Branch topics LASER World of PHOTONICS World of Photonics Congress LASER World of PHOTONICS China
HOME
INDUSTRY TOPICS
BUSINESS LIFE
Messe München GmbH FULL-TEXT-SEARCH

 
 
Partners  
 Subscribe to the Newsletter  Subscribe to the Newsletter

Mercateo - der Megahändler für Geschäftskunden im Internet

print page recommend page  |   Deutsch
PRACTICE
MMI/ks
How to Protect Your Web Server from Attacks

The National Institute of Standards and Technology (NIST) has released a new publication that provides detailed tips on how to make web servers more resistant to potential attacks. Called “Guidelines on Securing Public Web Servers,” the publication covers some of the latest threats to web security, while reflecting general changes in web technology that have taken place since the first version of the guide was published 5 years ago.

Web servers are the software programs that make information available over the Internet. They are often the most frequently targeted hosts on a computer network. Attackers gaining unauthorized access to the server may be able to change information on the site (e.g., defacing a web page), access sensitive personal information, or install malicious software to launch further attacks. Recently emerging threats include “pharming,” in which people attempting to visit a web site are redirected surreptitiously to a malicious site.

How does one thwart these attacks? The guide advocates taking basic steps such as keeping up-to-date on patches (fixes and updates) for web server software and the underlying operating system. Also, the guide recommends configuring the software in as secure a fashion as possible, for example by disabling unnecessary software services and applications, which may themselves have security holes that can provide openings for attacks. Another key recommendation, especially for large-scale operations, is to consider the proper human-resource requirements for deploying and operating a secure web server, by staffing the appropriate complement of IT experts (such as system and network administrators) all doing their jobs to establish and promote security.

The guide advocates “defense in depth”—installing safeguards at various points of entry into the server, from the router that handles all incoming data traffic to the specific machines that house the server software. In addition, the guide recommends, organizations should monitor log files, create procedures for recovering from attacks, and regularly test the security of their systems.

The guide is designed for federal departments and agencies, but may be applicable to any web server to which the outside world has access. The guide is available free of charge at http://csrc.nist.gov/publications/nistpubs/800-44-ver2/SP800-44v2.pdf.


PRACTICE
more articles ( 52 )  more articles ( 52 ) 
Lean Manufacturing
How eliminating waste will increase your profits go
Innecto consultants - reward strategies
The importance of bonus schemes during recession go
Analytics made simple:
How to measure, rate, and improve customer acquisition & retention go
NEWS
more articles ( 117 )  more articles ( 117 ) 
From red tape to e-barriers - changing challenges
Commission approves new programme to break down e-barriers go
September 2008 compared with August 2008
Volume of retail trade down by 0.2% in euro area - down by 0.1% in EU27  go
September 2008 compared with August 2008
Industrial producer prices down by 0.2% in both euro area and EU27 go
ANALYSIS-MARKET-TRENDS
more articles ( 124 )  more articles ( 124 ) 
Gartner says
Changing the cost structure of IT will become a business imperative for most CIOs go
The Mental Codes
Are you suck in life because of your mental codes? go
Daw Web Hosting Blog
Asian consumers drive online economy to growth go
CAREER TIPS
Global Career Company
US talent wanted for boom time Africa go
PRODUCT INNOVATIONS
more articles ( 19 )  more articles ( 19 ) 
Made in IBM Labs: technology to aid human memory
New software helps people struggling with information overload go
Gamercize - electronic motivator
Fitness machine launched for office workers go
Text Internet Marketing
Free express web test go
APPLICATIONS
Data Mining - Software Tool
Rapid-I knows, what customers are going to buy go


LASER World of Photonics June 15 - 18, 2009
World of Photonics Congress June 14 - 19, 2009
LASER World of Photonics China March 17 - 19, 2009
 Up to date - 01.12.2008
 back    top