AccessMyLibrary provides FREE access to over 30 million articles from top publications available through your library.

SECURITY MODELS FOR WEB-BASED APPLICATIONS.(Internet/Web/Online Service Information)

Communications of the ACM

| February 01, 2001 | Joshi, James B.D.; Aref, Walid G.; Ghafoor, Arif; Spafford, Eugene H. | COPYRIGHT 2001 Association for Computing Machinery, Inc. This material is published under license from the publisher through the Gale Group, Farmington Hills, Michigan.  All inquiries regarding rights should be directed to the Gale Group. (Hide copyright information)Copyright

Using traditional and emerging access control approached to develop secure applications far the Web.

THE RAPID PROLIFERATION of the Internet and the cost-effective growth of its key enabling technologies are revolutionizing information technology and creating unprecedented opportunities for developing large-scale distributed applications. At the same time, there is a growing concern over the security of Web-based applications, which are rapidly being deployed over the Internet [4]. For example, e-commerce--the leading Web-based application--is projected to have a market exceeding $1 trillion over the next several years. However, this application has already become a security nightmare for both customers and business enterprises as indicated by the recent episodes involving unauthorized access to credit card information. Other leading Web-based applications with considerable information security and privacy issues include telemedicine-based health-care services and online services or businesses involving both public and private sectors. Many of these applications are supported by workflow management systems (WFMSs) [1]. A large number of public and private enterprises are in the forefront of adopting Internet-based WFMSs and finding ways to improve their services and decision-making processes, hence we are faced with the daunting challenge of ensuring the security and privacy of information in such Web-based applications [4].

Typically, a Web-based application can be represented as a three-tier architecture, depicted in the figure, which includes a Web client, network servers, and a back-end information system supported by a suite of databases. For transaction-oriented applications, such as e-commerce, middleware is usually provided between the network servers and back-end systems to ensure proper interoperability. Considerable security challenges and vulnerabilities exist within each component of this architecture. Existing public-key infrastructures (PKIs) provide encryption mechanisms for ensuring information confidentiality, as well as digital signature techniques for authentication, data integrity and non-repudiation [11]. As no access authorization services are provided in this approach, it has a rather limited scope for Web-based applications.

The strong need for information security on the Internet is attributable to several factors, including the massive interconnection of heterogeneous and distributed systems, the availability of high volumes of sensitive information at the end systems maintained by corporations and government agencies, easy distribution of automated malicious software by malfeasors, the ease with which computer crimes can be committed anonymously from across geographic boundaries, and the lack of forensic evidence in computer crimes, which makes the detection and prosecution of criminals extremely difficult.

Two classes of services are crucial for a secure Internet infrastructure. These include access control services and communication security services. Access control services protect Internet resources from unauthorized use, whereas communication security services ensure confidentiality and integrity of data transmitted over the network, in addition to nonrepudiation of services to the communicating entities. An important prerequisite for access control is user authentication, the process that establishes the identity of a user. In the context of the Internet, we assume authentication is handled communication security services.

Security in the Web Environment

End users are exposed to several security and privacy risks when using Web browsers, and browser vulnerabilities can result in compromising the security of a Web client [4]. Information about a user such as login name or machine name can be collected and used to profile the user, thus raising serious privacy concerns. Cookies, the data stored on the client's machine and exchanged between the Web client and the Web server to maintain connection information, can be used for the purpose of gathering such information. A source of vulnerability at the client site also comes from the use of executable content on the Web, such as Java applets, ActiveX controls, and the like. The current improvement in JDK1.2, which allows signed applets, requires the client to use a security policy for downloadable applets. Many sites also use push technology to deliver Web content to clients. This process can result in serious security breaches, as the content provider can exploit browser vulnerabilities by sending malicious executable code or by overwhelming the system by pushing a high volume of information.

Related articles from newspapers, magazines, journals, and more
Research and Markets: Web-Based Applications Case Studies Analysis.
Press release article from: Business Wire December 7, 2004 700+ words
...announced the addition of Web-Based Applications Case Studies Analysis to...from the deployment of Web-based applications by companies operating...considered when evaluating Web-based applications, how they chose to deploy...
Software automates terminal-based testing techniques.(IBM Rational Functional...
Magazine article from: Product News Network December 19, 2005 700+ words
...iSeries(TM)) terminal-based applications. This extension tool is...testing of their terminal-based applications with the same tool they use to test their Java(TM) and Web-based applications. Highlights of this release...
Software is used for MS .NET Framework-based applications.(CA Releases Wily...
Magazine article from: Product News Network November 10, 2006 700+ words
...users to monitor .NET Framework-based applications and components continuously in production...Capabilities to .NET Framework-Based Applications ISLANDIA, N.Y., Oct. 24...mission-critical .NET Framework-based applications and components continuously in production...
NEOS Offers Conversion Path for Character-Based Applications.
Press release article from: PR Newswire July 6, 2005 700+ words
...conversion path for character-based applications using Oracle(R) Application...conversion option for character-based applications via its Vgo4Oracle(TM...move from these character-based applications should also be thinking...mberg@neosllc.com Web site: http://www...
SilverStream Software Enables the Deployment of J2EE and Web Services-Based...
Press release article from: Business Wire May 29, 2001 700+ words
...announced that J2EE and Web Services-based applications built with SilverStream...to deploy J2EE and Web Services-based applications using SilverStream...to deploy J2EE and Web Services-based applications on Itanium-based...
MyInternetDesktop.com Web-based Applications Offer 100 Mb Virtual Hard Drive...
Press release article from: Business Wire April 5, 2000 700+ words
...distribution and use of web-based applications via Internet connected...MyInternetDesktop.com web-based applications are now available to WebTV...provides users with free web-based applications for business and personal...
Software offers Web-based applications for TIFM.(ARCHIBUS, Inc. Extends Range...
Magazine article from: Product News Network November 30, 2005 700+ words
...TIFM) software provides 3 Web-based applications. First aids in collaborative...release provides three new Web-based applications: Project Management...Management. "These new Web-based applications expand the breadth of the...
Web-based applications and industrial mobile devices--a good marriage? The best...
Magazine article from: Wireless Design & Development Cichosz, Jay November 1, 2006 700+ words
...does not lessen the value of today's Web-based solutions. Web-based applications are easier to maintain, run on less expensive...believe could fit into a single Starbucks! Web-based applications are ubiquitous and inevitably they will...
AppStream Introduces Breakthrough Technology for Streaming Java...
Press release article from: Business Wire September 25, 2000 700+ words
...Deliver Java(TM) Technology-Based Applications to Next Generation Mobile Phones...dynamic Java(TM) technology-based applications to mobile phones. LG TeleCom will...to sophisticated Java technology-based applications on their mobile phones. "Limited...
Wireless Subscribers Download More Than 50 Million BREW(TM)-Based Applications;...
Press release article from: PR Newswire October 20, 2003 700+ words
...downloaded more than 50 million BREW-based applications since BREW- enabled products and...deliver demand-driven, BREW-based applications." "The accomplishment is also...number of unique downloads of BREW-based applications. The figure does not take into account...
For more facts and information, see all results
©2009 Gale, a part of Cengage Learning. All rights reserved.
About us | FAQs | Contact us | Privacy policy | Terms and conditions
Other Gale sites: Encyclopedia.com | HighBeam Research | Acquire Content | Books & Authors | Goliath | MovieRetriever | Smart QandA