Home » , » Security layers on a modern website

Security layers on a modern website




anypreview.blogspot.com



Last time, we looked at a basic website design. Now its time to start digging into the details around whats really being used behind the scenes. This time, well focus on security aspects. When a user starts their browser and connects into the website, there are many layers of security that may be present to ensure only authorized users can access the data. The more valuable the data, the more steps required to ensure that this data is protected. Here is a typical setup for higher value content websites:

Each piece adds a different layer of security. All combined, they can act as a strong defense against unauthorized access of the information. The first two, are best done by a dedicated network engineer or network consulting services company that understands security implementations and is up to date on best practices and the latest procedures.

1) Firewalls are familiar to most. You setup firewalls in a static configuration to stop all traffic unless to a service that you want available. For this, we use a Juniper SSG20 firewall:

http://www.juniper.net/us/en/products-services/security/ssg-series/ssg20/

2) Next, if youre on the internet with valuable data, you should have a Intrusion detection system and Intrusion Prevention System. These detect abnormalities and protect the service by denying access from computers that act incorrectly. Perhaps the user fails login more than X times. Perhaps theyre fishing for a URL and doing iterative attempts to try and discover content.
                  
Perhaps theyre requesting a URL thats a known buffer overflow attack? Juniper makes this unit which is a good starter:

http://www.juniper.net/us/en/products-services/security/idp-series/idp75/

3) From here, the application takes over security responsibility. Its recommended to have an application server management consultant setup Single Sign On (SSO) due complexity. From there, an application programmer can handle the rest.

Theres typically a SSO that allows for authentication of the user. This authentication can take the form of a simple user/password. It can be extended to require SecureID cards with randomizing passwords. Or higher end retinal, face recognition, or fingerprint scanners may be used depending on the value of the data being presented.

4) After a person authenticates, they need to be authorized for the data theyre requesting. This is typically an LDAP lookup against Active Directory or some other.

5) Most companies stop here and allow the user full access to the SSL web service. However, one thing thats common today: You no longer can trust the client computer thats connecting into the site. It could be a company Desktop or Laptop and relatively safe. It could be a personal smart phone, iPad or other PDA, or worse: a public computer. You can no longer treat all computers the same.

For instance, what happens when your CEO logs into a kiosk at the airport because his computer broke. He/She needs to approve the latest acquisition plan of the XYZ Company. He/She can authenticate correctlyhell be authorized to see the content. Whats stopping a download of this criticalinformation onto a public PC? Will any of this data be left in cache after he logs off? This is where Endpoint Integrity Checks are used.

Endpoint integrity are checks against the client PC. They can be as simple as: Did you run a virus scan in the past 30 days. More typical today is: will the data remain secure if loaded on the device. Is there an encrypted hard drive? Is there a BIOS password? Is the device a sanctioned platform?

6) SSL encryption of the transaction between the client and server. This is the last step of defense. Information passed between the two computers are encrypted in transit.

Security today is complex. And the cost of getting it wrong is harsh. During RSA 2011 discussions, the average cost for a single incident: $250-300k. Has HIPPA been compromised? Is SarbanesOxley affected? Did company confidentialinformation get disclosed? In the end, a better plan and execution up front can save money and aggravation in the end.

Click Here To Compare Product



Search Result

This course will introduce modern web security, with a focus on HTTPS and the Secure Socket Layer (SSL) standard. In the age of the modern web application, security ,Transport Layer Security different versions of SSL and TLS are supported by modern web browsers and by most modern web frameworks and platforms.,are a key element in most modern network system designs. four). But then we are deficient on our application layer security (layer seven, and often,How much security do you need? The only way to obtain a fully secure system is to disconnect it from the network, from all removable media devices, and from the ,A modern web-based enterprise application has four layers, security, reliability a data layer may simply be a modern relational database.,Two important components of a modern website are flexible Vulnerabilities in any of the layers of the web application will Web Application Security 18 ,Two important components of a modern website are flexible web browsers and web The first layer is normally a web browser or the user Web Security Issues,Transport Layer Security (TLS) and its predecessor, Secure Sockets Layer (SSL), are cryptographic protocols that provide communication security over the Internet.,Last time, we looked at a basic website design. Now its time to start digging into the details around whats really being used behind the scenes.,Security layers on a modern website - SPK and Associates. Blog | Contact | Sitemap Call us now to arrange a meeting! 888-310-4540. Home; Solutions. By Role

0 komentar:

Posting Komentar