A Security Model for Web-Based Communication

被引:0
|
作者
Tehrani, Pouyan Fotouhi [1 ]
Osterweil, Eric [2 ]
Schmidt, Thomas C. [3 ]
Waehlisch, Matthias [4 ]
机构
[1] Weizenbaum Inst Fraunhofer FOKUS, Berlin, Germany
[2] George Mason Univ, Fairfax, VA USA
[3] HAW Hamburg, Hamburg, Germany
[4] Tech Univ Dresden, Dresden, Germany
关键词
Websites;
D O I
10.1145/3623292
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Web access involves various protocols to resolve domain names to IP addresses, establish data exchange channels with Web servers, and to authenticate communication partners. Each protocol has its own set of requirements and security measures. In addition to technical features, operating the Web also introduces organizational and political aspects which are important to consider when deploying a secure basis for Web-based communication.In this paper, we propose an algorithmic security model based on the widely deployed technologies DNSSEC and Web PKI to cover three dimensions: identification, resolu-tion, and transaction. Our model enables quantification and qualification of the security assurance provided by an online service provider. To verify the applicability of our model, we investigate the online presence of Alerting Au-thorities in the U.S., selected German Emergency Serviceproviders, and UN member states. We observe partially en-hanced security relative to global Internet trends, yet find cause for concern as only about 6% of unique hosts cater to secure resolution. About 46% of investigated organizations use shared certificates with 1% of all organizations having no or invalid certificates. Two thirds of organizations are not uniquely identifiable and as such lack the basic require-ment of trustworthy communication
引用
收藏
页码:83 / 90
页数:8
相关论文
共 50 条
  • [41] Web-based security cost analysis in electricity markets
    Chen, H
    Cañizares, CA
    Singh, A
    IEEE TRANSACTIONS ON POWER SYSTEMS, 2005, 20 (02) : 659 - 667
  • [42] A model for a web-based learning system
    Carchiolo, Vincenza
    Longheu, Alessandro
    Malgeri, Michele
    Mangioni, Giuseppe
    INFORMATION SYSTEMS FRONTIERS, 2007, 9 (2-3) : 267 - 282
  • [43] A model for a web-based learning system
    Vincenza Carchiolo
    Alessandro Longheu
    Michele Malgeri
    Giuseppe Mangioni
    Information Systems Frontiers, 2007, 9 : 267 - 282
  • [44] An Evaluation Model for Web-Based Instruction
    Jun, Woochun
    Gruenwald, Le
    IEEE TRANSACTIONS ON EDUCATION, 2001, 44 (02) : 205 - 205
  • [45] The Model of Web-based Crowdfunding Platform
    Maryani
    Perbangsa, Anzaludin Samsinga
    Udiono, Tangkas
    PROCEEDINGS OF 2020 INTERNATIONAL CONFERENCE ON INFORMATION MANAGEMENT AND TECHNOLOGY (ICIMTECH), 2020, : 957 - 961
  • [46] Web-based diagnosis of model specifications
    Derrick, EJ
    1998 WINTER SIMULATION CONFERENCE PROCEEDINGS, VOLS 1 AND 2, 1998, : 1703 - 1706
  • [47] Mechatronic Web-based tutorial model
    Tolkemit, B.
    Buchheim, J.
    VDI Berichte, 2001, (1631): : 197 - 215
  • [48] Web-based mesoscale model computing
    Kirby, S
    Yee, Y
    Henmi, T
    Haines, P
    IC'2001: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON INTERNET COMPUTING, VOLS I AND II, 2001, : 684 - 688
  • [49] Accessible Golf Courses: Web-Based Accommodation Communication
    Wanless, Elizabeth A.
    Petersen, Jeffrey C.
    Pursglove, Lindsay K.
    Desmond, Logan
    Judge, Lawrence W.
    PHYSICAL EDUCATOR-US, 2018, 75 (05): : 816 - 834
  • [50] Creating a web-based incident analysis and communication system
    Marsal, Scott
    Heffner, John E.
    JOURNAL OF HOSPITAL MEDICINE, 2012, 7 (02) : 142 - 147