AccessMyLibrary provides FREE access to over 30 million articles from top publications available through your library.

SECURITY MODELS FOR WEB-BASED APPLICATIONS.(Internet/Web/Online Service Information)

Communications of the ACM

| February 01, 2001 | Joshi, James B.D.; Aref, Walid G.; Ghafoor, Arif; Spafford, Eugene H. | COPYRIGHT 2001 Association for Computing Machinery, Inc. This material is published under license from the publisher through the Gale Group, Farmington Hills, Michigan.  All inquiries regarding rights should be directed to the Gale Group. (Hide copyright information)Copyright

Using traditional and emerging access control approached to develop secure applications far the Web.

THE RAPID PROLIFERATION of the Internet and the cost-effective growth of its key enabling technologies are revolutionizing information technology and creating unprecedented opportunities for developing large-scale distributed applications. At the same time, there is a growing concern over the security of Web-based applications, which are rapidly being deployed over the Internet [4]. For example, e-commerce--the leading Web-based application--is projected to have a market exceeding $1 trillion over the next several years. However, this application has already become a security nightmare for both customers and business enterprises as indicated by the recent episodes involving unauthorized access to credit card information. Other leading Web-based applications with considerable information security and privacy issues include telemedicine-based health-care services and online services or businesses involving both public and private sectors. Many of these applications are supported by workflow management systems (WFMSs) [1]. A large number of public and private enterprises are in the forefront of adopting Internet-based WFMSs and finding ways to improve their services and decision-making processes, hence we are faced with the daunting challenge of ensuring the security and privacy of information in such Web-based applications [4].

Typically, a Web-based application can be represented as a three-tier architecture, depicted in the figure, which includes a Web client, network servers, and a back-end information system supported by a suite of databases. For transaction-oriented applications, such as e-commerce, middleware is usually provided between the network servers and back-end systems to ensure proper interoperability. Considerable security challenges and vulnerabilities exist within each component of this architecture. Existing public-key infrastructures (PKIs) provide encryption mechanisms for ensuring information confidentiality, as well as digital signature techniques for authentication, data integrity and non-repudiation [11]. As no access authorization services are provided in this approach, it has a rather limited scope for Web-based applications.

The strong need for information security on the Internet is attributable to several factors, including the massive interconnection of heterogeneous and distributed systems, the availability of high volumes of sensitive information at the end systems maintained by corporations and government agencies, easy distribution of automated malicious software by malfeasors, the ease with which computer crimes can be committed anonymously from across geographic boundaries, and the lack of forensic evidence in computer crimes, which makes the detection and prosecution of criminals extremely difficult.

Two classes of services are crucial for a secure Internet infrastructure. These include access control services and communication security services. Access control services protect Internet resources from unauthorized use, whereas communication security services ensure confidentiality and integrity of data transmitted over the network, in addition to nonrepudiation of services to the communicating entities. An important prerequisite for access control is user authentication, the process that establishes the identity of a user. In the context of the Internet, we assume authentication is handled communication security services.

Related articles from newspapers, magazines, journals, and more
Web-Based Applications Case Studies Analysis.
Press release article from: M2 Presswire December 7, 2004 700+ words
...Research and Markets: Web-Based Applications Case Studies Analysis...announced the addition of Web-Based Applications Case Studies Analysis to...from the deployment of Web-based applications by companies operating...
Research and Markets: Web-Based Applications Case Studies Analysis.
Press release article from: Business Wire December 7, 2004 700+ words
...announced the addition of Web-Based Applications Case Studies Analysis to...from the deployment of Web-based applications by companies operating...considered when evaluating Web-based applications, how they chose to deploy...
NOVELL: Novell announces the next NetWare for e- e-business and web-based...
Press release article from: M2 Presswire November 9, 1999 700+ words
...NetWare for e-business and web-based applications (C)1994-99 M2 COMMUNICATIONS...server operating system to Web-based applications, management and resources...will now be coupled with Web-based applications, management and administration...
NEOS Offers Conversion Path for Character-Based Applications.
Press release article from: PR Newswire July 11, 2005 700+ words
...conversion path for character-based applications using Oracle(R) Application...conversion option for character-based applications via its Vgo4Oracle(TM...move from these character-based applications should also be thinking...mberg@neosllc.com Web site: http://www...
NOVELL: Novell announces the next NetWare for e- e-business and web-based...
Press release article from: M2 Presswire November 9, 1999 700+ words
...NetWare for e-business and web-based applications (C)1994-99 M2 COMMUNICATIONS...Server Operating System to Web-based Applications, Management and Resources...will now be coupled with Web-based applications, management and administration...
Novell Announces the Next NetWare for E-Business and Web-Based Applications.
Press release article from: PR Newswire November 8, 1999 700+ words
...Server Operating System to Web-Based Applications, Management and Resources...will now be coupled with Web-based applications, management and administration...platform for developing Web-based applications, Novell is partnering...
CA releases Wily Introscope for Microsoft .net CA's Wily Technology Extends...
Press release article from: M2 Presswire October 24, 2006 700+ words
...CapabilitiesTo .NET Framework-Based Applications (C)1994-2006 M2 COMMUNICATIONS...mission-critical .NET Framework-based applications and components continuously in production...capabilities to Microsoft .NET Framework-based applications, Wily enables IT staff to fully...
SilverStream Software Enables the Deployment of J2EE and Web Services-Based...
Press release article from: Business Wire May 29, 2001 700+ words
...announced that J2EE and Web Services-based applications built with SilverStream...to deploy J2EE and Web Services-based applications using SilverStream...to deploy J2EE and Web Services-based applications on Itanium-based...
For more facts and information, see all results
©2009 Gale, a part of Cengage Learning. All rights reserved.
About us | FAQs | Contact us | Privacy policy | Terms and conditions
Other Gale sites: Encyclopedia.com | HighBeam Research | Acquire Content | Books & Authors | Goliath | MovieRetriever | Smart QandA