Advanced Search

Information Security Journal: A Global Perspective

Volume 17, Issue 5-6, 2008

New AspectJ Pointcuts for Integer Overflow and Underflow Detection

New AspectJ Pointcuts for Integer Overflow and Underflow Detection

DOI:
10.1080/19393550802492479
D. Alhadidia*, M. Debbabia & P. Bhattacharyaa

pages 278-287

Available online: 04 Dec 2008

ABSTRACT

Aspect-oriented Programming (AOP) appears to be a promising paradigm for software security hardening. Using AOP, security experts can be responsible for coding security properties, and developers can concentrate on the basic functionality of the program. AspectJ extends the Java programming language to implement crosscutting concerns modularly in general. In this paper, we have extended AspectJ with new pointcuts in order to detect integer overflows and underflows in Java. Integer overflows and underflows in Java occur silently without throwing an exception. A malicious user can exploit them to produce a security breach. Hence, we implement new pointcuts: addition, multiplication, and subtraction that allow to write advices around integer arithmetic operations to detect integer overflow and underflow and consequently prevent considerable number of security breaches.

KEYWORDS

 

Details

  • Available online: 04 Dec 2008

Author affiliations

  • a Computer Security Laboratory (CSL), Concordia Institute for Information Systems Engineering, Concordia University, Montreal, Quebec, Canada

Journal news

Librarians

Taylor & Francis Group