Empreu aquest identificador per citar o enllaçar aquest ítem: http://hdl.handle.net/10609/93050
Títol: Model-based analysis of Java EE web security misconfigurations
Autoria: Martínez Pérez, Salvador
Cosentino, Valerio
Cabot, Jordi  
Altres: AtlanMod
Universitat Oberta de Catalunya (UOC)
Citació: Martínez Pérez, S., Cosentino, V. & Cabot Sagrera, J. (2017). Model-based analysis of Java EE web security misconfigurations. Computer Languages, Systems and Structures, 49(), 36-61. doi: 10.1016/j.cl.2017.02.001
Resum: The Java EE framework, a popular technology of choice for the development of web applications, provides developers with the means to define access-control policies to protect application resources from unauthorized disclosures and manipulations. Unfortunately, the definition and manipulation of such security policies remains a complex and error prone task, requiring expert-level knowledge on the syntax and semantics of the Java EE access-control mechanisms. Thus, misconfigurations that may lead to unintentional security and/or availability problems can be easily introduced. In response to this problem, we present a (model-based) reverse engineering approach that automatically evaluates a set of security properties on reverse engineered Java EE security configurations, helping to detect the presence of anomalies. We evaluate the efficacy and pertinence of our approach by applying our prototype tool on a sample of real Java EE applications extracted from GitHub.
Paraules clau: enginyeria dirigida per models
seguretat
enginyeria inversa
DOI: 10.1016/j.cl.2017.02.001
Tipus de document: info:eu-repo/semantics/article
Versió del document: info:eu-repo/semantics/submittedVersion
Data de publicació: 1-set-2017
Llicència de publicació: http://creativecommons.org/licenses/by-nc-nd/3.0/es/  
Apareix a les col·leccions:Articles cientÍfics
Articles

Arxius per aquest ítem:
Arxiu Descripció MidaFormat 
javaEE.pdfPreprint440,09 kBAdobe PDFThumbnail
Veure/Obrir
Comparteix:
Exporta:
Consulta les estadístiques

Els ítems del Repositori es troben protegits per copyright, amb tots els drets reservats, sempre i quan no s’indiqui el contrari.