Skip to main content

Pasic: A Novel Approach for Page-Wise Web Application Security

  • Conference paper
  • First Online:
Computer Networks & Communications (NetCom)

Part of the book series: Lecture Notes in Electrical Engineering ((LNEE,volume 131))

  • 1705 Accesses

Abstract

Secured access to Web contents and the interaction with Web application are becoming one of the most important issues in the context of Internet. HTTP protocol which uses plain text transmission is employed for data communication over Internet. Secure Socket Layer (SSL) certificates over HTTP evolve into HTTPS protocol which is one of most used solutions that provide security. However the same certificate has been used for all the pages irrespective of sensitivity of the data. Moreover, data with different security requirements have been secured using the same algorithm which could either reduce the performance of the Web application or do not provide the appropriate security according to the nature of each data item. In order to compensate the degradation in the quality of service, it is proposed to use appropriate encryption and integrity algorithms for each page, based on the sensitivity of information and security requirements for the data. A gradation of security levels namely high, medium, and low has been proposed. A combination of different algorithms are considered to provide confidentiality and integrity for each level of security. The proposed approach is experimented with a prototype in healthcare domain.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 299.00
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 379.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info
Hardcover Book
USD 379.99
Price excludes VAT (USA)
  • Durable hardcover edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

References

  1. Stallings W (2002) Cryptography and network security-principles and practice, 3rd edn. Prentice Hall, Engle-wood Cliffs

    Google Scholar 

  2. Ben G, Whitney H, Andre H, Murali J, Prasad DV, Ravi T, David W (2002) Professional Web Services Security. Shroff Publishers and Distributors, Professional

    Google Scholar 

  3. Luo Q, Lin Y (2009) Analysis and comparison of several algorithms in SSL/TLS handshake protocol. In: IEEE international conference on information technology and computer science, pp 613–617

    Google Scholar 

  4. Huawei Z, Ruixia L (2009) A scheme to improve security of SSL. In: Proceedings of the 2009 pacific-asia conference on circuits communications and system, pp 401–404

    Google Scholar 

  5. Masaru T (2009) An HTTP extension for secure transfer of confidential data. In: IEEE international conference on networking architecture and storage, pp 101–108

    Google Scholar 

  6. Fisher T (2008) Ruby on rails bible. Wiley Publishing Inc, New York

    Google Scholar 

  7. Model-view-controller architecture. http://www.jcorporate.com/expresso/doc/edg/edgWhatIsMVC.htmls

  8. Openssl security implementation. http://www.ruby-forum.com/topic

  9. Openssl algorithms. http://stackoverow.com/questions/2043557/des3-decryption-in-ruby-on-rails

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Angamuthu Maheswaran .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2013 Springer Science+Business Media New York

About this paper

Cite this paper

Maheswaran, A., Kanchana, R. (2013). Pasic: A Novel Approach for Page-Wise Web Application Security. In: Chaki, N., Meghanathan, N., Nagamalai, D. (eds) Computer Networks & Communications (NetCom). Lecture Notes in Electrical Engineering, vol 131. Springer, New York, NY. https://doi.org/10.1007/978-1-4614-6154-8_43

Download citation

  • DOI: https://doi.org/10.1007/978-1-4614-6154-8_43

  • Published:

  • Publisher Name: Springer, New York, NY

  • Print ISBN: 978-1-4614-6153-1

  • Online ISBN: 978-1-4614-6154-8

  • eBook Packages: EngineeringEngineering (R0)

Publish with us

Policies and ethics