首页> 外文期刊>Journal of Computer Virology and Hacking Techniques >Static vulnerability detection in Java service-oriented components
【24h】

Static vulnerability detection in Java service-oriented components

机译:面向Java服务的组件中的静态漏洞检测

获取原文
获取原文并翻译 | 示例

摘要

Extensible component-based platforms allow dynamic discovery, installation and execution of components. Such platforms are service-oriented, as components may directly interact with each other via the services they provide. Even robust languages such as Java were not designed to handle safe code interaction between trusted and untrusted parties. Dynamic installation of code provided by different third parties leads to several security issues. The different security layers adopted by Java or component-based platforms cannot fully address the problem of untrusted components trying to tamper with other components via legitimate interactions. A malicious component might even use vulnerable ones to compromise the whole component-based platform. Our approach identifies vulnerable components in order to prevent them from threatening services security. We use static analysis to remain as exhaustive as possible and to avoid the need for non-standard or intrusive environments. We show that a static analysis through tainted object propagation is well suited to detect vulnerabilities in Java service-oriented components. We present STOP, a Service-oriented Tainted Object Propagation tool, which applies this technique to statically detect those security flaws. Finally, the audit of several trusted Apache Felix bundles shows that nowadays component-based platforms are not prepared for malicious Java interactions.
机译:基于组件的可扩展平台允许动态发现,安装和执行组件。这样的平台是面向服务的,因为组件可以通过它们提供的服务直接相互交互。甚至健壮的语言(例如Java)也没有设计为处理受信任方和不受信任方之间的安全代码交互。由不同第三方提供的代码的动态安装会导致几个安全问题。 Java或基于组件的平台采用的不同安全层无法完全解决试图通过合法交互来篡改其他组件的不受信任组件的问题。恶意组件甚至可能使用易受攻击的组件来破坏整个基于组件的平台。我们的方法可以识别易受攻击的组件,以防止它们威胁服务安全。我们使用静态分析来保持尽可能详尽,并避免需要非标准或侵入性环境。我们展示了通过受污染对象传播进行的静态分析非常适合检测面向Java服务的组件中的漏洞。我们介绍了STOP,这是一种面向服务的受污染对象传播工具,该工具将此项技术应用于静态检测那些安全漏洞。最后,对几个受信任的Apache Felix捆绑软件的审计表明,如今基于组件的平台尚未为恶意Java交互做好准备。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号