The Community for Technology Leaders
2012 IEEE 21st International Workshop on Enabling Technologies: Infrastructure for Collaborative Enterprises (2005)
Linkoping, Sweden
June 13, 2005 to June 15, 2005
ISSN: 1524-4547
ISBN: 0-7695-2362-5
pp: 178-186
Nahid Shahmehri , Linkoping University, Sweden
Almut Herzog , Linkoping University, Sweden
ABSTRACT
<p>Web browsers, web servers, Java application servers and OSGi frameworks are all instances of Java execution environments that run more or less untrusted Java applications. In all these environments, Java applications can come from different sources. Consequently, application developers rarely know which other applications exist in the target Java execution environment.</p> <p>This paper investigates the requirements that need to be imposed on such a container from a security point of view and how the requirements have been implemented by different Java application containers.</p> <p>More specifically, we show a general risk analysis considering assets, threats and vulnerabilities of a Java container. This risk analysis exposes generic Java security problems and leads to a set of security requirements. These security requirements are then used to evaluate the security architecture of existing Java containers for Java applications, applets, servlets, OSGi bundles, and Enterprise Java Beans. For comparison, the requirements are also examined for a C++ application.</p>
INDEX TERMS
null
CITATION
Nahid Shahmehri, Almut Herzog, "An Evaluation of Java Application Containers according to Security Requirements", 2012 IEEE 21st International Workshop on Enabling Technologies: Infrastructure for Collaborative Enterprises, vol. 00, no. , pp. 178-186, 2005, doi:10.1109/WETICE.2005.18
94 ms
(Ver 3.3 (11022016))