首页> 外文会议>Enabling Technologies: Infrastructure for Collaborative Enterprise, 2005. 14th IEEE International Workshops on >An evaluation of Java application containers according to security requirements
【24h】

An evaluation of Java application containers according to security requirements

机译:根据安全要求评估Java应用程序容器

获取原文
获取外文期刊封面目录资料

摘要

Web browsers, Web servers, Java application servers and OSGi frameworks are all instances of Java execution environments that tun more or less untrusted Java applications. In all these environments, Java applications can come from different sources. Consequently, application developers rarely know which other applications exist in the target Java execution environment. This paper investigates the requirements that need to be imposed on such a container from a security point of view and how the requirements have been implemented by different Java application containers. More specifically, we show a general risk analysis considering assets, threats and vulnerabilities of a Java container. This risk analysis exposes generic Java security problems and leads to a set of security requirements. These security requirements are then used to evaluate the security architecture of existing Java containers for Java applications, applets, servlets, OSGi bundles, and Enterprise Java Beans. For comparison, the requirements are also examined for a C++ application.
机译:Web浏览器,Web服务器,Java应用程序服务器和OSGi框架都是Java执行环境的实例,它们或多或少地调整了不受信任的Java应用程序。在所有这些环境中,Java应用程序可以来自不同的来源。因此,应用程序开发人员很少知道目标Java执行环境中还存在哪些其他应用程序。本文从安全的角度研究了对此类容器必须执行的要求,以及不同的Java应用程序容器如何实现这些要求。更具体地说,我们展示了一个综合风险分析,其中考虑了Java容器的资产,威胁和漏洞。此风险分析揭示了通用Java安全问题,并提出了一系列安全要求。然后,这些安全要求用于评估Java应用程序,小程序,Servlet,OSGi捆绑包和Enterprise Java Bean的现有Java容器的安全体系结构。为了进行比较,还检查了C ++应用程序的要求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号