A Security Model for Web-Based Communication

被引:0
|
作者
Tehrani, Pouyan Fotouhi [1 ]
Osterweil, Eric [2 ]
Schmidt, Thomas C. [3 ]
Wählisch, Matthias [4 ]
机构
[1] Weizenbaum Institute / Fraunhofer FOKUS, Berlin,60272635, Germany
[2] George Mason University, Fairfax,VA,60018319, United States
[3] HAW Hamburg, Hamburg,60032697, Germany
[4] TU Dresden, Dresden,60018353, Germany
关键词
Websites;
D O I
10.1145/3623292
中图分类号
学科分类号
摘要
Web access involves various protocols to resolve domain names to IP addresses, establish data exchange channels with Web servers, and to authenticate communication partners. Each protocol has its own set of requirements and security measures. In addition to technical features, operating the Web also introduces organizational and political aspects which are important to consider when deploying a secure basis for Web-based communication.In this paper, we propose an algorithmic security model based on the widely deployed technologies DNS(SEC) and Web PKI to cover the three dimensions identification, resolution, and transaction. Our model enables quantification and qualification of the security assurance provided by an online service provider. To verify the applicability of our model, we investigate the online presence of Alerting Authorities in the U.S., selected German Emergency Service providers, and UN member states. We observe partially enhanced security relative to global Internet trends, yet find cause for concern as only about 6% of unique hosts cater to secure resolution. About 46% of investigated organizations use shared certificates with 1% of all organizations having no or invalid certificates. Two thirds of organizations are not uniquely identifiable and as such lack the basic requirement of trustworthy communication. © 2024 ACM.
引用
收藏
页码:83 / 90
相关论文
共 50 条
  • [21] Web-based system for learning of communication protocols
    Komosny, Dan
    [J]. INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2006, 6 (9B): : 38 - 42
  • [22] Web-based communication and control for multiagent robots
    Hiraishi, H
    Ohwada, H
    Mizoguchi, F
    [J]. 1998 IEEE/RSJ INTERNATIONAL CONFERENCE ON INTELLIGENT ROBOTS AND SYSTEMS - PROCEEDINGS, VOLS 1-3: INNOVATIONS IN THEORY, PRACTICE AND APPLICATIONS, 1998, : 120 - 125
  • [23] A Web-Based Flexible Communication System in Radiology
    Rybkin, Alexander Valentine
    Wilson, Mark
    [J]. JOURNAL OF DIGITAL IMAGING, 2011, 24 (05) : 890 - 896
  • [24] A Web-based tutor for Internet communication protocols
    Santos, ETP
    Fialho, SV
    [J]. COMPUTER APPLICATIONS IN ENGINEERING EDUCATION, 2000, 8 (3-4) : 150 - 156
  • [25] A Web-Based Flexible Communication System in Radiology
    Alexander Valentine Rybkin
    Mark Wilson
    [J]. Journal of Digital Imaging, 2011, 24 : 890 - 896
  • [26] The Effects of Multimedia Communication on Web-Based Negotiation
    Yufei Yuan
    Milena Head
    Mei Du
    [J]. Group Decision and Negotiation, 2003, 12 : 89 - 109
  • [27] The effects of multimedia communication on Web-based negotiation
    Yuan, YF
    Head, M
    Du, M
    [J]. GROUP DECISION AND NEGOTIATION, 2003, 12 (02) : 89 - 109
  • [28] Towards semantic web-based management of security services
    Félix J. García Clemente
    Gregorio Martínez Pérez
    Andrés Muñoz Ortega
    Juan A. Botia
    Antonio F. Gómez Skarmeta
    [J]. annals of telecommunications - annales des télécommunications, 2008, 63 : 183 - 193
  • [29] Evaluation on security and privacy of web-based learning systems
    Chan, YY
    Leung, CH
    Liu, JK
    [J]. 3RD IEEE INTERNATIONAL CONFERENCE ON ADVANCED LEARNING TECHNOLOGIES, PROCEEDINGS, 2003, : 308 - 309
  • [30] Web-based security cost analysis in electricity markets
    Chen, H
    Canizares, C
    Singh, A
    [J]. 2005 IEEE POWER ENGINEERING SOCIETY GENERAL MEETING, VOLS, 1-3, 2005, : 2676 - 2676