Design of a secure shield for internet and web-based services using software reflection - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2018

Design of a secure shield for internet and web-based services using software reflection

Résumé

This paper presents a new methodology using software reflection to prevent, detect, and mitigate internal attacks to a running Internet Web server. This methodology is very suitable to design such systems as secure by default, that is, when designing the software some parts are marked as secured, and any change/modification of these parts will be an unexpected behavior that needs to be analyzed. If these changes turn out to be attacks, then some remediation techniques are activated, in order to guarantee that the system will continue to work even in the presence of an attack. In addition of providing the methodology, we show how this technique has been used as the basis to develop a real information system. Our experiments are convincing and argue for a secure design to develop complex systems in order to facilitate their protection, and to help to prevent attacks and intrusions
Fichier non déposé

Dates et versions

hal-02017535 , version 1 (13-02-2019)

Identifiants

Citer

Ana Rosa Cavalli, Antonio M. Ortiz, Georges Ouffoué, Cesar Andres Sanchez, Fatiha Zaidi. Design of a secure shield for internet and web-based services using software reflection. IEEE International Conference on Web Services (ICWS), Jun 2018, Seattle, United States. pp.472 - 486, ⟨10.1007/978-3-319-94289-6_30⟩. ⟨hal-02017535⟩
48 Consultations
0 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More