Embedded Java Security: Security for Mobile Devices (Hardcover)

Mourad Debbabi, Mohamed Saleh, Chamseddine Talhi, Sami Zhioua

買這商品的人也買了...

商品描述

Description

Whereas Java brings functionality and versatility to the world of mobile devices, at the same time it also introduces new security threats. The rapid growth of the number of mobile devices that support Java makes this a pressing issue. Embedded Java Security carefully examines the security aspects of Java and offers a security evaluation for the Java platform.

After explaining background material on the architecture of embedded platforms and relating to its role in security, the book deconstructs the security model into its main components: It explains each component and relates it to the aim of securing the applications and the device. Toward this end, several implementations of the Java platform are examined and tested to relate the model to its actual implementation on devices. The security holes found are further used to clarify security issues and point out common errors. Finally, the book provides an evaluation of embedded Java security that includes security models and security tests performed on real-life implementations.

Topics and features:

• Presents the security model underlying Java ME

• Provides a vulnerability analysis of Java CLDL and a risk analysis study of Java ME vulnerabilities

• Supplies an example of a protection profile for Java ME - illustrated using the common criteria framework

• Discusses the most prominent standards that are relevant for Java ME security

• Reports on areas of common vulnerabilities, and considers specifications and programming mistakes

• Hints and suggestions are provided as ways for hardening security

This invaluable volume provides researchers and practitioners with a broader and deeper understanding of the issues involved in embedded Java security, and, as a larger view, mobile-devices security. It can also serve as an ancillary course text or helpful guide for self study in the field.

商品描述(中文翻譯)

描述

儘管Java為移動設備的世界帶來了功能和多樣性,但同時也引入了新的安全威脅。支援Java的移動設備數量的快速增長使這成為一個迫切的問題。《嵌入式Java安全》仔細研究了Java的安全方面,並為Java平台提供了安全評估。

在解釋嵌入式平台架構的背景材料並與其在安全方面的角色相關聯之後,本書將安全模型拆解為其主要組件:解釋每個組件並將其與保護應用程序和設備的目標相關聯。為此,對Java平台的幾個實現進行了檢查和測試,以將模型與其在設備上的實際實現相關聯。發現的安全漏洞進一步用於澄清安全問題並指出常見錯誤。最後,本書提供了對嵌入式Java安全的評估,包括對實際實現進行的安全模型和安全測試。

主題和特點:
- 提供了Java ME底層的安全模型
- 提供了Java CLDL的漏洞分析和Java ME漏洞的風險分析研究
- 提供了使用通用標準框架演示的Java ME保護配置文件的示例
- 討論了與Java ME安全相關的最重要的標準
- 報告了常見漏洞的領域,並考慮了規範和編程錯誤
- 提供了加強安全性的提示和建議

這本寶貴的著作為研究人員和從業人員提供了對嵌入式Java安全問題以及更廣泛的移動設備安全問題的更廣泛和更深入的理解。它還可以作為附加課程教材或自學指南。