首页> 外文会议>ACM symposium on access control models and technologies >SCUTA: A Server-Side Access Control System for Web Applications
【24h】

SCUTA: A Server-Side Access Control System for Web Applications

机译:SCUTA:Web应用程序的服务器端访问控制系统

获取原文

摘要

The Web is playing a very important role in our lives, and is becoming an essential element of the computing infrastructure. Unfortunately, its importance makes it the preferred target of attacks. Web-based vulnerabilities now outnumber traditional computer security concerns. A recent study shows that over 80 percent of web sites have had at least one serious vulnerability. We believe that the Web's problems, to a large degree, are caused by the inadequacy of its underlying access control systems. To reduce the number of vulnerabilities, it is essential to provide web applications with better access control models that can adequately address the protection needs of the current Wei). As a part of the efforts to develop a better access control system for the Web. we focus on the server-side access control in this paper. We introduce a new concept called subsession. based on which, we have developed a ring-based access control system (called Scuta) for web servers. Scuta provides a fine-grained and backward-compatible access control mechanism for web applications. We have implemented Scuta in PUP. and have conducted comprehensive case studies to evaluate its benefits.
机译:网络在我们的生活中发挥着非常重要的作用,并成为计算基础设施的基本要素。不幸的是,它的重要性使其成为攻击的首选目标。基于Web的漏洞现已超过传统计算机安全问题。最近的一项研究表明,超过80%的网站至少有一个严重的脆弱性。我们认为网络的问题,在很大程度上是由其底层访问控制系统的不足引起的。为了减少漏洞的数量,必须提供具有更好的访问控制模型的Web应用程序,可以充分解决当前魏的保护需求)。作为为Web开发更好的访问控制系统的努力的一部分。我们专注于本文的服务器端访问控制。我们介绍了一个名为Subessies的新概念。根据其中,我们开发了一个用于Web服务器的基于环形的访问控制系统(称为SCUTA)。 SCUTA为Web应用提供了一种微粒和后向兼容的访问控制机制。我们已经在小狗中实施了Scuta。并进行了全面的案例研究,以评估其利益。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号