An In-Depth Study of More Than Ten Years of Java']Java Exploitation

被引:20
|
作者
Holzinger, Philipp [1 ]
Triller, Stefan [1 ]
Bartel, Alexandre [2 ]
Bodden, Eric [3 ,4 ]
机构
[1] Fraunhofer SIT, Darmstadt, Germany
[2] Tech Univ Darmstadt, Darmstadt, Germany
[3] Univ Paderborn, Paderborn, Germany
[4] Fraunhofer IEM, Paderborn, Germany
来源
CCS'16: PROCEEDINGS OF THE 2016 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY | 2016年
关键词
D O I
10.1145/2976749.2978361
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
When created, the Java platform was among the first runtimes designed with security in mind. Yet, numerous Java versions were shown to contain far-reaching vulnerabilities, permitting denial-of-service attacks or even worse allowing intruders to bypass the runtime's sandbox mechanisms, opening the host system up to many kinds of further attacks. This paper presents a systematic in-depth study of 87 publicly available Java exploits found in the wild. By collecting, minimizing and categorizing those exploits, we identify their commonalities and root causes, with the goal of determining the weak spots in the Java security architecture and possible countermeasures. Our findings reveal that the exploits heavily rely on a set of nine weaknesses, including unauthorized use of restricted classes and confused deputies in combination with caller-sensitive methods. We further show that all attack vectors implemented by the exploits belong to one of three categories: single-step attacks, restricted-class attacks, and information hiding attacks. The analysis allows us to propose ideas for improving the security architecture to spawn further research in this area.
引用
收藏
页码:779 / 790
页数:12
相关论文
共 50 条
  • [21] Integration Sentinel-1 SAR data and machine learning for land subsidence in-depth analysis in the North Coast of Central Java']Java, Indonesia
    Yananto, Ardila
    Yulianto, Fajar
    Wibowo, Mardi
    Rahili, Nurkhalis
    Perdana, Dhedy Husada Fadjar
    Wiguna, Edwin Adi
    Prabowo, Yudhi
    Iswari, Marindah Yulia
    Ma'rufatin, Anies
    Fachrudin, Imam
    EARTH SCIENCE INFORMATICS, 2024, 17 (05) : 4707 - 4738
  • [22] Nutritional status and linear growth of Indonesian infants in West Java']Java are determined more by prenatal environment than by postnatal factors
    Schmidt, MK
    Muslimatun, S
    West, CE
    Schultink, W
    Gross, R
    Hautvast, JGAJ
    JOURNAL OF NUTRITION, 2002, 132 (08) : 2202 - 2207
  • [23] Handedness frequency over more than ten thousand years
    Faurie, C
    Raymond, M
    PROCEEDINGS OF THE ROYAL SOCIETY B-BIOLOGICAL SCIENCES, 2004, 271 : S43 - S45
  • [24] An overview of more than ten years of operation of the CMS ECAL
    Zghiche, Amina
    INTERNATIONAL JOURNAL OF MODERN PHYSICS A, 2025, 40 (08):
  • [25] VISUALIZING IMPROVEMENT PROJECTS: MORE THAN TEN YEARS OF EXPERIENCE
    Billiet, E.
    Smet, E.
    QUALITY MANAGEMENT IN HIGHER EDUCATION, PROCEEDINGS, 2008, : 161 - 165
  • [26] The natural history of periodontal disease: The Java']Java study-Origin, implementation, and results 35 years on
    Van der Velden, Ubele
    PERIODONTOLOGY 2000, 2023,
  • [27] Are SNNs Really More Energy-Efficient Than ANNs? an In-Depth Hardware-Aware Study
    Dampfhoffer, Manon
    Mesquida, Thomas
    Valentian, Alexandre
    Anghel, Lorena
    IEEE TRANSACTIONS ON EMERGING TOPICS IN COMPUTATIONAL INTELLIGENCE, 2023, 7 (03): : 731 - 741
  • [28] More than just mud: the importance of wallows to Java']Javan rhino ecology and behaviour
    Wilson, Steven G.
    Hockings, Georgina
    Deretic, Jo-Anne M.
    Kark, Salit
    PACHYDERM, 2019, (61): : 49 - 62
  • [29] Causes of death more than ten years after liver transplantation
    Yang, HJ
    Mahyl, JN
    Khakhar, A
    Alghamdi, M
    Mcgrath, J
    Dale, C
    Levstik, M
    Ghent, CN
    Marotta, P
    Quan, D
    McAlister, V
    Wall, WJ
    LIVER TRANSPLANTATION, 2004, 10 (06) : C34 - C34
  • [30] Can rotation osteotomy remain effective for more than ten years?
    Langlais, F
    Fourastier, J
    Gédouin, JE
    Ropars, M
    Lambotte, JC
    Thomazeau, H
    ORTHOPEDIC CLINICS OF NORTH AMERICA, 2004, 35 (03) : 345 - +