Uppsats

Static Analysis of Java Plugins for Minecraft Servers

Master-uppsats

Stockholms universitet/Institutionen för data- och systemvetenskap

Publicerad: 2026

Språk: Engelska

Sammanfattning

One of the most common ways for people to play Minecraft, the best selling video game of all time, is to host servers to play with friends. These servers can be customized to the player's choice, often using lightweight and easy to install plugins. These plugins, commonly written in Java, have in the past been used to perform attacks on a large scale. Since a large number of files are uploaded every day in the repositories hosting these plugins, human based detection has a hard time keeping up and there is therefore a need for tools. This thesis explores the idea of combining multiple static analysis methods, which rely on analysis without executing the code, for the detection of malicious files. The results of both the combined and individual methods are then presented, and their performance is evaluated using common statistical metrics. Lastly, this thesis also discusses the possibility of one or more of the metrics providing useless data for the analysis, as well as strengths and other issues that can arise from the methods applications. By using an action research methodology the tool was developed on a dataset of 300 files. This dataset contained plugins retrieved from three of the most common repositories as well as fifteen plugins that were modified to show malicious behavior. The results of the analysis conducted by the tool on the dataset were then reviewed and evaluated using statistical metrics such as accuracy, precision and recall. The results showed that of the 5 metrics used, 2 of them provided little useful information and generated noise, while the other three were found to provide more decisive data for the evaluation. Multiple limitations have been found in each method, some stemming from constraints coming from static analysis, such as the use of dynamic techniques to avoid detection, and others originating from the way the methods were implemented. As such, further research could be conducted to delve deeper into these limitations and find mitigation. Such experiments would help the development of a tool that could be used to reduce the risks for a large number of people, many of whom are children and players that have little to no experience with security.

Information

Författare
Garzon, Samuele
Lärosäte / institution
Stockholms universitet/Institutionen för data- och systemvetenskap
Publiceringsdatum
2026
Uppsatstyp
Master-uppsats
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.