DocumentCode :
185183
Title :
Security Benchmarks for Web Serving Systems
Author :
Mendes, Nuno ; Madeira, Henrique ; Duraes, Joao
Author_Institution :
CISUC, Univ. of Coimbra, Coimbra, Portugal
fYear :
2014
fDate :
3-6 Nov. 2014
Firstpage :
1
Lastpage :
12
Abstract :
The security of software-based systems is one of the most difficult issues when accessing the suitability of systems to most application scenarios. However, security is very hard to evaluate and quantify, and there are no standard methods to benchmark the security of software systems. This work proposes a novel methodology for benchmarking the security of software-based systems. This methodology uses the notion of risk in a quantifiable way and allows the comparison of functionally-equivalent systems (or different configurations of the same system) to enable users and system integrators to identify and select the most secure one. The benchmark methodology is based on both analytical and experimental steps and can be applicable to any software system. The benchmark procedures and rules guide users on how to instantiate the methodology to specific scenarios and how to execute the benchmark. In this paper we also present an instantiation of the methodology to a case study of web-serving systems and show how to use the results to identify the most secure system under benchmark.
Keywords :
Web services; benchmark testing; security of data; Web serving systems; functionally-equivalent systems; security benchmarking; software-based system security; Benchmark testing; Computers; Databases; Equations; Measurement; Security; Software; Benchmarking; security; web serving systems;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Software Reliability Engineering (ISSRE), 2014 IEEE 25th International Symposium on
Conference_Location :
Naples
ISSN :
1071-9458
Print_ISBN :
978-1-4799-6032-3
Type :
conf
DOI :
10.1109/ISSRE.2014.38
Filename :
6982349
Link To Document :
بازگشت