The document focuses on the model-based analysis of Java EE web security configurations, emphasizing the importance of access control in protecting against security misconfigurations in distributed web applications. It identifies common vulnerabilities and proposes methods for automatic detection of security anomalies in Java EE projects, confirming that many projects contain configuration issues while demonstrating the efficiency of the proposed approach. The authors discuss future work concerning the integration of programmatic security constraints and other data sources to enhance application security.
Related topics: