Por favor, use este identificador para citar o enlazar este ítem: http://hdl.handle.net/10609/93050
Registro completo de metadatos
Campo DC Valor Lengua/Idioma
dc.contributor.authorMartínez Pérez, Salvador-
dc.contributor.authorCosentino, Valerio-
dc.contributor.authorCabot, Jordi-
dc.contributor.otherAtlanMod-
dc.contributor.otherUniversitat Oberta de Catalunya (UOC)-
dc.date.accessioned2019-04-11T07:53:56Z-
dc.date.available2019-04-11T07:53:56Z-
dc.date.issued2017-09-01-
dc.identifier.citationMartínez Pérez, S., Cosentino, V. & Cabot Sagrera, J. (2017). Model-based analysis of Java EE web security misconfigurations. Computer Languages, Systems and Structures, 49(), 36-61. doi: 10.1016/j.cl.2017.02.001-
dc.identifier.issn1477-8424MIAR
-
dc.identifier.urihttp://hdl.handle.net/10609/93050-
dc.description.abstractThe Java EE framework, a popular technology of choice for the development of web applications, provides developers with the means to define access-control policies to protect application resources from unauthorized disclosures and manipulations. Unfortunately, the definition and manipulation of such security policies remains a complex and error prone task, requiring expert-level knowledge on the syntax and semantics of the Java EE access-control mechanisms. Thus, misconfigurations that may lead to unintentional security and/or availability problems can be easily introduced. In response to this problem, we present a (model-based) reverse engineering approach that automatically evaluates a set of security properties on reverse engineered Java EE security configurations, helping to detect the presence of anomalies. We evaluate the efficacy and pertinence of our approach by applying our prototype tool on a sample of real Java EE applications extracted from GitHub.en
dc.language.isoeng-
dc.publisherComputer Languages, Systems and Structures-
dc.relation.ispartofComputer Languages, Systems and Structures, 2017, 49()-
dc.relation.urihttps://doi.org/10.1016/j.cl.2017.02.001-
dc.rightsCC BY-NC-ND-
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/3.0/es/-
dc.subjectreverse engineeringen
dc.subjectmodel driven engineeringen
dc.subjectingeniería dirigida por modeloses
dc.subjectenginyeria dirigida per modelsca
dc.subjectsecurityen
dc.subjectseguridades
dc.subjectseguretatca
dc.subjectingeniería inversaes
dc.subjectenginyeria inversaca
dc.subject.lcshWeb applicationsen
dc.titleModel-based analysis of Java EE web security misconfigurations-
dc.typeinfo:eu-repo/semantics/article-
dc.subject.lemacAplicacions webca
dc.subject.lcshesAplicaciones webes
dc.rights.accessRightsinfo:eu-repo/semantics/openAccess-
dc.identifier.doi10.1016/j.cl.2017.02.001-
dc.gir.idAR/0000005525-
dc.type.versioninfo:eu-repo/semantics/submittedVersion-
Aparece en las colecciones: Articles cientÍfics
Articles

Ficheros en este ítem:
Fichero Descripción Tamaño Formato  
javaEE.pdfPreprint440,09 kBAdobe PDFVista previa
Visualizar/Abrir
Comparte:
Exporta:
Consulta las estadísticas

Los ítems del Repositorio están protegidos por copyright, con todos los derechos reservados, a menos que se indique lo contrario.