DocumentCode
185183
Title
Security Benchmarks for Web Serving Systems
Author
Mendes, Nuno ; Madeira, Henrique ; Duraes, Joao
Author_Institution
CISUC, Univ. of Coimbra, Coimbra, Portugal
fYear
2014
fDate
3-6 Nov. 2014
Firstpage
1
Lastpage
12
Abstract
The security of software-based systems is one of the most difficult issues when accessing the suitability of systems to most application scenarios. However, security is very hard to evaluate and quantify, and there are no standard methods to benchmark the security of software systems. This work proposes a novel methodology for benchmarking the security of software-based systems. This methodology uses the notion of risk in a quantifiable way and allows the comparison of functionally-equivalent systems (or different configurations of the same system) to enable users and system integrators to identify and select the most secure one. The benchmark methodology is based on both analytical and experimental steps and can be applicable to any software system. The benchmark procedures and rules guide users on how to instantiate the methodology to specific scenarios and how to execute the benchmark. In this paper we also present an instantiation of the methodology to a case study of web-serving systems and show how to use the results to identify the most secure system under benchmark.
Keywords
Web services; benchmark testing; security of data; Web serving systems; functionally-equivalent systems; security benchmarking; software-based system security; Benchmark testing; Computers; Databases; Equations; Measurement; Security; Software; Benchmarking; security; web serving systems;
fLanguage
English
Publisher
ieee
Conference_Titel
Software Reliability Engineering (ISSRE), 2014 IEEE 25th International Symposium on
Conference_Location
Naples
ISSN
1071-9458
Print_ISBN
978-1-4799-6032-3
Type
conf
DOI
10.1109/ISSRE.2014.38
Filename
6982349
Link To Document