Uppsats
Static Analysis of Java Plugins for Minecraft Servers
Master-uppsats
Stockholms universitet/Institutionen för data- och systemvetenskap
Publicerad: 2026
Språk: Engelska
Nyckelord
klicka för att sökaSammanfattning
One of the most common ways for people to play Minecraft, the best selling video game of all time, is to host servers to play with friends. These servers can be customized to the player's choice, often using lightweight and easy to install plugins. These plugins, commonly written in Java, have in the past been used to perform attacks on a large scale. Since a large number of files are uploaded every day in the repositories hosting these plugins, human based detection has a hard time keeping up and there is therefore a need for tools. This thesis explores the idea of combining multiple static analysis methods, which rely on analysis without executing the code, for the detection of malicious files. The results of both the combined and individual methods are then presented, and their performance is evaluated using common statistical metrics. Lastly, this thesis also discusses the possibility of one or more of the metrics providing useless data for the analysis, as well as strengths and other issues that can arise from the methods applications. By using an action research methodology the tool was developed on a dataset of 300 files. This dataset contained plugins retrieved from three of the most common repositories as well as fifteen plugins that were modified to show malicious behavior. The results of the analysis conducted by the tool on the dataset were then reviewed and evaluated using statistical metrics such as accuracy, precision and recall. The results showed that of the 5 metrics used, 2 of them provided little useful information and generated noise, while the other three were found to provide more decisive data for the evaluation. Multiple limitations have been found in each method, some stemming from constraints coming from static analysis, such as the use of dynamic techniques to avoid detection, and others originating from the way the methods were implemented. As such, further research could be conducted to delve deeper into these limitations and find mitigation. Such experiments would help the development of a tool that could be used to reduce the risks for a large number of people, many of whom are children and players that have little to no experience with security.
Information
- Författare
- Garzon, Samuele
- Lärosäte / institution
- Stockholms universitet/Institutionen för data- och systemvetenskap
- Publiceringsdatum
- 2026
- Uppsatstyp
- Master-uppsats
- Språk
- Engelska
Utforska vidare
Liknande uppsatser
Uppsatser med liknande ämnen och nyckelord.
Kandidat-uppsats, KTH/Hälsoinformatik och logistik
Mustafa Hamid Al Ashiri, Adam
Publicerad: 2026
Master-uppsats, Stockholms universitet/Institutionen för data- och systemvetenskap
Rau, Moritz Maximilian
Publicerad: 2026
Master-uppsats, KTH/Skolan för elektroteknik och datavetenskap (EECS)
Norlin, Johan
Publicerad: 2026
Master-uppsats, Lunds universitet/Institutionen för elektro- och informationsteknik
Svensson, August, Niklasson Lundqvist, Lukas
Publicerad: 2026
Master-uppsats, KTH/Skolan för elektroteknik och datavetenskap (EECS)
Correia, Diogo
Publicerad: 2026
Master-uppsats, Linköpings universitet/Institutionen för datavetenskap
Hashemi, Afshan
Publicerad: 2026