Link-E-Param 


Vol. 36,  No. 9, pp. 1073-1081, Sep.  2011


PDF
  Abstract

An URL parameter can hold some information that is confidential or vulnerable to illegitimate tampering. We propose Link-E-Param(Link with Encrypted Parameters) to protect the whole URL parameter names as well as their values. Unlike other techniques concealing only some of the URL parameters, it will successfully discourage attacks based on URL analysis to steal secret information on the Web sites. We implement Link-E-Param in the form of a servlet filter to be deployed on any Java Web server by simply copying a jar file and setting a few configuration values. Thus it can be used for any existing Web application without modifying the application. It also supports numerous encryption algorithms to choose from. Experiments show that our implementation induces only 2~3% increase in user response time due to encryption and decryption, which is deemed acceptable.

  Statistics
Cumulative Counts from November, 2022
Multiple requests among the same browser session are counted as one view. If you mouse over a chart, the values of data points will be shown.


  Cite this article

[IEEE Style]

D. Lim and J. Park, "Link-E-Param," The Journal of Korean Institute of Communications and Information Sciences, vol. 36, no. 9, pp. 1073-1081, 2011. DOI: .

[ACM Style]

Deok-Byung Lim and Jun-Cheol Park. 2011. Link-E-Param. The Journal of Korean Institute of Communications and Information Sciences, 36, 9, (2011), 1073-1081. DOI: .

[KICS Style]

Deok-Byung Lim and Jun-Cheol Park, "Link-E-Param," The Journal of Korean Institute of Communications and Information Sciences, vol. 36, no. 9, pp. 1073-1081, 9. 2011.