首页> 外文会议>10th IEEE International Conference on Computer and Information Technology >Spyware Security Management via a Public Key Infrastructure for Client-Side Web Communicating Applications
【24h】

Spyware Security Management via a Public Key Infrastructure for Client-Side Web Communicating Applications

机译:通过公钥基础结构对客户端Web通讯应用程序进行间谍软件安全管理

获取原文

摘要

Internet technologies continue to revolutionize the legitimate collection of information from targeted host machines and its transmission to remote servers. The term ȁ8;spywareȁ9; refers to that subset of information collection software that operates illicitly and non-consensually. Two fundamental issues continue to complicate spyware legislation development and operational control strategies. Firstly, unlike the clearly criminal distribution of virus infections, the distribution of spyware is mainly a commercial venture. Secondly, spyware utilizes the same technologies that underpin essential, legitimate information collection applications. This paper describes a security framework to manage these two issues. The security framework, at its core, requires the authentication by the host operating system of each outgoing Web session initiated by each software application running on that host machine. This authentication requires that each software application initiating Web communications be uniquely named via a Public Key Infrastructure digital certificate ȁ3; and must use this name in all initiated Web communications. This framework facilitates the user-management of all Web communication streams emanating from the host ȁ3; and this in turn supports the identification of software that engages in the deceptive, misleading, and fraudulent practices already proscribed in existing technology-focused legislation.
机译:互联网技术不断革新着从目标主机到其向远程服务器的信息合法收集的合法性。术语ȁ8;间谍软件ȁ9;指非法和非自愿运行的信息收集软件的子集。两个基本问题继续使间谍软件法规的制定和运营控制策略变得复杂。首先,与明显的病毒感染犯罪分布不同,间谍软件的分布主要是商业行为。其次,间谍软件利用了支持基本合法信息收集应用程序的相同技术。本文介绍了管理这两个问题的安全框架。安全框架的核心要求主机操作系统对主机上运行的每个软件应用程序发起的每个传出Web会话进行身份验证。这种身份验证要求启动Web通信的每个软件应用程序都必须通过公共密钥基础结构数字证书ȁ3进行唯一命名;并且必须在所有启动的Web通信中使用此名称。该框架简化了对主机ȁ3发出的所有Web通信流的用户管理;反过来,这也支持识别参与了以现有技术为中心的立法中已经禁止的欺骗性,误导性和欺诈性行为的软件。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号