Current - Issue
Year 2026 · Volume 5 · Issue 2
Review Article
A Systematic Review of Java Security: Architecture, Cryptographic Services, Vulnerabilities, and Emerging Security Paradigms
Md. Aali Rahman1
Khushboo Rani2
Md. Irfan Alam3
1 Bachelors of Computer Science and Engineering (AI & ML),Woxsen University, Hyderabad, Telangana, India. 2 Assistant professor, Dr. Shyama Prasad Mukherjee University, Ranchi, Jharkhand, India. 3 Faculty of CSE & IT, Jharkhand Rai University, Ranchi, Jharkhand, India.
Published Online: May-August 2026
Pages: 972-978
Cite this article
↗ https://www.doi.org/10.59256/indjcst.20260502106References
1. L. Gong, G. Ellison, and M. Dageforde, Inside Java 2 Platform Security: Architecture, API Design, and Implementation, 2nd ed. Boston,
MA: Addison-Wesley, 2003.
2. X. Leroy, “Java bytecode verification: Algorithms and formalizations,” Journal of Automated Reasoning, vol. 30, no. 3–4, pp. 235–269,
2003.
3. L. Gong, “Java security: A ten-year retrospective,” in Proc. Annual Computer Security Applications Conference (ACSAC), Honolulu, HI,
USA, 2009.
4. Oracle Corporation, “Java Cryptography Architecture (JCA) Reference Guide,” Java SE Documentation. [Online]. Available:
https://docs.oracle.com/en/java/javase/11/security/java-cryptography-architecture-jca-reference-guide.html
5. National Institute of Standards and Technology, Advanced Encryption Standard (AES), Federal Information Processing Standards Publication
FIPS 197, Nov. 2001 (updated 2023).
6. National Institute of Standards and Technology, Secure Hash Standard (SHS), Federal Information Processing Standards Publication FIPS
180-4, Aug. 2015.
7. S. Thomas, L. Williams, and T. Xie, “On automated prepared statement generation to remove SQL injection vulnerabilities,” Information
and Software Technology, vol. 51, no. 3, pp. 589–598, 2009.
8. OWASP Foundation, “SQL Injection Prevention Cheat Sheet,” OWASP Cheat Sheet Series. [Online]. Available:
https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html
9. I. Sayar, A. Bartel, E. Bodden, and Y. Le Traon, “An in-depth study of Java deserialization remote-code execution exploits and
vulnerabilities,” ACM Trans. Softw. Eng. Methodol., vol. 32, no. 1, Art. 25, pp. 1–45, 2023.
10. S. Rasheed, J. Dietrich, and A. Tahir, “A hybrid analysis to detect Java serialisation vulnerabilities,” in Proc. 35th IEEE/ACM Int. Conf.
Automated Software Engineering (ASE), 2020, pp. 1209–1213.
11. OWASP Foundation, “A08:2021 – Software and Data Integrity Failures,” OWASP Top 10:2021. [Online]. Available:
https://owasp.org/Top10/2021/A08_2021-Software_and_Data_Integrity_Failures/
12. OWASP Foundation, “Unsafe Use of Reflection.” [Online]. Available: https://owasp.org/www-
community/vulnerabilities/Unsafe_use_of_Reflection.
13. SEI CERT, “SEC05-J. Do not use reflection to increase accessibility of classes, methods, or fields,” SEI CERT Oracle Coding Standard for
Java, Carnegie Mellon University.
14. OWASP Foundation, “A02:2021 – Cryptographic Failures,” OWASP Top 10:2021. [Online]. Available:
https://owasp.org/Top10/2021/A02_2021-Cryptographic_Failures/
15. MITRE Corporation, “CWE-798: Use of Hard-coded Credentials,” Common Weakness Enumeration. [Online]. Available:
https://cwe.mitre.org/data/definitions/798.html
16. R. Riggs, JEP 290: Filter Incoming Serialization Data, OpenJDK, 2016. [Online]. Available: https://openjdk.org/jeps/290
17. S. Mullan, L. Andersen, and W. Wang, JEP 411: Deprecate the Security Manager for Removal, OpenJDK, 2021. [Online]. Available:
https://openjdk.org/jeps/411
18. OpenJDK, JEP 486: Permanently Disable the Security Manager, 2024. [Online]. Available: https://openjdk.org/jeps/486
19. M. Reinhold, JEP 261: Module System, OpenJDK, 2017. [Online]. Available: https://openjdk.org/jeps/261
20. T. Marjanov, I. Pashchenko, and F. Massacci, “Machine learning for source code vulnerability detection: What works and what isn’t there
yet,” IEEE Security & Privacy, vol. 20, no. 5, pp. 60–76, 2022.
