A Security Model for Web-Based Communication

被引:0
|
作者
Tehrani, Pouyan Fotouhi [1 ]
Osterweil, Eric [2 ]
Schmidt, Thomas C. [3 ]
Wählisch, Matthias [4 ]
机构
[1] Weizenbaum Institute / Fraunhofer FOKUS, Berlin,60272635, Germany
[2] George Mason University, Fairfax,VA,60018319, United States
[3] HAW Hamburg, Hamburg,60032697, Germany
[4] TU Dresden, Dresden,60018353, Germany
关键词
Websites;
D O I
10.1145/3623292
中图分类号
学科分类号
摘要
Web access involves various protocols to resolve domain names to IP addresses, establish data exchange channels with Web servers, and to authenticate communication partners. Each protocol has its own set of requirements and security measures. In addition to technical features, operating the Web also introduces organizational and political aspects which are important to consider when deploying a secure basis for Web-based communication.In this paper, we propose an algorithmic security model based on the widely deployed technologies DNS(SEC) and Web PKI to cover the three dimensions identification, resolution, and transaction. Our model enables quantification and qualification of the security assurance provided by an online service provider. To verify the applicability of our model, we investigate the online presence of Alerting Authorities in the U.S., selected German Emergency Service providers, and UN member states. We observe partially enhanced security relative to global Internet trends, yet find cause for concern as only about 6% of unique hosts cater to secure resolution. About 46% of investigated organizations use shared certificates with 1% of all organizations having no or invalid certificates. Two thirds of organizations are not uniquely identifiable and as such lack the basic requirement of trustworthy communication. © 2024 ACM.
引用
收藏
页码:83 / 90
相关论文
共 50 条
  • [1] Web-based construction project communication model
    Tai, SL
    Liu, RH
    [J]. Proceedings of 2005 International Conference on Construction & Real Estate Management, Vols 1 and 2: CHALLENGE OF INNOVATION IN CONSTRUCTION AND REAL ESTATE, 2005, : 374 - 376
  • [2] Secure web-based communication
    Mir, Nighat
    Hussain, Sayed Afaq
    [J]. WORLD CONFERENCE ON INFORMATION TECHNOLOGY (WCIT-2010), 2011, 3
  • [3] Software security analysis and assessment model for the web-based applications
    Wang, Y.
    Lively, W. M.
    Simmons, D. B.
    [J]. JOURNAL OF COMPUTATIONAL METHODS IN SCIENCES AND ENGINEERING, 2009, 9 (01) : S179 - S189
  • [4] Say Aloha to web-based security
    Anon
    [J]. Marine Log, 2002, 107 (05)
  • [5] Study on Security of Web-based Database
    Zhao, Qing
    Qin, Shihong
    [J]. PACIIA: 2008 PACIFIC-ASIA WORKSHOP ON COMPUTATIONAL INTELLIGENCE AND INDUSTRIAL APPLICATION, VOLS 1-3, PROCEEDINGS, 2008, : 1853 - 1856
  • [6] Security models for Web-based applications
    Joshi, JBD
    Aref, WG
    Ghafoor, A
    Spafford, EH
    [J]. COMMUNICATIONS OF THE ACM, 2001, 44 (02) : 38 - 44
  • [7] Data security for Web-based CAD
    Hauck, S
    Knol, S
    [J]. 1998 DESIGN AUTOMATION CONFERENCE, PROCEEDINGS, 1998, : 788 - 793
  • [8] Web-based communication in palliative care
    Stenekes, Simone
    Harlos, Mike
    Chochinov, Harvey Max
    [J]. JOURNAL OF PALLIATIVE CARE, 2007, 23 (03) : 191 - 191
  • [9] Web-based systems for communication and scheduling
    ElAarag, H
    Hartford, R
    [J]. IPCC 2003 PROCEEDINGS, THE SHAPE OF KNOWLEDGE, 2003, : 201 - 208
  • [10] Web-based hazard communication is piloted
    不详
    [J]. CHEMICAL ENGINEERING, 1997, 104 (07) : 153 - 153