A Security Model for Web-Based Communication

计算机科学 Web应用程序安全性 计算机安全 万维网 Web服务 Web开发
作者
Pouyan Fotouhi Tehrani,Eric Osterweil,Thomas C. Schmidt,Matthias Wählisch
出处
期刊:Communications of The ACM [Association for Computing Machinery]
卷期号:67 (10): 83-90
标识
DOI:10.1145/3623292
摘要

Web access involves various protocols to resolve domain names to IP addresses, establish data exchange channels with Web servers, and to authenticate communication partners. Each protocol has its own set of requirements and security measures. In addition to technical features, operating the Web also introduces organizational and political aspects which are important to consider when deploying a secure basis for Web-based communication. In this paper, we propose an algorithmic security model based on the widely deployed technologies DNS(SEC) and Web PKI to cover the three dimensions identification , resolution , and transaction . Our model enables quantification and qualification of the security assurance provided by an online service provider. To verify the applicability of our model, we investigate the online presence of Alerting Authorities in the U.S., selected German Emergency Service providers, and UN member states . We observe partially enhanced security relative to global Internet trends, yet find cause for concern as only about 6% of unique hosts cater to secure resolution. About 46% of investigated organizations use shared certificates with 1% of all organizations having no or invalid certificates. Two thirds of organizations are not uniquely identifiable and as such lack the basic requirement of trustworthy communication.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
ding应助未碎冰蓝采纳,获得30
刚刚
科目三应助clownnn采纳,获得10
刚刚
1秒前
任性天晴完成签到,获得积分20
1秒前
1秒前
追寻紫安发布了新的文献求助10
2秒前
大模型应助与谁相濡以沫采纳,获得10
2秒前
优雅的草丛完成签到,获得积分10
2秒前
2秒前
Xenia发布了新的文献求助10
4秒前
醉玉颓山完成签到,获得积分10
6秒前
小二郎应助怕黑三毒采纳,获得10
6秒前
镜中永恒完成签到,获得积分10
7秒前
Xenia完成签到,获得积分10
9秒前
喵喵拳完成签到,获得积分10
9秒前
11秒前
13秒前
13秒前
科目三应助冷艳的裙子采纳,获得10
13秒前
Yanran发布了新的文献求助30
13秒前
ding应助侯伯军采纳,获得10
14秒前
14秒前
14秒前
15秒前
16秒前
苗条的嫣完成签到,获得积分10
17秒前
vv完成签到,获得积分20
17秒前
淡然丹寒完成签到 ,获得积分10
19秒前
斯文翠发布了新的文献求助10
19秒前
可颂发布了新的文献求助10
20秒前
史萌发布了新的文献求助10
24秒前
24秒前
聪慧的乐驹完成签到,获得积分10
24秒前
25秒前
华仔应助Starry采纳,获得10
25秒前
Blassom发布了新的文献求助10
25秒前
ZQP完成签到 ,获得积分10
25秒前
26秒前
可颂完成签到,获得积分10
26秒前
凡尔赛老痘完成签到,获得积分10
27秒前
高分求助中
Adhesion Science: Principles & Practice 1234
Signals, Systems, and Signal Processing 610
The Resilient Mindset 400
Impact of Storage Orientation and Duration on Prefilled Syringe Performance: Break-Loose and Glide Forces, and Injection Time Across Multiple Time Points 360
Programming for Chemical Engineers Using C, C++, and MATLAB 300
Upland Kenya wild flowers and ferns: a flora of the flowers, ferns, grasses, and sedges of highland Kenya 300
Disturbing the Quiet Life? Competition and CEO Incentives 300
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6652611
求助须知:如何正确求助?哪些是违规求助? 8406460
关于积分的说明 17974950
捐赠科研通 5848033
什么是DOI,文献DOI怎么找? 2971759
邀请新用户注册赠送积分活动 1947257
关于科研通互助平台的介绍 1867762