A Security Model for Web-Based Communication

被引:0
|
作者
Tehrani, Pouyan Fotouhi [1 ]
Osterweil, Eric [2 ]
Schmidt, Thomas C. [3 ]
Waehlisch, Matthias [4 ]
机构
[1] Weizenbaum Inst Fraunhofer FOKUS, Berlin, Germany
[2] George Mason Univ, Fairfax, VA USA
[3] HAW Hamburg, Hamburg, Germany
[4] Tech Univ Dresden, Dresden, Germany
关键词
Websites;
D O I
10.1145/3623292
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Web access involves various protocols to resolve domain names to IP addresses, establish data exchange channels with Web servers, and to authenticate communication partners. Each protocol has its own set of requirements and security measures. In addition to technical features, operating the Web also introduces organizational and political aspects which are important to consider when deploying a secure basis for Web-based communication.In this paper, we propose an algorithmic security model based on the widely deployed technologies DNSSEC and Web PKI to cover three dimensions: identification, resolu-tion, and transaction. Our model enables quantification and qualification of the security assurance provided by an online service provider. To verify the applicability of our model, we investigate the online presence of Alerting Au-thorities in the U.S., selected German Emergency Serviceproviders, and UN member states. We observe partially en-hanced security relative to global Internet trends, yet find cause for concern as only about 6% of unique hosts cater to secure resolution. About 46% of investigated organizations use shared certificates with 1% of all organizations having no or invalid certificates. Two thirds of organizations are not uniquely identifiable and as such lack the basic require-ment of trustworthy communication
引用
收藏
页码:83 / 90
页数:8
相关论文
共 50 条
  • [31] Home security system in a web-based networking environment
    Chang, Kyung-Bae
    Kim, Jae-Woo
    Shim, Il-Joo
    Park, Gwi-Tae
    ADVANCES IN COMPUTATIONAL METHODS IN SCIENCES AND ENGINEERING 2005, VOLS 4 A & 4 B, 2005, 4A-4B : 1613 - 1616
  • [32] Web-based security constrained unit commitment system
    Risteiu, Mircea
    Sturgul, John
    Ileana, Loan
    2006 IEEE-TTTC INTERNATIONAL CONFERENCE ON AUTOMATION, QUALITY AND TESTING, ROBOTICS, VOL 1, PROCEEDINGS, 2006, : 370 - +
  • [33] Challenges of Web-based Information Security Knowledge Sharing
    Feledi, Daniel
    Fenz, Stefan
    2012 SEVENTH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES), 2012, : 514 - 521
  • [34] Reliability, compliance, and security in web-based course assessments
    Bonham, Scott
    PHYSICAL REVIEW SPECIAL TOPICS-PHYSICS EDUCATION RESEARCH, 2008, 4 (01):
  • [35] Towards semantic web-based management of security services
    Garcia Clemente, Felix J.
    Martinez Perez, Gregorio
    Munoz Ortega, Andres
    Botia, Juan A.
    Gomez Skarmeta, Antonio F.
    ANNALS OF TELECOMMUNICATIONS, 2008, 63 (3-4) : 183 - 193
  • [36] Security Design of Web-based Information Integrated System
    Chen, Tao
    Pan, Hai-peng
    ADVANCED DESIGNS AND RESEARCHES FOR MANUFACTURING, PTS 1-3, 2013, 605-607 : 2341 - 2344
  • [37] Security methods for web-based applications on embedded system
    Maharak, C
    Sowanwanichakul, B
    TENCON 2004 - 2004 IEEE REGION 10 CONFERENCE, VOLS A-D, PROCEEDINGS: ANALOG AND DIGITAL TECHNIQUES IN ELECTRICAL ENGINEERING, 2004, : C56 - C59
  • [38] A Decentralized Security Framework for Web-Based Social Networks
    Carminati, Barbara
    Ferrari, Elena
    Perego, Andrea
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY AND PRIVACY, 2008, 2 (04) : 22 - 53
  • [39] Security in collaborative multimedia web-based art projects
    Koukopoulos D.K.
    Styliaras G.D.
    Journal of Multimedia, 2010, 5 (05): : 404 - 416
  • [40] Integrative security management for web-based enterprise applications
    Zhao, C
    Chen, Y
    Xu, DW
    Heilili, NM
    Lin, ZQ
    ADVANCES IN WEB-AGE INFORMATION MANAGEMENT, PROCEEDINGS, 2005, 3739 : 618 - 625