A permission system for secure AOP

Wouter De Borger, Bart De Win, Bert Lagaisse, Wouter Joosen · 2010

The integration of third-party aspects into applications creates security challenges. Due to the intrusive impact of aspects, one cannot guarantee that the dynamic composition of aspects does not lead to misbehavior. The newly composed aspect typically has many, if not unrestricted, rights to read and modify attributes of the base system. AspectJ, amongst other AOP systems, suffers from this limitation, which makes the composition of independently developed aspects riskful.

Read the paper · More papers on PaperTik