2020 · 13 citations · 25 references
EngineeringUsable SecurityInformation SecuritySoftware EngineeringSecurity EvaluationSoftware AnalysisSpring SecuritySecurity ManagementSecurity TestingSecure By DesignSpring ApplicationsSpring Security CommunitySoftware DesignData SecurityCryptographySoftware SecuritySoftware TestingSecurityModel-driven Security
Spring security is tremendously popular among practitioners for its ease of use to secure enterprise applications. In this paper, we study the application framework misconfiguration vulnerabilities in the light of Spring security, which is relatively understudied in the existing literature. Towards that goal, we identify 6 types of security anti-patterns and 4 insecure vulnerable defaults by conducting a measurement-based approach on 28 Spring applications. Our analysis shows that security risks associated with the identified security anti-patterns and insecure defaults can leave the enterprise application vulnerable to a wide range of high-risk attacks. To prevent these high-risk attacks, we also provide recommendations for practitioners. Consequently, our study has contributed one update to the official Spring security documentation while other security issues identified in this study are being considered for future major releases by Spring security community.
25
Why eve and mallory love android
Sascha Fahl, Marian Harbach, Thomas Muders et al. · 2012 · 484 citations
An empirical study of cryptographic misuse in android applications
Manuel Egele, David Brumley, Yanick Fratantonio et al. · 2013 · 434 citations
The most dangerous code in the world
Martin Georgiev, Subodh Iyengar, Suman Jana et al. · 2012 · 412 citations
Public Key Infrastructure, Internet Security, Threat (Computer) +15
Robust defenses for cross-site request forgery
Adam Barth, Collin Jackson, John C. Mitchell · 2008 · 409 citations