Performance analysis of unified enterprise application security framework


Autoria(s): Sheikh, Riaz A.; Sharif, Kashif; Ahmed, Ejaz
Data(s)

01/08/2005

Resumo

Unified Enterprise application security is a new emerging approach for providing protection against application level attacks. Conventional application security approach that consists of embedding security into each critical application leads towards scattered security mechanism that is not only difficult to manage but also creates security loopholes. According to the CSIIFBI computer crime survey report, almost 80% of the security breaches come from authorized users. In this paper, we have worked on the concept of unified security model, which manages all security aspect from a single security window. The basic idea is to keep business functionality separate from security components of the application. Our main focus was on the designing of frame work for unified layer which supports single point of policy control, centralize logging mechanism, granular, context aware access control, and independent from any underlying authentication technology and authorization policy.

Formato

application/pdf

Identificador

http://eprints.qut.edu.au/33629/

Publicador

IEEE

Relação

http://eprints.qut.edu.au/33629/1/c33629.pdf

DOI:10.1109/SCONEST.2005.4382878

Sheikh, Riaz A., Sharif, Kashif, & Ahmed, Ejaz (2005) Performance analysis of unified enterprise application security framework. In Proceedings of Student Conference on Engineering Sciences and Technology 2005, IEEE, NED University of Engineering and Technology, Karachi.

Direitos

Copyright 2005 IEEE

Fonte

Faculty of Science and Technology; Information Security Institute

Palavras-Chave #080303 Computer System Security #Unified Enterprise #Framework #Security #Performance Analysis
Tipo

Conference Paper