Umeå University's logo

umu.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
A Graphical Representation of RCE Vulnerabilities in Java Deserialization
Umeå University, Faculty of Science and Technology, Department of Computing Science.
2023 (English)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

Unsafe deserialization in Java risks exposing systems to remote code execution (RCE) attacks. By combining certain versions of the Java Virtual Machine (JVM) with common third-party libraries, deserialization vulnerabilities can be introduced in otherwise safe systems. Because of the large number of possible combinations, developers and analysts cannot easily determine whether any given versions of software are safe to use. To facilitate this, this project makes use of the deserialization vulnerability detection tool ysoserial, and automates its testing on just over half a million combinations of different JVMs and versions of libraries. These results are then presented in a graphical format and made accessible online for future referencing.

Place, publisher, year, edition, pages
2023. , p. 35
Series
UMNAD ; 1385
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:umu:diva-209640OAI: oai:DiVA.org:umu-209640DiVA, id: diva2:1766231
Educational program
Bachelor of Science Programme in Computing Science
Supervisors
Examiners
Available from: 2023-06-13 Created: 2023-06-12 Last updated: 2023-06-13Bibliographically approved

Open Access in DiVA

fulltext(2521 kB)717 downloads
File information
File name FULLTEXT01.pdfFile size 2521 kBChecksum SHA-512
42e97d27ba0578e6d98719ec4070ff952eca0125508062c34857a7c3a30b7a0f5eba8a169694d6e229f6a910568f1af9877694e97f1b7508353e9c303b7fb58e
Type fulltextMimetype application/pdf

Search in DiVA

By author/editor
Jansson, Glenn
By organisation
Department of Computing Science
Computer Sciences

Search outside of DiVA

GoogleGoogle Scholar
Total: 718 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 549 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf