DocumentCode
142773
Title
An authentication and auditing architecture for enhancing security on egovernment services
Author
Flores, Denys A.
Author_Institution
Dept. of Inf. & Comput. Sci. (DICC), Escuela Politec. Nac., Quito, Ecuador
fYear
2014
fDate
24-25 April 2014
Firstpage
73
Lastpage
76
Abstract
eGovernment deploys governmental information and services for citizens and general society. As the Internet is being used as underlying platform for information exchange, these services are exposed to data tampering and unauthorised access as main threats against citizen privacy. These issues have been usually tackled by applying controls at application level, making authentication stronger and protecting credentials in transit using digital certificates. However, these efforts to enhance security on governmental web sites have been only focused on what malicious users can do from the outside, and not in what insiders can do to alter data straight on the databases. In fact, the lack of security controls at back-end level hinders every effort to find evidence and investigate events related to credential misuse and data tampering. Moreover, even though attackers can be found and prosecuted, there is no evidence and audit trails on the databases to link illegal activities with identities. In this article, a Salting-Based Authentication Module and a Database Intrusion Detection Module are proposed as enhancements to eGovernment security to provide better authentication and auditing controls.
Keywords
Internet; Web sites; access control; digital signatures; government data processing; information systems; public administration; security of data; Internet platform; auditing control; citizen privacy; data tampering; database intrusion detection module; digital certificates; eGovernment security enhancement; eGovernment services; governmental Web sites; governmental information deployment; salting-based authentication module; unauthorised access; Access control; Authentication; Databases; Intrusion detection; Servers; Web sites; architecture; auditing; authentication; database; eGovernment; intrusion detection; log; salting;
fLanguage
English
Publisher
ieee
Conference_Titel
eDemocracy & eGovernment (ICEDEG), 2014 First International Conference on
Conference_Location
Quito
Print_ISBN
978-3-907589-16-8
Type
conf
DOI
10.1109/ICEDEG.2014.6819952
Filename
6819952
Link To Document