Title :
A cryptography-based approach to web mashup security
Author :
Ali, Shady ; Khusro, S. ; Rauf, Abdul Mannan
Author_Institution :
Dept. of Comput. Sci., Univ. of Peshawar, Peshawar, Pakistan
Abstract :
With the dawn of this century emerged new and innovative ways for creating software applications on the web. One of them is “web mashup”, which allows users to create new web applications by integrating data and services from other various web applications and data sources. Several technologies like Ajax, RSS, ATOM, REST, and XML etc have emerged which are used in creating mashups. The numerous online available data sources and services on one hand makes mashup creation fast and easy and also rich in content but on the other hand results in spawning security concerns. A wide array of security issues arises while combining diverse content/services from diverse sources into a new one, such as lack of security in the technologies and trustworthiness of content etc. In addition, several other issues like user privacy, data confidentiality, data integrity, and user authentication are needed to be addressed. In response to this, several proposals have been presented for improving the security of web mashups such as a new version of JavaScript with better security properties and addition of security tags in HTML etc. However, these approaches mostly focus on cross-site referencing issues. This research paper is aimed to provide a security framework that will use well-known cryptographic techniques to address the issues of data confidentiality, data integrity, and authentication as well as protection against the most common XSS and CSRF attacks in web mashups. Instead of concentrating on a particular security aspect, the proposed framework is more general and easy to conceptualize and implement.
Keywords :
Internet; XML; authorisation; cryptography; data privacy; hypermedia markup languages; ATOM; Ajax; CSRF attacks; JavaScript; REST; RSS; Web mashup security; XML; XSS attacks; cryptography-based approach; data confidentiality; data integration; online available data services; online available data sources; service integration; user authentication; user privacy; Cryptography; Electronic publishing; Encyclopedias; Mashups; Programming; XML; Cryptography; Mashup Security; Privacy; Syndication; Web 2.0;
Conference_Titel :
Computer Networks and Information Technology (ICCNIT), 2011 International Conference on
Conference_Location :
Abbottabad
Print_ISBN :
978-1-61284-940-9
DOI :
10.1109/ICCNIT.2011.6020907