Access Control Architecture Separating Privilege by a Thread on a Web Server

被引:0
|
作者
Matsumoto, Ryosuke [1 ]
Okabe, Yasuo [2 ]
机构
[1] Kyoto Univ, Grad Sch Informat, Sakyo Ku, Kyoto 6068501, Japan
[2] Kyoto Univ, Acad Ctr Comp & Media Studies, Kyoto 6068501, Japan
关键词
Security in a Server; Web Server; Access Control; Runtime Privilege;
D O I
10.1109/SAINT.2012.33
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In Web hosting services, hosting systems use access controls like suEXEC on apache Web servers to separate privilege by each virtual host. However, existing access control architectures on Web servers have a problem in their low performance and are not appropriate for dynamic contents like Web API since these architectures require termination of the process after each HTTP session. System developers are not easy to install existing access controls since these are provided by each interpreter and program execution methods conventionally. In this paper, we propose the access control architecture "mod_process_security". In this architecture a server process creates a new thread on the server process when accepting a request. Then, the web server separates privilege by the thread and processes the contents on the thread. The server process installed "mod_process_security" executes programs faster. System developers can easily install it on web servers since we replace it with the complicated existing access controls. "mod_process_security" can be installed for Apache HTTP Server on Linux as Apache Module which is widely used.
引用
收藏
页码:178 / 183
页数:6
相关论文
共 50 条
  • [31] Analyzing and Visualizing Web Server Access Log File
    Minh-Tri Nguyen
    Thanh-Dang Diep
    Tran Hoang Vinh
    Nakajima, Takuma
    Nam Thoai
    FUTURE DATA AND SECURITY ENGINEERING, FDSE 2018, 2018, 11251 : 349 - 367
  • [32] Embedded Web Server based NetLab for Remote Access
    Siddiqui, Masarrat Husain
    Purohit, Vijay
    Mane, Satendra
    2016 INTERNATIONAL CONFERENCE ON INVENTIVE COMPUTATION TECHNOLOGIES (ICICT), VOL 3, 2015, : 157 - 161
  • [33] The Connectivity Server: fast access to linkage information on the Web
    Bharat, K
    Broder, A
    Henzinger, M
    Kumar, P
    Venkatasubramanian, S
    COMPUTER NETWORKS AND ISDN SYSTEMS, 1998, 30 (1-7): : 469 - 477
  • [34] A message server architecture to improve the reliability of web service
    Jung, YH
    Kim, H
    Kim, H
    Choi, Y
    Lee, B
    7TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY, VOLS 1 AND 2, PROCEEDINGS, 2005, : 538 - 542
  • [35] OPC-based architecture of Embedded Web Server
    Jia, ZP
    Li, X
    EMBEDDED SOFTWARE AND SYSTEMS, 2005, 3605 : 362 - 367
  • [36] Integrated Web server technology for control
    不详
    HYDROCARBON PROCESSING, 1999, 78 (01): : 41 - +
  • [37] Users Access Discrimination and Remote Control Study of Embedded System using Mini Web Server
    Mun, Yihyeong
    Cho, Dongsub
    ALPIT 2008: SEVENTH INTERNATIONAL CONFERENCE ON ADVANCED LANGUAGE PROCESSING AND WEB INFORMATION TECHNOLOGY, PROCEEDINGS, 2008, : 341 - 346
  • [38] Web document Access Control using two-layered storage structures with RBAC server
    Shim, WB
    Park, S
    EURASIA-ICT 2002: INFORMATION AND COMMUNICATION TECHNOLOGY, PROCEEDINGS, 2002, 2510 : 220 - 227
  • [39] An Architecture for Enforcing End-to-End Access Control Over Web Applications
    Hicks, Boniface
    Rueda, Sandra
    King, Dave
    Moyer, Thomas
    Schiffman, Joshua
    Sreenivasan, Yogesh
    McDaniel, Patrick
    Jaeger, Trent
    SACMAT 2010: PROCEEDINGS OF THE 15TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2010, : 163 - 172
  • [40] An intelligent access control for web services based on Service Oriented Architecture platform
    Yu, Weider D.
    FOURTH IEEE WORKSHOP ON SOFTWARE TECHNOLOGIES FOR FUTURE EMBEDDED AND UBIQUITOUS SYSTEMS AND THE SECOND INTERNATIONAL WORKSHOP ON COLLABORATIVE COMPUTING, INTEGRATION, AND ASSURANCE, PROCEEDINGS, 2006, : 190 - 195