• Home
  • Search
  • Bringing java's wild native world under control
  • Cite Icon21
  • https://doi.org/10.1145/2535505Copy DOI Icon

Bringing java's wild native world under control

Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

For performance and for incorporating legacy libraries, many Java applications contain native-code components written in unsafe languages such as C and C++. Native-code components interoperate with Java components through the Java Native Interface (JNI). As native code is not regulated by Java's security model, it poses serious security threats to the managed Java world. We introduce a security framework that extends Java's security model and brings native code under control. Leveraging software-based fault isolation, the framework puts native code in a separate sandbox and allows the interaction between the native world and the Java world only through a carefully designed pathway. Two different implementations were built. In one implementation, the security framework is integrated into a Java Virtual Machine (JVM). In the second implementation, the framework is built outside of the JVM and takes advantage of JVM-independent interfaces. The second implementation provides JVM portability, at the expense of some performance degradation. Evaluation of our framework demonstrates that it incurs modest runtime overhead while significantly enhancing the security of Java applications.

Similar Papers
  • Conference Article
  • Citations17

Evaluating the Flexibility of the Java Sandbox

  • Dec 07, 2015
  • Zack Coker +4
  • Conference Article
  • Citations3

Building Java program analysis tools using Javana

  • Oct 22, 2006
  • Dries Buytaert +3
  • Research Article
  • Citations2

Evaluating the Java Native Interface (JNI)

  • Apr 01, 2018
  • International Journal of Distributed Systems and Technologies
  • Stelios Sotiriadis +3
  • Book Chapter
  • Citations19

Security for Distributed E-Service Composition

  • Jan 01, 2001
  • Stefan Seltzsam +2
  • Conference Article
  • Citations1

Applied cryptography in Java

  • Oct 05, 1999
  • A Partida +1
  • Conference Article
  • Citations31

Machine-Learning-based Performance Heuristics for Runtime CPU/GPU Selection

  • Sep 08, 2015
  • Akihiro Hayashi +3
  • Conference Article
  • Citations3

Too Quiet in the Library: An Empirical Study of Security Updates in Android Apps' Native Code

  • May 01, 2021
  • Sumaya Almanee +3
  • Conference Article

Software tool construction for deployment of JMX services in distributed testbeds

  • Jan 01, 2006
  • K Balos +3
  • Research Article
  • Citations8

AOT vs. JIT: impact of profile data on code quality

  • Jun 21, 2017
  • ACM SIGPLAN Notices
  • April W Wade +2
  • Research Article
  • Citations12

Using the Java Native Interface

  • Nov 01, 1997
  • XRDS: Crossroads, The ACM Magazine for Students
  • S Fouzi Husaini
  • Conference Article
  • Citations14

SJFuzz: Seed and Mutator Scheduling for JVM Fuzzing

  • Nov 30, 2023
  • Mingyuan Wu +7
  • Conference Article
  • Citations14

SIMD intrinsics on managed language runtimes

  • Feb 24, 2018
  • Alen Stojanov +3
  • Research Article
  • Citations1

Executing native Java code in R: an approach based on a local server.

  • Sep 28, 2020
  • PeerJ. Computer science
  • Mathieu Fortin
  • Conference Article
  • Citations9

File-based sharing for dynamically compiled code on Dalvik virtual machine

  • Dec 01, 2010
  • Yao-Chih Huang +3
  • PDF
  • Research Article
  • Citations6

Creating Java to Native Code Interfaces with Janet

  • Jan 01, 2001
  • Scientific Programming
  • Marian Bubak +3
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.