This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "Java Security Frameworks"
From OWASP
m (fix antisami name) |
m (update CSRF time) |
||
Line 83: | Line 83: | ||
|- | |- | ||
| [http://www.owasp.org/index.php/Category:OWASP_CSRFGuard_Project CSRFGuard]<br> | | [http://www.owasp.org/index.php/Category:OWASP_CSRFGuard_Project CSRFGuard]<br> | ||
− | | align="center" | | + | | align="center" | 2014<br> |
| align="center" | <br> | | align="center" | <br> | ||
| align="center" | <br> | | align="center" | <br> |
Revision as of 19:21, 15 March 2015
A list of third party (i.e. not part of Java SE or EE) security frameworks. This page contains a list of Java security libraries and frameworks and indicates which security features each library supports.
Enterprise
- OWASP Enterprise Security API a new OWASP project to provide all essential security services under one roof.
- HDIV A web application security framework that provides a number of functions.
Access Control (Authentication and Authorization)
- jGuard - jGuard is written in Java. Its goal is to provide a security framework based on JAAS (Java Authentication and Authorization Security). The framework is written for web and standalone applications, to easily provide solutions for access control problems.
- OACC - OACC is an application security framework for Java designed for fine grained (object level) access control. OACC uses the abstraction of a resource for the application objects being secured. This key abstraction enables OACC to provide a rich API that includes grant, revoke and query capabilities for storing and managing the application's security relationships.
Encryption
- Bouncycastle - Lightweight Java cryptography APIs
- Jasypt - Jasypt is a java library which allows the developer to add basic encryption capabilities to his/her projects with minimum effort, and without the need of having deep knowledge on how cryptography works.
Cross Site Scripting (XSS)
- OWASP Java Encoder Project is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies to help Java web developers defend against Cross Site Scripting.
- OWASP Java HTML Sanitizer Project is a fast and easy to configure HTML Sanitizer written in Java which lets you include HTML authored by third-parties in your web application while protecting against XSS.
- OWASP Java JSON Sanitizer is a tool to convert JSON-like content to valid JSON! The OWASP JSON Sanitizer Project is a simple to use Java library that can be attached at either end of a data-pipeline
Additional Java Security Libraries
Name and link |
Updated |
AU |
AC |
CF |
CR |
IV |
OE |
SM |
XM |
XS |
---|---|---|---|---|---|---|---|---|---|---|
AntiSamy |
2011 |
|
|
|
|
Y |
Y |
|
|
|
Apache Santuarrio |
2011 |
|
|
|
|
|
|
|
Y |
|
Apache Shiro |
2011 |
Y |
Y |
? |
Y |
? |
Y |
Y |
? |
Y |
Bouncy Castle |
2011 |
|
|
|
Y |
|
|
|
|
|
CSRFGuard |
2014 |
|
|
Y |
Y |
|
|
|
|
|
ESAPI |
2010 |
Y |
Y |
? |
Y |
Y |
Y |
? |
|
Y |
Jasypt |
2010 |
|
|
|
Y |
|
|
|
|
|
iGuard |
2011 |
Y |
Y |
|
|
|
|
|
|
|
OACC |
2014 |
Y |
Y |
|
Y |
Y |
|
? |
|
|
Vlad |
? |
|
|
|
|
Y |
|
|
|
|
Security Features Key
- AU Authentication
- AC Authorization / Access Control
- CF Anti CSRF
- CR Cryptography
- IV Input Validation
- OE Output encoding
- SM Session management
- XM XML security
- XS XSS protection