Java security: from HotJava to Netscape and beyond

Java security: from HotJava to Netscape and beyond
复制标题

Java 安全性:从 HotJava 到 Netscape 及其他

DOI:
--
复制
发表时间:
1996
期刊:
Proceedings 1996 IEEE Symposium on Security and Privacy
影响因子:
--
通讯作者:
D. Wallach
D. Wallach
中科院分区:
--
文献类型:
--
作者:
Drew Dean;E. Felten;D. Wallach

文献摘要

被引文献

相似文献

Java小程序的引入在万维网上掀起了一场风暴。信息服务器可以使用服务器提供的在Web浏览器内执行的代码来定制其内容的表示。我们研究了Java语言和支持它的HotJava和Netscape浏览器,并发现了大量的缺陷,危及其安全性。这些缺陷的出现有几个原因,包括实现错误,浏览器功能之间的意外交互,Java语言和字节码语义之间的差异,以及语言设计和字节码格式的弱点。在更深的层次上,这些缺陷的出现是因为创建Java和浏览器时使用的设计方法的弱点。除了这些缺陷之外,我们还讨论了Web应用程序编写者所期望的开放性与用户的安全需求之间的潜在紧张关系,并提出了如何兼顾这两个方面的建议。
The introduction of Java applets has taken the World Wide Web by storm. Information servers can customize the presentation of their content with server-supplied code which executes inside the Web browser. We examine the Java language and both the HotJava and Netscape browsers which support it, and find a significant number of flaws which compromise their security. These flaws arise for several reasons, including implementation errors, unintended interactions between browser features, differences between the Java language and bytecode semantics, and weaknesses in the design of the language and the bytecode format. On a deeper level, these flaws arise because of weaknesses in the design methodology used in creating Java and the browsers. In addition to the flaws, we discuss the underlying tension between the openness desired by Web application writers and the security needs of their users, and we suggest how both might be accommodated.