Embedded Java Security

Security for Mobile Devices

  • Mourad Debbabi
  • Mohamed Saleh
  • Chamseddine Talhi
  • Sami Zhioua

Table of contents

  1. Front Matter
    Pages i-xiii
  2. Pages 1-16
  3. Pages 81-114
  4. Pages 153-165
  5. Pages 203-230
  6. Pages 231-233
  7. Back Matter
    Pages 235-243

About this book

Introduction

Whereas Java brings functionality and versatility to the world of mobile devices, at the same time it also introduces new security threats. The rapid growth of the number of mobile devices that support Java makes this a pressing issue. Embedded Java Security carefully examines the security aspects of Java and offers a security evaluation for the Java platform.

After explaining background material on the architecture of embedded platforms and relating to its role in security, the book deconstructs the security model into its main components: It explains each component and relates it to the aim of securing the applications and the device. Toward this end, several implementations of the Java platform are examined and tested to relate the model to its actual implementation on devices. The security holes found are further used to clarify security issues and point out common errors. Finally, the book provides an evaluation of embedded Java security that includes security models and security tests performed on real-life implementations.

Topics and features:

• Presents the security model underlying Java ME

• Provides a vulnerability analysis of Java CLDL and a risk analysis study of Java ME vulnerabilities

• Supplies an example of a protection profile for Java ME - illustrated using the common criteria framework

• Discusses the most prominent standards that are relevant for Java ME security

• Reports on areas of common vulnerabilities, and considers specifications and programming mistakes

• Hints and suggestions are provided as ways for hardening security

This invaluable volume provides researchers and practitioners with a broader and deeper understanding of the issues involved in embedded Java security, and, as a larger view, mobile-devices security. It can also serve as an ancillary course text or helpful guide for self study in the field.

Keywords

CLDC Embedded Java Inform Java Mobile devices Risk analysis Security Security evaluation

Authors and affiliations

  • Mourad Debbabi
    • 1
  • Mohamed Saleh
    • 1
  • Chamseddine Talhi
    • 1
  • Sami Zhioua
    • 1
  1. 1.Computer Security Laboratory, Concordia Institute for Information Systems EngineeringConcordia UniversityMontrealCanada

Bibliographic information

  • DOI https://doi.org/10.1007/978-1-84628-711-4
  • Copyright Information Springer-Verlag London Limited 2007
  • Publisher Name Springer, London
  • eBook Packages Computer Science
  • Print ISBN 978-1-84628-590-5
  • Online ISBN 978-1-84628-711-4