dc.description.abstract |
Unified Enterprise application security is a newly emerging approach for
providing protection against application level attacks. Conventional application
security approaches that embed security into each critical application results into
scattered security mechanism, which are not only difficult to manage but also
creates security loopholes. Therefore, new unified enterprise application security
concept is evolving in the industry that consists of centralized authentication,
access control, incident response and auditing. Industries such as Computer
Associate, Cerebit, Entrust, Evidian, IBM Tivoli, Netegrity, Oblix and SunOne
have comes up with the identity and access management solutions that are based on
this concept. Significant amount of misunderstanding exists in the industry and
research community about appropriate features of such a unified product. This
research has investigated current research and available products.
We have proposed new enterprise application security (EAS) comparison
framework to compare existing enterprise application security products. This
framework helps an enterprise in selecting appropriate application security
product. From comparison we found that Computer Associate and Netegrity
solutions are the best available solutions, however none of the current available
solutions are providing complete enterprise application security. Therefore we
have proposed new unified enterprise application security architecture. This
architecture provides all basic information security and other critical services such
as, auditing, reporting, authentication, access control, confidentiality, integrity,
commitment to standards, incident response, scalability, flexibility, manageability,
and compliance of regulatory mandates. |
en_US |