首页> 外文会议>International Conference on eDemocracy eGovernment >An authentication and auditing architecture for enhancing security on egovernment services
【24h】

An authentication and auditing architecture for enhancing security on egovernment services

机译:用于增强例如Egovernment Services的安全性的身份验证和审核架构

获取原文

摘要

eGovernment deploys governmental information and services for citizens and general society. As the Internet is being used as underlying platform for information exchange, these services are exposed to data tampering and unauthorised access as main threats against citizen privacy. These issues have been usually tackled by applying controls at application level, making authentication stronger and protecting credentials in transit using digital certificates. However, these efforts to enhance security on governmental web sites have been only focused on what malicious users can do from the outside, and not in what insiders can do to alter data straight on the databases. In fact, the lack of security controls at back-end level hinders every effort to find evidence and investigate events related to credential misuse and data tampering. Moreover, even though attackers can be found and prosecuted, there is no evidence and audit trails on the databases to link illegal activities with identities. In this article, a Salting-Based Authentication Module and a Database Intrusion Detection Module are proposed as enhancements to eGovernment security to provide better authentication and auditing controls.
机译:Egovernment部署公民和普通社会的政府信息和服务。由于互联网被用作信息交换的基础平台,因此这些服务暴露于数据篡改和未经授权访问作为对公民隐私的主要威胁。这些问题通常通过应用程序级别应用控件来解决,使身份验证更强大并使用数字证书保护凭证。但是,这些努力加强政府网站上的安全性仅关注恶意用户可以从外面做些什么,而不是在内部人士可以做的事情,以便在数据库上改变数据。事实上,后端层面缺乏安全控制,每次都努力寻找证据和调查与凭证滥用和数据篡改相关的事件。此外,即使可以找到和检控攻击者,数据库上没有证据和审计跟踪,以将非法活动与身份联系起来。在本文中,提出了一种基于腌制的身份验证模块和数据库入侵检测模块作为EGovernment Security的增强,以提供更好的认证和审计控制。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号