A Security Model for Web-Based Communication

被引:0
|
作者
Tehrani, Pouyan Fotouhi [1 ]
Osterweil, Eric [2 ]
Schmidt, Thomas C. [3 ]
Waehlisch, Matthias [4 ]
机构
[1] Weizenbaum Inst Fraunhofer FOKUS, Berlin, Germany
[2] George Mason Univ, Fairfax, VA USA
[3] HAW Hamburg, Hamburg, Germany
[4] Tech Univ Dresden, Dresden, Germany
关键词
Websites;
D O I
10.1145/3623292
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Web access involves various protocols to resolve domain names to IP addresses, establish data exchange channels with Web servers, and to authenticate communication partners. Each protocol has its own set of requirements and security measures. In addition to technical features, operating the Web also introduces organizational and political aspects which are important to consider when deploying a secure basis for Web-based communication.In this paper, we propose an algorithmic security model based on the widely deployed technologies DNSSEC and Web PKI to cover three dimensions: identification, resolu-tion, and transaction. Our model enables quantification and qualification of the security assurance provided by an online service provider. To verify the applicability of our model, we investigate the online presence of Alerting Au-thorities in the U.S., selected German Emergency Serviceproviders, and UN member states. We observe partially en-hanced security relative to global Internet trends, yet find cause for concern as only about 6% of unique hosts cater to secure resolution. About 46% of investigated organizations use shared certificates with 1% of all organizations having no or invalid certificates. Two thirds of organizations are not uniquely identifiable and as such lack the basic require-ment of trustworthy communication
引用
收藏
页码:83 / 90
页数:8
相关论文
共 50 条
  • [1] Web-based construction project communication model
    Tai, SL
    Liu, RH
    Proceedings of 2005 International Conference on Construction & Real Estate Management, Vols 1 and 2: CHALLENGE OF INNOVATION IN CONSTRUCTION AND REAL ESTATE, 2005, : 374 - 376
  • [2] Secure web-based communication
    Mir, Nighat
    Hussain, Sayed Afaq
    WORLD CONFERENCE ON INFORMATION TECHNOLOGY (WCIT-2010), 2011, 3
  • [3] Software security analysis and assessment model for the web-based applications
    Wang, Y.
    Lively, W. M.
    Simmons, D. B.
    JOURNAL OF COMPUTATIONAL METHODS IN SCIENCES AND ENGINEERING, 2009, 9 (01) : S179 - S189
  • [4] Say Aloha to web-based security
    Anon
    Marine Log, 2002, 107 (05)
  • [5] Study on Security of Web-based Database
    Zhao, Qing
    Qin, Shihong
    PACIIA: 2008 PACIFIC-ASIA WORKSHOP ON COMPUTATIONAL INTELLIGENCE AND INDUSTRIAL APPLICATION, VOLS 1-3, PROCEEDINGS, 2008, : 1853 - 1856
  • [6] Security models for Web-based applications
    Joshi, JBD
    Aref, WG
    Ghafoor, A
    Spafford, EH
    COMMUNICATIONS OF THE ACM, 2001, 44 (02) : 38 - 44
  • [7] Data security for Web-based CAD
    Hauck, S
    Knol, S
    1998 DESIGN AUTOMATION CONFERENCE, PROCEEDINGS, 1998, : 788 - 793
  • [8] Web-based communication in palliative care
    Stenekes, Simone
    Harlos, Mike
    Chochinov, Harvey Max
    JOURNAL OF PALLIATIVE CARE, 2007, 23 (03) : 191 - 191
  • [9] Web-based systems for communication and scheduling
    ElAarag, H
    Hartford, R
    IPCC 2003 PROCEEDINGS, THE SHAPE OF KNOWLEDGE, 2003, : 201 - 208
  • [10] Web-based hazard communication is piloted
    不详
    CHEMICAL ENGINEERING, 1997, 104 (07) : 153 - 153