• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Artikel
  4. A Security Model for Web-Based Communication
 
  • Details
  • Full
Options
September 26, 2024
Journal Article
Title

A Security Model for Web-Based Communication

Abstract
Web access involves various protocols to resolve domain names to IP addresses, establish data exchange channels with Web servers, and to authenticate communication partners. Each protocol has its own set of requirements and security measures. In addition to technical features, operating the Web also introduces organizational and political aspects which are important to consider when deploying a secure basis for Web-based communication.
In this paper, we propose an algorithmic security model based on the widely deployed technologies DNS(SEC) and Web PKI to cover the three dimensions identification, resolution, and transaction. Our model enables quantification and qualification of the security assurance provided by an online service provider. To verify the applicability of our model, we investigate the online presence of Alerting Authorities in the U.S., selected German Emergency Service providers, and UN member states. We observe partially enhanced security relative to global Internet trends, yet find cause for concern as only about 6% of unique hosts cater to secure resolution. About 46% of investigated organizations use shared certificates with 1% of all organizations having no or invalid certificates. Two thirds of organizations are not uniquely identifiable and as such lack the basic requirement of trustworthy communication.
Author(s)
Fotouhi Tehrani, Pouyan  
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Osterweil, Eric
Schmidt, Thomas C.
Wählisch, Matthias
Journal
Communications of the ACM  
Project(s)
Deutsches Internet-Institut
Funder
Bundesministerium für Bildung und Forschung -BMBF-  
DOI
10.1145/3623292
Language
English
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Keyword(s)
  • Communication partners

  • Domain names

  • Organizational aspects

  • Security measure

  • Security modeling

  • Service provider

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024