Back to Search Start Over

Session-Based Adaptive Overload Control for Secure Dynamic Web Applications

Authors :
Jordi Torres
David Carrera
Jordi Guitart
Eduard Ayguadé
Vicenç Beltran
Source :
ICPP
Publication Year :
2005
Publisher :
IEEE, 2005.

Abstract

As dynamic Web content and security capabilities are becoming popular in current Web sites, the performance demand on application servers that host the sites is increasing, leading sometimes these servers to overload. As a result, response times may grow to unacceptable levels and the server may saturate or even crash. In this paper we present a session-based adaptive overload control mechanism based on SSL (secure socket layer) connections differentiation and admission control. The SSL connections differentiation is a key factor because the cost of establishing a new SSL connection is much greater than establishing a resumed SSL connection (it reuses an existing SSL session on server). Considering this big difference, we have implemented an admission control algorithm that prioritizes the resumed SSL connections to maximize performance on session-based environments and limits dynamically the number of new SSL connections accepted depending on the available resources and the current number of connections in the system to avoid server overload. In order to allow the differentiation of resumed SSL connections from new SSL connections we propose a possible extension of the Java Secure Sockets Extension (JSSE) API. Our evaluation on Tomcat server demonstrates the benefit of our proposal for preventing server overload.

Details

Database :
OpenAIRE
Journal :
2005 International Conference on Parallel Processing (ICPP'05)
Accession number :
edsair.doi...........0b0a98b62a1937217f663a95d9a40b79
Full Text :
https://doi.org/10.1109/icpp.2005.72