability is validated through the development of a pair of malicious and vulnerable components. Experiments are conducted in the context of the OSGi Platform. Based on the vulnerability taxonomies, recommendations for writing hardened component code are issued.
机译:基于Java的系统已经从独立应用程序演变为多组件,再到面向服务的编程(SOP)平台。这种演变的每个步骤都使得一系列Java漏洞可以被恶意代码直接利用:对多组件平台中的类的访问以及对SOP中对象的访问,通常是在没有控制的情况下授予它们的。本文定义了两个分类法来表征Java组件中的漏洞:漏洞类别和基于这些漏洞的攻击目标。 “漏洞类别”分类法基于三种应用程序类型:独立,类共享和SOP。条目表示在构建基于组件的安全系统所需的地方缺少适当的安全功能。 “目标”分类法基于不适当的访问(包括传统的完整性和机密性安全属性)与拒绝服务之间的区别。它提供了漏洞类别及其后果之间的匹配。通过开发一对恶意和易受攻击的组件,可以验证每个漏洞的可利用性。实验是在OSGi平台的上下文中进行的。根据漏洞分类法,发布了有关编写强化组件代码的建议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号