首页> 外文会议>Trust management III >Detection and Prevention of Insider Threats in Database Driven Web Services
【24h】

Detection and Prevention of Insider Threats in Database Driven Web Services

机译:检测和预防数据库驱动的Web服务中的内部威胁

获取原文
获取原文并翻译 | 示例

摘要

In this paper, we take the first step to address the gap between the security needs in outsourced hosting services and the protection provided in the current practice. We consider both insider and outsider attacks in the third-party web hosting scenarios. We present SafeWS, a modular solution that is inserted between server side scripts and databases in order to prevent and detect website hijacking and unauthorized access to stored data. To achieve the required security, SafeWS utilizes a combination of lightweight cryptographic integrity and encryption tools, software engineering techniques, and security data management principles. We also describe our implementation of SafeWS and its evaluation. The performance analysis of our prototype shows the overhead introduced by security verification is small. SafeWS will allow business owners to significantly reduce the security risks and vulnerabilities of outsourcing their sensitive customer data to third-party providers.
机译:在本文中,我们迈出了第一步,以解决外包托管服务的安全需求与当前实践提供的保护之间的差距。我们在第三方虚拟主机方案中同时考虑内部和外部攻击。我们提出了SafeWS,这是一种模块化解决方案,已插入服务器端脚本和数据库之间,以防止和检测网站劫持和对存储数据的未授权访问。为了实现所需的安全性,SafeWS利用了轻量级加密完整性和加密工具,软件工程技术以及安全性数据管理原理的组合。我们还将描述SafeWS的实施及其评估。我们的原型的性能分析表明,安全验证带来的开销很小。 SafeWS将使企业所有者可以大大降低将敏感客户数据外包给第三方提供商的安全风险和漏洞。

著录项

  • 来源
    《Trust management III》|2009年|117-132|共16页
  • 会议地点 West Lafayette IN(US);West Lafayette IN(US)
  • 作者

    Tzvi Chumash; Danfeng Yao;

  • 作者单位

    Rutgers University, Computer Science Department,110 Frelinghuysen Road, Piscataway, NJ 08854, USA;

    Rutgers University, Computer Science Department,110 Frelinghuysen Road, Piscataway, NJ 08854, USA;

  • 会议组织
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 通信;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号