Access Control Architecture Separating Privilege by a Thread on a Web Server

被引:0
|
作者
Matsumoto, Ryosuke [1 ]
Okabe, Yasuo [2 ]
机构
[1] Kyoto Univ, Grad Sch Informat, Sakyo Ku, Kyoto 6068501, Japan
[2] Kyoto Univ, Acad Ctr Comp & Media Studies, Kyoto 6068501, Japan
关键词
Security in a Server; Web Server; Access Control; Runtime Privilege;
D O I
10.1109/SAINT.2012.33
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In Web hosting services, hosting systems use access controls like suEXEC on apache Web servers to separate privilege by each virtual host. However, existing access control architectures on Web servers have a problem in their low performance and are not appropriate for dynamic contents like Web API since these architectures require termination of the process after each HTTP session. System developers are not easy to install existing access controls since these are provided by each interpreter and program execution methods conventionally. In this paper, we propose the access control architecture "mod_process_security". In this architecture a server process creates a new thread on the server process when accepting a request. Then, the web server separates privilege by the thread and processes the contents on the thread. The server process installed "mod_process_security" executes programs faster. System developers can easily install it on web servers since we replace it with the complicated existing access controls. "mod_process_security" can be installed for Apache HTTP Server on Linux as Apache Module which is widely used.
引用
收藏
页码:178 / 183
页数:6
相关论文
共 50 条
  • [41] A hybrid web server architecture for secure E-business web applications
    Beltran, V
    Carrera, D
    Guitart, J
    Torres, J
    Ayguadé, E
    HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS, PROCEEDINGS, 2005, 3726 : 366 - +
  • [42] THREaD Mapper Studio: a novel, visual web server for the estimation of genetic linkage maps
    Cheema, Jitender
    Ellis, T. H. Noel
    Dicks, Jo
    NUCLEIC ACIDS RESEARCH, 2010, 38 : W188 - W193
  • [43] A CONFERENCE CONTROL MODEL BETWEEN A WEB SERVER AND A TELECOM APPLICATION SERVER
    Wang Kaixi Yang Fangchun (State Key Laboratory of Networking and Switching Technology
    JournalofElectronics(China), 2008, (02) : 232 - 238
  • [44] The research of a new Web server cluster architecture supporting QoS
    Yang, Wu
    Li, ShuangQing
    Cheng, DaiJie
    2007 IFIP INTERNATIONAL CONFERENCE ON NETWORK AND PARALLEL COMPUTING WORKSHOPS, PROCEEDINGS, 2007, : 618 - 623
  • [45] Information architecture and web accessibility: the design of linear access to the web
    Voces-Merayo, Ramon
    PROFESIONAL DE LA INFORMACION, 2010, 19 (04): : 374 - 381
  • [46] Web Server Farm in the Cloud: Performance Evaluation and Dynamic Architecture
    Liu, Huan
    Wee, Sewook
    CLOUD COMPUTING, PROCEEDINGS, 2009, 5931 : 369 - 380
  • [47] A MULTI-CHANNEL CLUSTERED WEB APPLICATION SERVER: ARCHITECTURE
    Sameh, Ahmed
    Sobeh, Kariem
    PROCEEDINGS OF THE 2011 3RD INTERNATIONAL CONFERENCE ON FUTURE COMPUTER AND COMMUNICATION (ICFCC 2011), 2011, : 113 - +
  • [48] A hybrid web server architecture for e-commerce applications
    Carrera, D
    Beltran, V
    Torres, J
    Ayguadé, E
    11TH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS, VOL I, PROCEEDINGS, 2005, : 182 - 188
  • [49] Characterizing crawler behavior from Web server access logs
    Dikaiakos, M
    Stassopoulou, A
    Papageorgiou, L
    E-COMMERCE AND WEB TECHNOLOGIES, PROCEEDINGS, 2003, 2738 : 369 - 378
  • [50] Server-friendly delta compression for efficient Web access
    Savant, A
    Suel, T
    WEB CONTENT CACHING AND DISTRIBUTION, 2004, : 303 - 322