Securing multi-tiered web applications

George Mathew, Xiaojiang Du · 2010

Multi-tiered architecture is very common in today's enterprise web applications. It is necessary to secure channels in each tier in order to secure a multi-tiered web application. For a non-HTTP based channel, there are several options to secure the channel. These security options have been used in a number of applications. However, it is not clear which option has better performance (such as delay, security strength, etc). In our research, we conducted real-network experiments to study the performances of several popular security protocols that are being used for securing multi-tiered web applications. Our experimental results provide several useful insights and guidelines for the design and deployment of secure multi-tiered web application.

Read the paper · More papers on PaperTik