arrow
Return

A Security Model for Web-Based Communication

delete2024-09-26
delete0
PRE
AI
P
Pouyan Fotouhi Tehrani *
E
Eric Osterweil
T
Thomas C. Schmidt
M
Matthias Wählisch
DOI:10.1145/3623292delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Web access involves various protocols to resolve domain names to IP addresses, establish data exchange channels with Web servers, and to authenticate communication partners. Each protocol has its own set of requirements and security measures. In addition to technical features, operating the Web also introduces organizational and political aspects which are important to consider when deploying a secure basis for Web-based communication.In this paper, we propose an algorithmic security model based on the widely deployed technologies DNSSEC and Web PKI to cover three dimensions: identification, resolu-tion, and transaction. Our model enables quantification and qualification of the security assurance provided by an online service provider. To verify the applicability of our model, we investigate the online presence of Alerting Au-thorities in the U.S., selected German Emergency Serviceproviders, and UN member states. We observe partially en-hanced security relative to global Internet trends, yet find cause for concern as only about 6% of unique hosts cater to secure resolution. About 46% of investigated organizations use shared certificates with 1% of all organizations having no or invalid certificates. Two thirds of organizations are not uniquely identifiable and as such lack the basic require-ment of trustworthy communication

Journal

Communications of the ACM cover
Communications of the ACM
IF:
12.2
Papers:
1.2W
Citations:
3.7W

Organization

G
George Mason University
Scholars:
7.7K
Papers: 7.9K
Citations: 1.0W
H
hochschule angewandte wissenschaft hamburg
Scholars:
585
Papers: 591
Citations: 1
T
Technische Universitat Dresden
Scholars:
3.2W
Papers: 2.5W
Citations: 249
researcher View more organizations