Web Security and Log Management: An Application Centric Perspective
- 1 School of Computing and Informatics, University of Nairobi, Nairobi, Kenya
- 2 School of Computing and Informatics, University of Nairobi, Nairobi, Kenya
- 3 School of Computing and Informatics, University of Nairobi, Nairobi, Kenya
- 4 School of Computing and Informatics, University of Nairobi, Nairobi, Kenya
Abstract
The World Wide Web has been an environment with many security threats and lots of reported cases of security breaches. Various tools and techniques have been applied in trying to curb this problem, however new attacks continue to plague the Internet. We discuss risks that affect web applications and explain how network-centric and host-centric techniques, as much as they are crucial in an enterprise, lack necessary depth to comprehensively analyze overall appli cation security. The nature of web applications to span a number of servers introduces a new dimension of security re quirement that calls for a holistic approach to protect the information asset regardless of its physical or logical separa tion of modules and tiers. We therefore classify security mechanisms as either infrastructure-centric or application-cen tric based on what asset is being secured. We then describe requirements for such application-centric security mecha nisms.
- R. T. Fielding and R. N. Taylor, “Principled Design of the Modern Web Architecture,” Proceedings of the 2000 International Conference on Software Engineering, Limerick, 4-11 June 2000, pp. 407-416.
- Acunetix, “SQL Injection: What Is It?” Web Application Security, 2011.
- N. Borhan, R. Mahmod and A. Dehghantanha, “A Framework of TPM, SVM and Boot Control for Securing Forensic Logs,” International Journal of Computer Applications, Vol. 50, No. 13, 2012, pp. 15-19.
- M. Saleh, A. R. Arasteh, A. Sakha and M. Debbabi, “Forensic Analysis of Logs: Modeling and Veri?cation,” Knowledge-Based Systems, Vol. 20, No. 7, 2007, pp. 671-682. doi:10.1016/j.knosys.2007.05.002
- A. Miège and F. Cuppens, “Alert Correlation in a Cooperative Intrusion Detection Framework,” Proceedings of the IEEE Symposium on Security and Privacy, Berkeley, 12-15 May 2002, pp. 202-215.
- B. Solms, “Information Security—A Multidimensional Discipline,” Computer & Security, Vol. 20, No. 6, 2001, pp. 504-508. doi:10.1016/S0167-4048(01)00608-3
- K. R. Kumar, “A Model for Information Security Management in Government,” ISACA Journal, Vol. 4, 2011.
- A. Roichman and E. Gudes, “Fine-Grained Access Control to Web Databases,” Proceedings of the 12th ACM Symposium on Access Control Models and Technologies, SACMAT’07, Sophia Antipolis, 20-22 June 2007, pp. 31-40.
- Y. Gonen and E. Gudes, “Users Tracking and Roles Mining in Web-Based Applications,” Proceedings of the 2011 Joint EDBT/ICDT Ph.D. Workshop, Uppsala, 25 March 2011, pp. 14-18.
- A. Shulman, “Web-Exposed Databases,” Enterprise Tech Journal, 2007.
- D. R. Tsai, A. Y. Chang, P. C. Liu and H.-C. Chen, “Optimum Tuning of Defense Settings for Common on the Web Applications,” 43rd Annual 2009 International Carnahan Conference on Security Technology, Zurich, 5-8 October 2009, pp. 89-94.
- R. P. Lippmann, et al., “Evaluating and Strengthening Enterprise Network Security Using Attack Graphs,” MIT, Cambridge, 2005.
- G. V. Jourdan, “Securing Large Applications against Command Injections,” 41st Annual IEEE International Carnahan Conference on Security Technology, Ottawa, 8-11 October 2007, pp. 69-78.
- N. Gust, C. Fournet and F. Z. Nardelli, “Reliable Evidence: Auditability by Typing,” 14th European Symposium on Research in Computer Security: ESORICS, SaintMalo, 21-23 September 2009, pp. 168-183.