首页> 外文会议>IEEE International IOT, Electronics and Mechatronics Conference >Mitigating Remote Code Execution Vulnerabilities: A Study on Tomcat and Android Security Updates
【24h】

Mitigating Remote Code Execution Vulnerabilities: A Study on Tomcat and Android Security Updates

机译:缓解远程执行代码执行漏洞:Tomcat和Android安全更新的研究

获取原文

摘要

The security of web-applications has become increasingly important in recent years as their popularity has grown exponentially. More and more web-based enterprise applications deal with sensitive personal and private information, which, if compromised, can not only lead to system downtime, but can also cause mean millions of dollars in damages to the organization. It is critical to protect web-applications from the constant onslaught of hacker attacks. Remote Code Execution (RCE) attacks are one of the most prominent security threats for software systems, especially Java-based systems. In the current study, we have studied the security update reports for RCE vulnerabilities published by two Java-based projects: Apache Tomcat and Android. We analyzed and categorized the code-fixes (i.e., patches/updates) that were applied to mitigate/fix fifty-one (51) RCE vulnerabilities in the two above-mentioned Java projects. Our analysis showed that a significant majority of the RCE vulnerabilities found in Java projects can be mitigated with just five (5) types/categories of code-fixes. Overall, our goal was to study RCE vulnerabilities in an effort to provide programmers with a handy list of code-fixes, thus making it easier for them to effectively mitigate known RCE vulnerabilities in their own Java-based applications.
机译:近年来,网络应用的安全性越来越重要,因为他们的受欢迎程度是指数增长的。越来越多的基于Web的企业应用程序处理敏感的个人和私人信息,如果受到损害,不仅可以导致系统停机,但也可能导致数百万美元对本组织的损害赔偿。保护Web应用程序免受黑客攻击的恒定攻击。远程代码执行(RCE)攻击是软件系统最突出的安全威胁之一,尤其是基于Java的系统。在目前的研究中,我们研究了由两个基于Java的项目发布的RCE漏洞的安全更新报告:Apache Tomcat和Android。我们分析并分类了应用于缓解/修复的代码修复(即,修补程序/更新)在上述两个Java项目中的缓解/修复50-一(51)RCE漏洞。我们的分析表明,Java项目中发现的大多数RCE漏洞可以仅限于只有五(5)种/类代码修复。总的来说,我们的目标是研究RCE漏洞,以便为程序员提供具有方便的代码修复列表,从而使他们更容易在他们自己的基于Java的应用程序中有效地减轻已知的RCE漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号