21. S. Chakraborty, R. Krishna, Y. Ding, and B. Ray, “Deep learning based vulnerability detection: Are we there yet?,” IEEE Trans. Softw. Eng.,
vol. 48, no. 9, pp. 3280–3296, 2022.
22. T. Theodoropoulos et al., “Security in cloud-native services: A survey,” Journal of Cybersecurity and Privacy, vol. 3, no. 4, pp. 758–793,
2023.
23. Baeldung, “Class Loaders in Java.” [Online]. Available: https://www.baeldung.com/java-classloaders24. GeeksforGeeks, “How to Handle SQL Injection in JDBC Using PreparedStatement?” [Online]. Available:
https://www.geeksforgeeks.org/java/how-to-handle-sql-injection-in-jdbc-using-preparedstatement/
25. Baeldung, “Deserialization Vulnerabilities in Java.” [Online]. Available: https://www.baeldung.com/java-deserialization-vulnerabilities
26. Baeldung, “Is Java Reflection Bad Practice?” [Online]. Available: https://www.baeldung.com/java-reflection-benefits-drawbacks
27. Alam, M. I. (2020). Enhancing cloud security using multi-Level dna cryptography. Splint International Journal of Professionals, 7(1), 75-
82.
28. Irfan Alam, M., & Singh, S. N. (2021). Designing and implementing cloud security using multi-layer DNA cryptography in python. Trends
in Wireless Communication and Information Security: Proceedings of EWCIS 2020, 375-385.
29. Alam, Md Irfan. "Enhancing cloud security using multi-Level dna cryptography." Splint International Journal of Professionals 7.1 (2020):
75-82
MA: Addison-Wesley, 2003.
2. X. Leroy, “Java bytecode verification: Algorithms and formalizations,” Journal of Automated Reasoning, vol. 30, no. 3–4, pp. 235–269,
2003.
3. L. Gong, “Java security: A ten-year retrospective,” in Proc. Annual Computer Security Applications Conference (ACSAC), Honolulu, HI,
USA, 2009.
4. Oracle Corporation, “Java Cryptography Architecture (JCA) Reference Guide,” Java SE Documentation. [Online]. Available:
https://docs.oracle.com/en/java/javase/11/security/java-cryptography-architecture-jca-reference-guide.html
5. National Institute of Standards and Technology, Advanced Encryption Standard (AES), Federal Information Processing Standards Publication
FIPS 197, Nov. 2001 (updated 2023).
6. National Institute of Standards and Technology, Secure Hash Standard (SHS), Federal Information Processing Standards Publication FIPS
180-4, Aug. 2015.
7. S. Thomas, L. Williams, and T. Xie, “On automated prepared statement generation to remove SQL injection vulnerabilities,” Information
and Software Technology, vol. 51, no. 3, pp. 589–598, 2009.
8. OWASP Foundation, “SQL Injection Prevention Cheat Sheet,” OWASP Cheat Sheet Series. [Online]. Available:
https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html
9. I. Sayar, A. Bartel, E. Bodden, and Y. Le Traon, “An in-depth study of Java deserialization remote-code execution exploits and
vulnerabilities,” ACM Trans. Softw. Eng. Methodol., vol. 32, no. 1, Art. 25, pp. 1–45, 2023.
10. S. Rasheed, J. Dietrich, and A. Tahir, “A hybrid analysis to detect Java serialisation vulnerabilities,” in Proc. 35th IEEE/ACM Int. Conf.
Automated Software Engineering (ASE), 2020, pp. 1209–1213.
