• DocumentCode
    142773
  • Title

    An authentication and auditing architecture for enhancing security on egovernment services

  • Author

    Flores, Denys A.

  • Author_Institution
    Dept. of Inf. & Comput. Sci. (DICC), Escuela Politec. Nac., Quito, Ecuador
  • fYear
    2014
  • fDate
    24-25 April 2014
  • Firstpage
    73
  • Lastpage
    76
  • Abstract
    eGovernment deploys governmental information and services for citizens and general society. As the Internet is being used as underlying platform for information exchange, these services are exposed to data tampering and unauthorised access as main threats against citizen privacy. These issues have been usually tackled by applying controls at application level, making authentication stronger and protecting credentials in transit using digital certificates. However, these efforts to enhance security on governmental web sites have been only focused on what malicious users can do from the outside, and not in what insiders can do to alter data straight on the databases. In fact, the lack of security controls at back-end level hinders every effort to find evidence and investigate events related to credential misuse and data tampering. Moreover, even though attackers can be found and prosecuted, there is no evidence and audit trails on the databases to link illegal activities with identities. In this article, a Salting-Based Authentication Module and a Database Intrusion Detection Module are proposed as enhancements to eGovernment security to provide better authentication and auditing controls.
  • Keywords
    Internet; Web sites; access control; digital signatures; government data processing; information systems; public administration; security of data; Internet platform; auditing control; citizen privacy; data tampering; database intrusion detection module; digital certificates; eGovernment security enhancement; eGovernment services; governmental Web sites; governmental information deployment; salting-based authentication module; unauthorised access; Access control; Authentication; Databases; Intrusion detection; Servers; Web sites; architecture; auditing; authentication; database; eGovernment; intrusion detection; log; salting;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    eDemocracy & eGovernment (ICEDEG), 2014 First International Conference on
  • Conference_Location
    Quito
  • Print_ISBN
    978-3-907589-16-8
  • Type

    conf

  • DOI
    10.1109/ICEDEG.2014.6819952
  • Filename
    6819952