• DocumentCode
    2112331
  • Title

    Performance Analysis of Unified Enterprise Application Security Framework

  • Author

    Shaikh, Riaz A. ; Sharif, Kashif ; Ahmed, Ejaz

  • Author_Institution
    NUST Inst. of inf. Technol., Rawalpindi
  • fYear
    2005
  • fDate
    27-27 Aug. 2005
  • Firstpage
    1
  • Lastpage
    7
  • Abstract
    Unified Enterprise application security is a new emerging approach for providing protection against application level attacks. Conventional application security approach that consists of embedding security into each critical application leads towards scattered security mechanism that is not only difficult to manage but also creates security loopholes. According to the CSI/FBI computer crime survey report, almost 80% of the security breaches come from authorized users. In this paper, we have worked on the concept of unified security model, which manages all security aspect from a single security window. The basic idea is to keep business functionality separate from security components of the application. Our main focus was on the designing of frame work for unified layer which supports single point of policy control, centralize logging mechanism, granular, context aware access control, and independent from any underlying authentication technology and authorization policy.
  • Keywords
    authorisation; commerce; computer crime; embedded systems; CSI-FBI computer crime; application level attacks; authentication technology; authorization policy; centralize logging mechanism; context aware access control; embedding security; granular; unified enterprise application security framework; unified security model; Access control; Application software; Authentication; Centralized control; Computer crime; Computer security; Context awareness; Performance analysis; Protection; Scattering; Application; Enterprise; Security; Unified;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Engineering Sciences and Technology, 2005. SCONEST 2005. Student Conference on
  • Conference_Location
    Karachi
  • Print_ISBN
    978-0-7803-9442-1
  • Electronic_ISBN
    978-0-7803-9442-1
  • Type

    conf

  • DOI
    10.1109/SCONEST.2005.4382878
  • Filename
    4382878