Access Control Architecture Separating Privilege by a Thread on a Web Server

被引:0
|
作者
Matsumoto, Ryosuke [1 ]
Okabe, Yasuo [2 ]
机构
[1] Kyoto Univ, Grad Sch Informat, Sakyo Ku, Kyoto 6068501, Japan
[2] Kyoto Univ, Acad Ctr Comp & Media Studies, Kyoto 6068501, Japan
关键词
Security in a Server; Web Server; Access Control; Runtime Privilege;
D O I
10.1109/SAINT.2012.33
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In Web hosting services, hosting systems use access controls like suEXEC on apache Web servers to separate privilege by each virtual host. However, existing access control architectures on Web servers have a problem in their low performance and are not appropriate for dynamic contents like Web API since these architectures require termination of the process after each HTTP session. System developers are not easy to install existing access controls since these are provided by each interpreter and program execution methods conventionally. In this paper, we propose the access control architecture "mod_process_security". In this architecture a server process creates a new thread on the server process when accepting a request. Then, the web server separates privilege by the thread and processes the contents on the thread. The server process installed "mod_process_security" executes programs faster. System developers can easily install it on web servers since we replace it with the complicated existing access controls. "mod_process_security" can be installed for Apache HTTP Server on Linux as Apache Module which is widely used.
引用
收藏
页码:178 / 183
页数:6
相关论文
共 50 条
  • [21] Embedded Web server Architecture For Mobile Phone
    Wang ZhenXing
    Shi LinXiang
    Wei ShuTao
    INTERNATIONAL CONFERENCE ON FUTURE NETWORKS, PROCEEDINGS, 2009, : 208 - 211
  • [22] The content and access dynamics of a busy Web server
    Padmanabhan, VN
    Qiu, LI
    PERFORMANCE EVALUATION REVIEW, SPECIAL ISSUE, VOL 28 NO 1, JUNE 2000: ACM SIGMETRICS '2000, PROCEEDINGS, 2000, 28 (01): : 122 - 123
  • [23] Secure remote access to an internal Web server
    Gilmore, C
    Kormann, D
    Rubin, AD
    IEEE NETWORK, 1999, 13 (06): : 31 - 37
  • [24] Extensible embedded web server architecture for Internet-based data acquisition and control
    Klimchynski, Igor
    IEEE SENSORS JOURNAL, 2006, 6 (03) : 804 - 811
  • [25] Privacy-enhanced SPKI access control on PKIX and its application to web server
    Saito, T
    Umesawa, K
    Kito, T
    Okuno, HG
    AINA 2003: 17TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS, 2003, : 696 - 703
  • [26] Automatically Reducing Privilege for Access Control Policies
    D'Antoni, Loris
    Ding, Shuo
    Goel, Amit
    Ramesh, Mathangi
    Rungta, Neha
    Sung, Chungha
    Proceedings of the ACM on Programming Languages, 2024, 8 (OOPSLA2)
  • [27] Discretionary overriding of access control in the privilege calculus
    Rissanen, E
    Firozabadi, BS
    Sergot, M
    FORMAL ASPECTS IN SECURITY AND TRUST, 2005, 173 : 219 - 232
  • [28] Improving web cache server performance through arbitral thread and delayed caching
    Lee, Daesung
    Kim, Kuinam J.
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2012, 15 (01): : 17 - 25
  • [29] Improving web cache server performance through arbitral thread and delayed caching
    Daesung Lee
    Kuinam J. Kim
    Cluster Computing, 2012, 15 : 17 - 25
  • [30] From a Master Server Architecture to a Feedback Control Architecture
    Alaya, Bechir
    Duvallet, Claude
    Sadeg, Bruno
    EUROPEAN SIMULATION AND MODELLING CONFERENCE 2008, 2008, : 566 - 572