11. OWASP Foundation, “A08:2021 – Software and Data Integrity Failures,” OWASP Top 10:2021. [Online]. Available:
https://owasp.org/Top10/2021/A08_2021-Software_and_Data_Integrity_Failures/
12. OWASP Foundation, “Unsafe Use of Reflection.” [Online]. Available: https://owasp.org/www-
community/vulnerabilities/Unsafe_use_of_Reflection.
13. SEI CERT, “SEC05-J. Do not use reflection to increase accessibility of classes, methods, or fields,” SEI CERT Oracle Coding Standard for
Java, Carnegie Mellon University.
14. OWASP Foundation, “A02:2021 – Cryptographic Failures,” OWASP Top 10:2021. [Online]. Available:
https://owasp.org/Top10/2021/A02_2021-Cryptographic_Failures/
15. MITRE Corporation, “CWE-798: Use of Hard-coded Credentials,” Common Weakness Enumeration. [Online]. Available:
https://cwe.mitre.org/data/definitions/798.html
16. R. Riggs, JEP 290: Filter Incoming Serialization Data, OpenJDK, 2016. [Online]. Available: https://openjdk.org/jeps/290
17. S. Mullan, L. Andersen, and W. Wang, JEP 411: Deprecate the Security Manager for Removal, OpenJDK, 2021. [Online]. Available:
https://openjdk.org/jeps/411
18. OpenJDK, JEP 486: Permanently Disable the Security Manager, 2024. [Online]. Available: https://openjdk.org/jeps/486
19. M. Reinhold, JEP 261: Module System, OpenJDK, 2017. [Online]. Available: https://openjdk.org/jeps/261
20. T. Marjanov, I. Pashchenko, and F. Massacci, “Machine learning for source code vulnerability detection: What works and what isn’t there
yet,” IEEE Security & Privacy, vol. 20, no. 5, pp. 60–76, 2022.
21. S. Chakraborty, R. Krishna, Y. Ding, and B. Ray, “Deep learning based vulnerability detection: Are we there yet?,” IEEE Trans. Softw. Eng.,
vol. 48, no. 9, pp. 3280–3296, 2022.
22. T. Theodoropoulos et al., “Security in cloud-native services: A survey,” Journal of Cybersecurity and Privacy, vol. 3, no. 4, pp. 758–793,
2023.
23. Baeldung, “Class Loaders in Java.” [Online]. Available: https://www.baeldung.com/java-classloaders24. GeeksforGeeks, “How to Handle SQL Injection in JDBC Using PreparedStatement?” [Online]. Available:
https://www.geeksforgeeks.org/java/how-to-handle-sql-injection-in-jdbc-using-preparedstatement/
25. Baeldung, “Deserialization Vulnerabilities in Java.” [Online]. Available: https://www.baeldung.com/java-deserialization-vulnerabilities
26. Baeldung, “Is Java Reflection Bad Practice?” [Online]. Available: https://www.baeldung.com/java-reflection-benefits-drawbacks
27. Alam, M. I. (2020). Enhancing cloud security using multi-Level dna cryptography. Splint International Journal of Professionals, 7(1), 75-
82.
28. Irfan Alam, M., & Singh, S. N. (2021). Designing and implementing cloud security using multi-layer DNA cryptography in python. Trends
in Wireless Communication and Information Security: Proceedings of EWCIS 2020, 375-385.
29. Alam, Md Irfan. "Enhancing cloud security using multi-Level dna cryptography." Splint International Journal of Professionals 7.1 (2020):
75-82
Related Articles
2026
Artificial Intelligence in Learning and Teaching
2026
Admin Assist: An AI – Driven Configuration and Orchestration for Enterprise Application
2026
Enhancing Blood Group Identification using pigeon inspired optimization: An Innovative Approach
2026
Eco-Genius: Power Up Smart, Power Down Waste
2026
Crowd-Sourced Disaster Response and Rescue Assistant
2026
Unveiling Deepfake Detection Using Vision Transformers: A Survey and Experimental Study
Share Article
Or copy link
https://www.indjcst.com/archives/a-systematic-review-of-java-security-architecture-cryptographic-services-vulnerabilities-and-emerging-security-paradigms
*Instagram doesn't support direct link sharing from web. Copy the link and share it in your Instagram story or post.