首页> 外文会议>IEEE Symposium on Security and Privacy >Java security: from HotJava to Netscape and beyond
【24h】

Java security: from HotJava to Netscape and beyond

机译:Java Security:来自Hotjava到Netscape及以后

获取原文

摘要

The introduction of Java applets has taken the World Wide Web by storm. Information servers can customize the presentation of their content with server-supplied code which executes inside the Web browser. We examine the Java language and both the HotJava and Netscape browsers which support it, and find a significant number of flaws which compromise their security. These flaws arise for several reasons, including implementation errors, unintended interactions between browser features, differences between the Java language and bytecode semantics, and weaknesses in the design of the language and the bytecode format. On a deeper level, these flaws arise because of weaknesses in the design methodology used in creating Java and the browsers. In addition to the flaws, we discuss the underlying tension between the openness desired by Web application writers and the security needs of their users, and we suggest how both might be accommodated.
机译:Java applet的引入已经乘以绕过全球Web。信息服务器可以使用在Web浏览器中执行的服务器提供的代码自定义其内容的演示文稿。我们检查Java语言和支持它的热门景观和Netscape浏览器,并找到大量损害其安全性的缺陷。由于几种原因,这些缺陷包括实现错误,浏览器功能之间的意外交互,Java语言与字节码语义之间的差异,以及语言设计中的缺点和字节码格式。在更深层面上,由于创建Java和浏览器的设计方法中的弱点,这些缺点会产生。除了缺陷外,我们还讨论了Web应用程序作者所需的开放性与用户的安全需求之间的潜在张力,我们建议如何容纳两者。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号