Security is the topic for three JavaOneSM Online technical sessions now accessible.
You Are Hacked: Ajax Security Essentials for Enterprise JavaTM Technology Developers
Presented by James Gould and Karthik Shyamsunder, both of VeriSign Inc., this session covers browsers' JavaScriptTM programming language security models and common exploits found in Ajax applications, such as cross-site scripting, cross-site request forgery, malicious data and code injection.
Three Approaches to Securing Your JavaServerTM Faces Technology/Spring/Hibernate Applications
Presented by Jaya Doraiswamy with ELM Resources and Ray Lai with Intuit, this session discusses how different security frameworks can secure the web pages components; the business tier, such as the JavaBeansTM architecture; the data tier such as data objects using Hibernate; and techniques to support both Web and non-Web applications and a variety of security providers, such as JavaTM Authentication and Authorization Service (JAAS), database and LDAP.
Leveraging SolarisTM Trusted Extensions to Implement Platform Security Services for the Java Language
Presented by John Weeks with Sun, he introduces an experimental JavaTM Native Interface (JNITM) implementation of the Trusted Extensions label APIs for use in Java applications. Specifics covered include how these extensions enable Java applications and web services to handle multilevel data and modulate the quality of service when situations arise, and the types of platform-specific services that might be created by using these Java extensions, such as those that use sensitivity labels.
Read More ...
[...read more...]