Coding Practices and Recommendations of Spring Security for Enterprise Applications

07/28/2020
by   Mazharul Islam, et al.
0

Spring security is tremendously popular among practitioners for its ease of use to secure enterprise applications. In this paper, we study the application framework misconfiguration vulnerabilities in the light of Spring security, which is relatively understudied in the existing literature. Towards that goal, we identify 6 types of security anti-patterns and 4 insecure vulnerable defaults by conducting a measurement-based approach on 28 Spring applications. Our analysis shows that security risks associated with the identified security anti-patterns and insecure defaults can leave the enterprise application vulnerable to a wide range of high-risk attacks. To prevent these high-risk attacks, we also provide recommendations for practitioners. Consequently, our study has contributed one update to the official Spring security documentation while other security issues identified in this study are being considered for future major releases by Spring security community.

READ FULL TEXT
research
12/19/2019

Blockchain-based Application Security Risks: A Systematic Literature Review

Although the blockchain-based applications are considered to be less vul...
research
08/25/2022

XDRI Attacks - and - How to Enhance Resilience of Residential Routers

We explore the security of residential routers and find a range of criti...
research
10/20/2019

Identity Document and banknote security forensics: a survey

Counterfeiting and piracy are a form of theft that has been steadily gro...
research
08/09/2019

That Was Then, This Is Now: A Security Evaluation of Password Generation, Storage, and Autofill in Thirteen Password Managers

Password managers have the potential to help users more effectively mana...
research
04/13/2018

Mitigating Docker Security Issues

It is very easy to run applications in Docker. Docker offers an ecosyste...
research
04/11/2018

How vulnerable are the Indian banks: A cryptographers' view

With the advent of e-commerce and online banking it has become extremely...
research
05/29/2021

A Measurement Study on the (In)security of End-of-Life (EoL) Embedded Devices

Embedded devices are becoming popular. Meanwhile, researchers are active...

Please sign up or login with your details

Forgot password? Click here to reset