Model-based Analysis of Java EE Web Security Configurations - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Communication Dans Un Congrès Année : 2016

Model-based Analysis of Java EE Web Security Configurations

Résumé

The widespread use of Java EE web applications as a means to provide distributed services to remote clients imposes strong security requirements, so that the resources managed by these applications remain protected from unauthorized disclosures and manipulations. For this purpose, the Java EE framework provides developers with mechanisms to define access-control policies. Unfortunately , the variety and complexity of the provided security configuration mechanisms cause the definition and manipulation of a security policy to be complex and error prone. As security requirements are not static, and thus, implemented policies must be changed and reviewed often, discovering and representing the policy at an appropriate abstraction level to enable their understanding and reenginering appears as a critical requirement. To tackle this problem, this paper presents a (model-based) approach aimed to help security experts to visualize, (automatically) analyse and manipulate web security policies.
Fichier principal
Vignette du fichier
Mise2016-ModelBasedWebSecurityAnalysis.pdf (349.28 Ko) Télécharger le fichier
Loading...

Dates et versions

hal-02868060 , version 1 (15-06-2020)

Identifiants

Citer

Salvador Martínez, Valerio Cosentino, Jordi Cabot. Model-based Analysis of Java EE Web Security Configurations. 2016 IEEE/ACM 8th International Workshop on Modeling in Software Engineering (MiSE), May 2016, Austin, Texas, United States. ⟨10.1145/2896982.2896986⟩. ⟨hal-02868060⟩
31 Consultations
113 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More