• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. A Systematic Hardening of Java's Information Hiding
 
  • Details
  • Full
Options
2021
Conference Paper
Title

A Systematic Hardening of Java's Information Hiding

Abstract
The Java runtime is installed on billions of devices worldwide, and over years it has been a primary attack vector for online criminals. In this work, we address that many attack vectors exploit weaknesses in Java's information hiding, making use of illegal access to private members of system classes. To study to what extent such attacks can be mitigated, and at what cost, this paper demonstrates a proof-of-concept solution to strengthen information hiding. Experiments show that this approach is backward compatible, and that it blocks 84% of all information-hiding attacks in a large-scale sample set at an average performance overhead below 2%. Based on our experiments, we suggest a solution to strengthen information hiding for productive use that has the potential to outperform our proof o f concept in terms of robustness and performance, and also would block the remaining information-hiding attacks. Finally, we conclude with general advice on the design of secure software.
Author(s)
Holzinger, Philipp  
Boden, Eric
Mainwork
International Symposium on Advanced Security on Software and Systems 2021. Proceedings  
Conference
International Symposium on Advanced Security on Software and Systems (ASSS) 2021  
Asia Conference on Computer and Communications Security (ASIA CCS) 2021  
DOI
10.1145/3457340.3458300
Language
English
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024