An In-Depth Study of More Than Ten Years of Java']Java Exploitation

被引:20
|
作者
Holzinger, Philipp [1 ]
Triller, Stefan [1 ]
Bartel, Alexandre [2 ]
Bodden, Eric [3 ,4 ]
机构
[1] Fraunhofer SIT, Darmstadt, Germany
[2] Tech Univ Darmstadt, Darmstadt, Germany
[3] Univ Paderborn, Paderborn, Germany
[4] Fraunhofer IEM, Paderborn, Germany
来源
CCS'16: PROCEEDINGS OF THE 2016 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY | 2016年
关键词
D O I
10.1145/2976749.2978361
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
When created, the Java platform was among the first runtimes designed with security in mind. Yet, numerous Java versions were shown to contain far-reaching vulnerabilities, permitting denial-of-service attacks or even worse allowing intruders to bypass the runtime's sandbox mechanisms, opening the host system up to many kinds of further attacks. This paper presents a systematic in-depth study of 87 publicly available Java exploits found in the wild. By collecting, minimizing and categorizing those exploits, we identify their commonalities and root causes, with the goal of determining the weak spots in the Java security architecture and possible countermeasures. Our findings reveal that the exploits heavily rely on a set of nine weaknesses, including unauthorized use of restricted classes and confused deputies in combination with caller-sensitive methods. We further show that all attack vectors implemented by the exploits belong to one of three categories: single-step attacks, restricted-class attacks, and information hiding attacks. The analysis allows us to propose ideas for improving the security architecture to spawn further research in this area.
引用
收藏
页码:779 / 790
页数:12
相关论文
共 50 条
  • [41] More than ten years of Lusi: A review of facts, coincidences, and past and future studies
    Miller, Stephen A.
    Mazzini, Adriano
    MARINE AND PETROLEUM GEOLOGY, 2018, 90 : 10 - 25
  • [42] Europeanisation of Turkish Foreign Policy after more than Ten Years of EU Candidacy
    Terzi, Ozlem
    TURKEY AND THE EUROPEAN UNION: PROCESSES OF EUROPEANISATION, 2012, : 205 - 224
  • [43] After more than ten years of effort, are remedial action plans making a difference?
    Krantzberg, G
    JOURNAL OF GREAT LAKES RESEARCH, 1998, 24 (03) : 485 - 486
  • [44] PROGNOSTIC FACTORS FOR BIOCHEMICAL RECURRENCE MORE THAN TEN YEARS AFTER RADICAL PROSTATECTOMY
    Herkommer, Kathleen
    Liesenfeld, Lea A.
    Kron, Martina
    Gschwend, Juergen E.
    JOURNAL OF UROLOGY, 2016, 195 (04): : E716 - E716
  • [45] Neuropathic pain in people treated for multibacillary leprosy more than ten years previously
    Saunderson, Paul
    Bizuneh, Elizabeth
    Leekassa, Ruth
    LEPROSY REVIEW, 2008, 79 (03) : 270 - 276
  • [46] Overwhelming pneumoccoccal sepsis in two patients splenectomised more than ten years previously
    Hassan, ISA
    Snow, MH
    Ong, ELC
    SCOTTISH MEDICAL JOURNAL, 1996, 41 (01) : 17 - 19
  • [47] More than ten million years of hyper-aridity recorded in the Atacama Gravels
    Sun, Tao
    Bao, Huiming
    Reich, Martin
    Hemming, Sidney R.
    GEOCHIMICA ET COSMOCHIMICA ACTA, 2018, 227 : 123 - 132
  • [48] MORE THAN 1000 YEARS OF MINING EXPLOITATION IN THE SIERRA DE FAMATINA LA RIOJA, ARGENTINA
    Callegari, Adriana B.
    Jacob, Cristian
    REVISTA DE ARQUEOLOGIA HISTORICA ARGENTINA Y LATINOAMERICANA, 2012, 6 : 157 - 181
  • [49] STUDY OF A 4,000 YEARS POLLEN RECORD IN THE AMBARAWA BASIN (CENTRAL-JAVA']JAVA, INDONESIA) - EVIDENCE OF OLDER GRUBBING PERIODS
    SEMAH, AM
    SEMAH, F
    GUILLOT, C
    DJUBIANTONO, T
    FOURNIER, M
    COMPTES RENDUS DE L ACADEMIE DES SCIENCES SERIE II, 1992, 315 (07): : 903 - 908
  • [50] ENGINEERS NEED MORE THAN 4 YEARS OF STUDY
    VIDAL, MA
    CIVIL ENGINEERING, 1994, 64 (12): : 32 - 32