• DocumentCode
    2373865
  • Title

    A Study of Security and Performance Issues in Designing Web-based Applications

  • Author

    Yang, Shin-Jer ; Chen, Jia-Shin

  • Author_Institution
    Soochow Univ., Taipei
  • fYear
    2007
  • fDate
    24-26 Oct. 2007
  • Firstpage
    81
  • Lastpage
    88
  • Abstract
    Due to the evolution of Internet technology and application popularization, security and performance have become key issues for implementing Web-based applications. Presently, most of the Web-based applications design only consider security issue, but ignore performance problem. According to these two issues, we propose a new approach to integrate security and performance aspects for Web-based applications, called ISPWAD, which combines SWAP and RBAC frameworks. The purposes of proposed ISPWAD are to fix the security holes and improve the processing performance during in designing Web-based applications. In this paper, we propose the ISPWAD framework and design its algorithm, and also illustrate how to implement the secure Web-based applications with tuning performance. Then, we will utilize the ISPWAD to set up a practical EIP system and perform simulations for security solutions and performance improvements. Finally, our experimental results indicate that the proposed ISPWAD can solve related security holes, obtain better processing performance, and reduce development time and cost. In addition, the ISPWAD can attain a good balance-point between security and performance. In the future, the ISPWAD framework can provide a reference model for implementing e-commerce, ERP II, or EIP systems.
  • Keywords
    Internet; authorisation; telecommunication security; EIP system; ISPWAD framework; Internet; SWAP framework; Web-based application; application popularization; role based access control; security holes; Algorithm design and analysis; Application software; Computer hacking; Computer security; Costs; Data security; Information security; Internet; Laboratories; Web pages; EIP.; ISPWAD; RBAC; SWAP; Web-Based Applications;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    e-Business Engineering, 2007. ICEBE 2007. IEEE International Conference on
  • Conference_Location
    Hong Kong
  • Print_ISBN
    978-0-7695-3003-1
  • Type

    conf

  • DOI
    10.1109/ICEBE.2007.44
  • Filename
    4402078