• DocumentCode
    3361601
  • Title

    A dynamic Web agent for verifying the security and integrity of a Web site´s contents

  • Author

    Sedaghat, Soroush ; Pieprsyk, J. ; Vossough, Ehsan

  • Author_Institution
    Div. of Planing & Quality Inf. Manage. & Anal., Univ. of Western Ontario, London, Ont., Canada
  • fYear
    2001
  • fDate
    2001
  • Firstpage
    330
  • Lastpage
    337
  • Abstract
    To harness safe operation of Web-based systems in Web environments, we propose an SSPA (Server-based SHA-1 Page-digest Algorithm) to verify the integrity of Web contents before the server issues an HTTP response to a user request. In addition to standard security measures, our Java implementation of the SSPA, which is called the Dynamic Security Surveillance Agent (DSSA), provides further security in terms of content integrity to Web-based systems. Its function is to prevent the display of Web contents that have been altered through the malicious acts of attackers and intruders on client machines. This is to protect the reputation of organisations from cyber-attacks and to ensure the safe operation of Web systems by dynamically monitoring the integrity of a Web site´s content on demand. We discuss our findings in terms of the applicability and practicality of the proposed system. We also discuss its time metrics, specifically in relation to its computational overhead at the Web server, as well as the overall latency from the clients´ point of view, using different Internet access methods. The SSPA, our DSSA implementation, some experimental results and related work are all discussed
  • Keywords
    Internet; Java; data integrity; file servers; information resources; safety; security of data; software agents; surveillance; system monitoring; DSSA; Dynamic Security Surveillance Agent; HTTP response; Internet access methods; Java implementation; SSPA; Secure Hash Algorithm 1; Server-based SHA-1 Page-digest Algorithm; Web server; Web site content integrity verification; altered Web content display prevention; applicability; attackers; client machines; computational overhead; cyber-attacks; dynamic Web agent; intruders; latency; malicious acts; on-demand dynamic monitoring; organisation reputation protection; practicality; safe operation; security verification; time metrics; Decision support systems; Delay; Displays; Java; Measurement standards; Monitoring; Protection; Security; Surveillance; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Supported Cooperative Work in Design, The Sixth International Conference on, 2001
  • Conference_Location
    London, Ont.
  • Print_ISBN
    0-660-18493-1
  • Type

    conf

  • DOI
    10.1109/CSCWD.2001.942281
  • Filename
    942281