Developing certificate-based projects for web security classes

  • Authors:
  • Shamima Rahman;Tuan Anh Nguyen;T. Andrew Yang

  • Affiliations:
  • Univ. of Houston, Houston, TX;Univ. of Houston, Houston, TX;Univ. of Houston, Houston, TX

  • Venue:
  • Journal of Computing Sciences in Colleges
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

Increasing number of applications are using the Internet to exchange data, varying from online chatting to credit card numbers and other sensitive information. Accompanying the widespread use of inter-networks is the ubiquitous problem of malicious attacks at the applications and the underlying networks. Data transmitted without proper protection are subject to unauthorized access and tampering. To fortify an application against attacks, it is important to integrate proper security measures. In this paper we present web security projects utilizing certificate-based mechanisms to secure web applications. The projects involve imitating attacks and protecting resources from those attacks. The projects involve the use of security technologies such as Secure Socket Layer (SSL), Digital certificates, and HTTPS (Secure HyperText Transport Protocol) for securing communication channels. By integrating the projects into web development courses, instructors may provide practical exercises that help students to acquire real-life knowledge of how these attacks are performed and how the control measures work.