Enforcing code security in database web applications using libraries and object models

Nicolas Juillerat · 2007

Libraries are commonly though as toolboxes offering reusable components and algorithms. In this paper, we show that a properly designed library can also be used to enforce security, and hence to help in the creation of robust and secure applications. As an illustration, we choose database web applications, because they are the kind of applications that suffers from the highest amount of vulnerabilities. SQL injection or Cross Site Scripting are common examples. We present how a library can be designed in such a way to completely mitigate these vulnerabilities. We also show how a properly designed library does not only allow a programmer to write secure code, but can also make vulnerable code impossible to write. We validate our theories through the presentation of a concrete Java library named "Stones" that follows and applies our ideas. Finally, our approach is compared with related work and various practical results are stated.

Read the paper · More papers on PaperTik