论文标题

企业应用程序春季安全的编码实践和建议

Coding Practices and Recommendations of Spring Security for Enterprise Applications

论文作者

Islam, Mazharul, Rahaman, Sazzadur, Meng, Na, Hassanshahi, Behnaz, Krishnan, Padmanabhan, Danfeng, Yao

论文摘要

春季安全性在从业人员中很受欢迎,因为它易于使用企业应用程序。在本文中,我们根据春季安全性研究了应用框架错误配置的漏洞,这在现有文献中相对研究。为了实现这一目标,我们通过对28个春季应用程序进行基于测量的方法来确定6种类型的安全反版社和4种不安全的弱势违约方法。我们的分析表明,与已识别的安全反版社和不安全默认值相关的安全风险可能会使企业应用程序容易受到广泛的高风险攻击的影响。为了防止这些高风险攻击,我们还为从业者提供了建议。因此,我们的研究对官方的春季安全文件贡献了一项更新,而本研究中确定的其他安全问题正在由春季安全社区考虑未来的主要版本。

Spring security is tremendously popular among practitioners for its ease of use to secure enterprise applications. In this paper, we study the application framework misconfiguration vulnerabilities in the light of Spring security, which is relatively understudied in the existing literature. Towards that goal, we identify 6 types of security anti-patterns and 4 insecure vulnerable defaults by conducting a measurement-based approach on 28 Spring applications. Our analysis shows that security risks associated with the identified security anti-patterns and insecure defaults can leave the enterprise application vulnerable to a wide range of high-risk attacks. To prevent these high-risk attacks, we also provide recommendations for practitioners. Consequently, our study has contributed one update to the official Spring security documentation while other security issues identified in this study are being considered for future major releases by Spring security community.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源