Mrunali Bukkawar, Pathan Mohd. Shafi
{"title":"针对客户端HTTP攻击的基于web代理的认证授权机制","authors":"Mrunali Bukkawar, Pathan Mohd. Shafi","doi":"10.4018/IJSE.2017010105","DOIUrl":null,"url":null,"abstract":"Therehasbeenahugedevelopmentinhowtoreadadatafromsensordevicesuchasinfrared(IR) device, temperature device, etc. Sensor data collection has wide issues of information security. Informationsecurityisalsothecurrenttopicofdiscussionduetoitsuseinapplicationinvarious fields.Therearenumberofusershavingdifferentuserroleswithsmartdevices.Thesepersonneluse devicesforvariouspurposeslikeaccesstheinformationfromvariousdevicessuchaswirelesssensors sothatasecureandefficientmutualauthenticationandauthorizationschemeisusedinthesmartgrid networktopreventvariousinsiderandoutsiderattacksoninformationordata.Therefore,proposed workdesignnovelapproachtoovercomethatattack,malicioususeranddevicebyauthentication andauthorization.Thetechniqueofauthenticateauthenticateseachuserroledynamicallyusinga signaturebasedaccesscontrolandverifiestheidentityofusertogetherwiththedevice.Accesscontrol mechanismnotonlypreventsunauthorizedaccessbutalsopreventmisuseofdata.Existingsystem generatessharedkeyforeachsessionbutitgenerateshugeoverheadandnotsuitablefortherealworldapplicationssoinproposedsystemweusedpublickeycryptographytoreducetheoverhead. KEyWoRdS Anomaly Detection, Authentication, Authorization, DDoS Attack, SQL Injection","PeriodicalId":272943,"journal":{"name":"Int. J. Synth. Emot.","volume":"76 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"Web-Proxy-Based Authentication and Authorization Mechanism Against Client-Based HTTP Attacks\",\"authors\":\"Mrunali Bukkawar, Pathan Mohd. Shafi\",\"doi\":\"10.4018/IJSE.2017010105\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Therehasbeenahugedevelopmentinhowtoreadadatafromsensordevicesuchasinfrared(IR) device, temperature device, etc. Sensor data collection has wide issues of information security. Informationsecurityisalsothecurrenttopicofdiscussionduetoitsuseinapplicationinvarious fields.Therearenumberofusershavingdifferentuserroleswithsmartdevices.Thesepersonneluse devicesforvariouspurposeslikeaccesstheinformationfromvariousdevicessuchaswirelesssensors sothatasecureandefficientmutualauthenticationandauthorizationschemeisusedinthesmartgrid networktopreventvariousinsiderandoutsiderattacksoninformationordata.Therefore,proposed workdesignnovelapproachtoovercomethatattack,malicioususeranddevicebyauthentication andauthorization.Thetechniqueofauthenticateauthenticateseachuserroledynamicallyusinga signaturebasedaccesscontrolandverifiestheidentityofusertogetherwiththedevice.Accesscontrol mechanismnotonlypreventsunauthorizedaccessbutalsopreventmisuseofdata.Existingsystem generatessharedkeyforeachsessionbutitgenerateshugeoverheadandnotsuitablefortherealworldapplicationssoinproposedsystemweusedpublickeycryptographytoreducetheoverhead. KEyWoRdS Anomaly Detection, Authentication, Authorization, DDoS Attack, SQL Injection\",\"PeriodicalId\":272943,\"journal\":{\"name\":\"Int. J. Synth. Emot.\",\"volume\":\"76 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"1900-01-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Int. J. Synth. Emot.\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.4018/IJSE.2017010105\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Int. J. Synth. Emot.","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.4018/IJSE.2017010105","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1
Web-Proxy-Based Authentication and Authorization Mechanism Against Client-Based HTTP Attacks
Therehasbeenahugedevelopmentinhowtoreadadatafromsensordevicesuchasinfrared(IR) device, temperature device, etc. Sensor data collection has wide issues of information security. Informationsecurityisalsothecurrenttopicofdiscussionduetoitsuseinapplicationinvarious fields.Therearenumberofusershavingdifferentuserroleswithsmartdevices.Thesepersonneluse devicesforvariouspurposeslikeaccesstheinformationfromvariousdevicessuchaswirelesssensors sothatasecureandefficientmutualauthenticationandauthorizationschemeisusedinthesmartgrid networktopreventvariousinsiderandoutsiderattacksoninformationordata.Therefore,proposed workdesignnovelapproachtoovercomethatattack,malicioususeranddevicebyauthentication andauthorization.Thetechniqueofauthenticateauthenticateseachuserroledynamicallyusinga signaturebasedaccesscontrolandverifiestheidentityofusertogetherwiththedevice.Accesscontrol mechanismnotonlypreventsunauthorizedaccessbutalsopreventmisuseofdata.Existingsystem generatessharedkeyforeachsessionbutitgenerateshugeoverheadandnotsuitablefortherealworldapplicationssoinproposedsystemweusedpublickeycryptographytoreducetheoverhead. KEyWoRdS Anomaly Detection, Authentication, Authorization, DDoS Attack, SQL Injection