A commonplace solution for putting a web site on-line at a reasonable cost is hosting, that is placing it on a shared server, together with other sites. Hosting providers face significant security problems, both in terms of avoiding misuse of their servers by “guests”, and in terms of providing effective isolation between them; the Discretionary Access Control model implemented by traditional operating systems can fail to provide adequate solutions to these problems. This work describes a system based on the integration of the widely adopted Apache/PHP platform with the powerful Mandatory Access Control features offered by the Security-Enhanced Linux project. The resulting solution combines a sound approach to the most common security problems with a very tolerable impact on system administration complexity.

M. Prandini (2006). Securing a Linux-based Multi-User Web Server. CALGARY : ACTA Press.

Securing a Linux-based Multi-User Web Server

PRANDINI, MARCO
2006

Abstract

A commonplace solution for putting a web site on-line at a reasonable cost is hosting, that is placing it on a shared server, together with other sites. Hosting providers face significant security problems, both in terms of avoiding misuse of their servers by “guests”, and in terms of providing effective isolation between them; the Discretionary Access Control model implemented by traditional operating systems can fail to provide adequate solutions to these problems. This work describes a system based on the integration of the widely adopted Apache/PHP platform with the powerful Mandatory Access Control features offered by the Security-Enhanced Linux project. The resulting solution combines a sound approach to the most common security problems with a very tolerable impact on system administration complexity.
2006
Proceedings of the third international conference on Communication, Network, and Information Security
165
171
M. Prandini (2006). Securing a Linux-based Multi-User Web Server. CALGARY : ACTA Press.
M. Prandini
File in questo prodotto:
Eventuali allegati, non sono esposti

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11585/35731
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? ND
social impact