loading...
Role Based Reengineering of Web Applications
Budapest, Hungary September 26-September 26
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/WSE.2005.12Seventh IEEE International Symposium ...
 This Article 
 
PDF
HTML
 
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Andrea De Lucia, Dipartimento di Matematica e Informatica - Universit? di Salerno (SA) Italy
Massimiliano Giordano, Dipartimento di Matematica e Informatica - Universit? di Salerno (SA) Italy
Giuseppe Polese, Dipartimento di Matematica e Informatica - Universit? di Salerno (SA) Italy
Giuseppe Scanniello, Dipartimento di Matematica e Informatica - Universit? di Salerno (SA) Italy
Genoveffa Tortora, Dipartimento di Matematica e Informatica - Universit? di Salerno (SA) Italy

We present an approach based on roles and access policies to improve security management of Web Applications. The approach first identifies the roles users have in the application, and then the software resources they can access based on the assigned role. Roles and resources are then used to design access policies by means of a visual language based tool providing a metaphor oriented layer above the well known Role Based Access Control (RBAC) model. A network infrastructure based on a Policy Enforcement Point (PEP) and a Policy Decision Point (PDP) is used to enforce these policies.

The proposed approach has been used in a preliminary case study.

Citation:
Andrea De Lucia, Massimiliano Giordano, Giuseppe Polese, Giuseppe Scanniello, Genoveffa Tortora, "Role Based Reengineering of Web Applications," wse, pp.103-110, Seventh IEEE International Symposium on Web Site Evolution, 2005
Usage of this product signifies your acceptance of the Terms of Use.