Prof. Eric Bodden, Ph.D.

Professor for Software Engineering at Heinz Nixdorf Institute, Paderborn University and
Director for Software Engineering at Fraunhofer IEM
  • rss
  • Home
  • Research
    • Publications
  • Tools
  • Teaching
  • About me
  • Photos

IEEE S&P Paper on Hardening the Java Runtime is now available

Eric | March 20, 2017

Our new S&P paper Hardening Java’s Access Control by Abolishing Implicit Privilege Elevation is now available online. It is a follow-up work to our previous CCS’16 paper An In-Depth Study of More Than Ten Years of Java Exploitation. In this former paper we classified a large number of history Java exploits. In doing so, we found that the largest class of exploits was made possible by shortcuts in Java’s implementation of access control. In the S&P paper we now show that it is possible to go without those shortcuts, without any loss of performance. We also discuss the usability implications that this removal of shortcuts would have.

Cross-posted from Secure Software Engineering

Related Posts

  1. An In-Depth Study of More Than Ten Years of Java Exploitation
  2. Eric Bodden named Associate Editor of IEEE TSE
  3. Eric Bodden named Associate Editor of IEEE TSE
  4. GaLity accepted at ESSoS 2016
  5. GaLity accepted at ESSoS 2016
Categories
Misc, Research, Uncategorized
Comments rss
Comments rss

« New Paper “The Soot-based Toolchain For Analyzing Android Apps” Official inauguration of Fraunhofer IEM »

Welcome

Welcome to my website. Interested in my research? Click here for details or jump directly to my publications.

Memberships

   

Previous Posts

March 2017
M T W T F S S
« Feb   May »
 12345
6789101112
13141516171819
20212223242526
2728293031  

Tags

Alumni AOP AOSD AspectJ Atlanta Bike Blizzard Bug finding Caro Clara COMP 621 Eclipse FSE Google ISSTA Java LinkedIn Mac McGill Microsoft Montreal NASA Photos Programming Quebec City Race detection Racer Runtime Monitoring Runtime verification RV RWTH Seattle Slides Snow storm Soot Soot Tutorial Static Analysis Strike TamiFlex TA strike Thesis tracematches Typestate Vacation Winter carnival


rss Comments rss valid xhtml 1.1 design by jide powered by Wordpress get firefox