Access Control Architecture Separating Privilege by a Thread on a Web Server

被引:0
|
作者
Matsumoto, Ryosuke [1 ]
Okabe, Yasuo [2 ]
机构
[1] Kyoto Univ, Grad Sch Informat, Sakyo Ku, Kyoto 6068501, Japan
[2] Kyoto Univ, Acad Ctr Comp & Media Studies, Kyoto 6068501, Japan
关键词
Security in a Server; Web Server; Access Control; Runtime Privilege;
D O I
10.1109/SAINT.2012.33
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In Web hosting services, hosting systems use access controls like suEXEC on apache Web servers to separate privilege by each virtual host. However, existing access control architectures on Web servers have a problem in their low performance and are not appropriate for dynamic contents like Web API since these architectures require termination of the process after each HTTP session. System developers are not easy to install existing access controls since these are provided by each interpreter and program execution methods conventionally. In this paper, we propose the access control architecture "mod_process_security". In this architecture a server process creates a new thread on the server process when accepting a request. Then, the web server separates privilege by the thread and processes the contents on the thread. The server process installed "mod_process_security" executes programs faster. System developers can easily install it on web servers since we replace it with the complicated existing access controls. "mod_process_security" can be installed for Apache HTTP Server on Linux as Apache Module which is widely used.
引用
收藏
页码:178 / 183
页数:6
相关论文
共 50 条
  • [1] Feedback control with prediction for thread allocation in pipeline architecture Web server
    Peng Shao-Liang
    Li Shan-Shan
    Liao Xiang-Ke
    Peng Yu-Xing
    Ye Hui
    DISTRIBUTED COMPUTING AND NETWORKING, PROCEEDINGS, 2006, 4308 : 454 - 465
  • [2] Performance Analysis of a Web Server with Dynamic Thread Pool Architecture
    Lu, Jijun
    Gokhale, Swapna S.
    22ND INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING & KNOWLEDGE ENGINEERING (SEKE 2010), 2010, : 99 - 105
  • [3] Access control architecture for web services
    Yuan, SJ
    Hu, YF
    GRID AND COOPERATIVE COMPUTING, PT 1, 2004, 3032 : 1004 - 1007
  • [4] Open architecture design of embedded web server for control applications
    Chen, Cheng-Yi
    Lee, Chien-Hua
    Cheng, Marvin H.
    ICIC Express Letters, 2011, 5 (8 A): : 2471 - 2478
  • [5] A trusted decentralized access control framework for the client/server architecture
    Han, Weili
    Xu, Min
    Zhao, Weidong
    Li, Guofu
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2010, 33 (02) : 76 - 83
  • [6] Secure Web server based on resource access control mechanism
    Wang, Tao
    Qing, Sihan
    Liu, Haifeng
    Jisuanji Gongcheng/Computer Engineering, 2003, 29 (15):
  • [7] A Scalable Web Server Architecture
    Belloum A.S.Z.
    Kaletas E.C.
    van Halderen A.W.
    Afsarmanesh H.
    Hertzberger L.O.
    Peddemors A.J.H.
    World Wide Web, 2002, 5 (1) : 5 - 23
  • [8] Architecture of a Web server accelerator
    Song, J
    Iyengar, A
    Levy-Abegnoli, E
    Dias, D
    COMPUTER NETWORKS-THE INTERNATIONAL JOURNAL OF COMPUTER AND TELECOMMUNICATIONS NETWORKING, 2002, 38 (01): : 75 - 97
  • [9] Data Lake Architecture for Storing and Transforming Web Server Access Log Files
    Zagan, Elisabeta
    Danubianu, Mirela
    IEEE ACCESS, 2023, 11 : 40916 - 40929
  • [10] Dynamic thread assignment in web server performance optimization
    van der Weij, Wemke
    Bhulai, Sandjai
    van der Mei, Rob
    PERFORMANCE EVALUATION, 2009, 66 (06) : 301 - 310