Title :
A dynamic Web agent for verifying the security and integrity of a Web site´s contents
Author :
Sedaghat, Soroush ; Pieprsyk, J. ; Vossough, Ehsan
Author_Institution :
Div. of Planing & Quality Inf. Manage. & Anal., Univ. of Western Ontario, London, Ont., Canada
Abstract :
To harness safe operation of Web-based systems in Web environments, we propose an SSPA (Server-based SHA-1 Page-digest Algorithm) to verify the integrity of Web contents before the server issues an HTTP response to a user request. In addition to standard security measures, our Java implementation of the SSPA, which is called the Dynamic Security Surveillance Agent (DSSA), provides further security in terms of content integrity to Web-based systems. Its function is to prevent the display of Web contents that have been altered through the malicious acts of attackers and intruders on client machines. This is to protect the reputation of organisations from cyber-attacks and to ensure the safe operation of Web systems by dynamically monitoring the integrity of a Web site´s content on demand. We discuss our findings in terms of the applicability and practicality of the proposed system. We also discuss its time metrics, specifically in relation to its computational overhead at the Web server, as well as the overall latency from the clients´ point of view, using different Internet access methods. The SSPA, our DSSA implementation, some experimental results and related work are all discussed
Keywords :
Internet; Java; data integrity; file servers; information resources; safety; security of data; software agents; surveillance; system monitoring; DSSA; Dynamic Security Surveillance Agent; HTTP response; Internet access methods; Java implementation; SSPA; Secure Hash Algorithm 1; Server-based SHA-1 Page-digest Algorithm; Web server; Web site content integrity verification; altered Web content display prevention; applicability; attackers; client machines; computational overhead; cyber-attacks; dynamic Web agent; intruders; latency; malicious acts; on-demand dynamic monitoring; organisation reputation protection; practicality; safe operation; security verification; time metrics; Decision support systems; Delay; Displays; Java; Measurement standards; Monitoring; Protection; Security; Surveillance; Web server;
Conference_Titel :
Computer Supported Cooperative Work in Design, The Sixth International Conference on, 2001
Conference_Location :
London, Ont.
Print_ISBN :
0-660-18493-1
DOI :
10.1109/CSCWD.2001.942281