A Security Model for Web-Based Communication

被引:0
|
作者
Tehrani, Pouyan Fotouhi [1 ]
Osterweil, Eric [2 ]
Schmidt, Thomas C. [3 ]
Waehlisch, Matthias [4 ]
机构
[1] Weizenbaum Inst Fraunhofer FOKUS, Berlin, Germany
[2] George Mason Univ, Fairfax, VA USA
[3] HAW Hamburg, Hamburg, Germany
[4] Tech Univ Dresden, Dresden, Germany
关键词
Websites;
D O I
10.1145/3623292
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Web access involves various protocols to resolve domain names to IP addresses, establish data exchange channels with Web servers, and to authenticate communication partners. Each protocol has its own set of requirements and security measures. In addition to technical features, operating the Web also introduces organizational and political aspects which are important to consider when deploying a secure basis for Web-based communication.In this paper, we propose an algorithmic security model based on the widely deployed technologies DNSSEC and Web PKI to cover three dimensions: identification, resolu-tion, and transaction. Our model enables quantification and qualification of the security assurance provided by an online service provider. To verify the applicability of our model, we investigate the online presence of Alerting Au-thorities in the U.S., selected German Emergency Serviceproviders, and UN member states. We observe partially en-hanced security relative to global Internet trends, yet find cause for concern as only about 6% of unique hosts cater to secure resolution. About 46% of investigated organizations use shared certificates with 1% of all organizations having no or invalid certificates. Two thirds of organizations are not uniquely identifiable and as such lack the basic require-ment of trustworthy communication
引用
收藏
页码:83 / 90
页数:8
相关论文
共 50 条
  • [11] An effective communication model for collaborative commerce of web-based surveillance services
    Wang, CH
    Chang, RI
    Ho, JM
    IEEE INTERNATIONAL CONFERENCE ON E-COMMERCE, 2003, : 40 - 44
  • [12] Rethinking Security of Web-Based System Applications
    Georgiev, Martin
    Jana, Suman
    Shmatikov, Vitaly
    PROCEEDINGS OF THE 24TH INTERNATIONAL CONFERENCE ON WORLD WIDE WEB (WWW 2015), 2015, : 366 - 376
  • [13] Implementing security in a distributed web-based EHCR
    Sucurovic, Snezana
    INTERNATIONAL JOURNAL OF MEDICAL INFORMATICS, 2007, 76 (5-6) : 491 - 496
  • [14] Retrofitting security into a Web-based information system
    da Cruz, DB
    Rumpe, B
    Wimmel, G
    WEB ENGINEERING, PROCEEDINGS, 2003, 2722 : 301 - 305
  • [15] Security Concerns for Web-based Research Survey
    Hailu, Alemayehu
    Rahman, Syed M.
    2012 7TH INTERNATIONAL CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING (ICECE), 2012,
  • [16] Web-based programming model
    Anastasiu, Doru Popescu
    Boroghina, Gabriel
    2015 6TH INTERNATIONAL CONFERENCE ON MODELING, SIMULATION, AND APPLIED OPTIMIZATION (ICMSAO), 2015,
  • [17] Lightweight Web-based Communication Interface Design For Web of Objects
    An, Sanghong
    Park, Sangmin
    Oh, Hyeontaek
    Yang, Jinhong
    Park, Hyojin
    Choi, Junkyun
    2013 15TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT), 2013, : 535 - 539
  • [18] A Web-based communication aid for patients with cancer
    Meropol, Neal J.
    Egleston, Brian L.
    Buzaglo, Joanne S.
    Balshem, Andrew
    Benson, Al B., III
    Cegala, Donald J.
    Cohen, Roger B.
    Collins, Michael
    Diefenbach, Michael A.
    Miller, Suzanne M.
    Fleisher, Linda
    Millard, Jennifer L.
    Ross, Eric A.
    Schulman, Kevin A.
    Silver, Allison
    Slater, Elyse
    Solarino, Nicholas
    Sulmasy, Daniel P.
    Trinastic, Jonathan
    Weinfurt, Kevin P.
    CANCER, 2013, 119 (07) : 1437 - 1445
  • [19] Web-based chatting: Consumer communication in cyberspace
    Zinkhan, GM
    Kwak, H
    Morrison, M
    Peters, CO
    JOURNAL OF CONSUMER PSYCHOLOGY, 2003, 13 (1-2) : 17 - 27
  • [20] ACT: A web-based adaptive communication tool
    Gogoulou, Agoritsa
    Gouli, Evangelia
    Grigoriadou, Maria
    Samarakou, Maria
    CSCL 2005: COMPUTER SUPPORTED COLLABORATIVE LEARNING 2005: THE NEXT 10 YEARS, PROCEEDINGS, 2005, : 180 - 189