DocumentCode
2195031
Title
Spyware Security Management via a Public Key Infrastructure for Client-Side Web Communicating Applications
Author
Clutterbuck, Peter
Author_Institution
UQ Bus. Sch., Univ. of Queensland, Brisbane, QLD, Australia
fYear
2010
fDate
June 29 2010-July 1 2010
Firstpage
859
Lastpage
864
Abstract
Internet technologies continue to revolutionize the legitimate collection of information from targeted host machines and its transmission to remote servers. The term `spyware´ refers to that subset of information collection software that operates illicitly and non-consensually. Two fundamental issues continue to complicate spyware legislation development and operational control strategies. Firstly, unlike the clearly criminal distribution of virus infections, the distribution of spyware is mainly a commercial venture. Secondly, spyware utilizes the same technologies that underpin essential, legitimate information collection applications. This paper describes a security framework to manage these two issues. The security framework, at its core, requires the authentication by the host operating system of each outgoing Web session initiated by each software application running on that host machine. This authentication requires that each software application initiating Web communications be uniquely named via a Public Key Infrastructure digital certificate - and must use this name in all initiated Web communications. This framework facilitates the user-management of all Web communication streams emanating from the host - and this in turn supports the identification of software that engages in the deceptive, misleading, and fraudulent practices already proscribed in existing technology-focused legislation.
Keywords
Web services; client-server systems; computer viruses; legislation; message authentication; public key cryptography; Internet; authentication; client side Web communication; criminal distribution; host operating system; information collection software; legislation; public key cryptography; spyware security management; virus infections; Authentication; Business; Operating systems; Servers; Spyware; controls; privacy; risk; spyware;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer and Information Technology (CIT), 2010 IEEE 10th International Conference on
Conference_Location
Bradford
Print_ISBN
978-1-4244-7547-6
Type
conf
DOI
10.1109/CIT.2010.161
Filename
5578087
Link To Document