Eclipse Java security scanner - JSS

Russell Spitler · Journal of computing sciences in colleges · 2005

JSS is a plug-in that scans Java code for security vulnerabilities. The are statically detectable and come from research in Java security. This research looks at both the structure of the code that leads to the vulnerability and how that structure can be taken advantage of to compromise sensitive information or critical code. Such security problems include improper visibility restraints, use of inner classes, failure to handle exceptions properly, execution of code in the JNI, and failure to finalize methods and classes. Gary McGraw and John Viega's paper Statically Scanning Java Code: finding security vulnerabilities is the inspiration for JSS. Using the built in org.eclipse.jdt.core package the plug-in parses the Java code and then generates an AST. Then using the Visitor pattern the tree is traversed and the problem sections of the code are identified. These sections are then highlighted and possible solutions are suggested. The scanner will be implemented as a fully functional, updatable plug-in for the Eclipse JDE.

Read the paper · More papers on PaperTik