Web Security
Web Security
WEB SECURITY
The Web presents new challenges not generally appreciated in the context of
computer and network security:
The Web is increasingly serving as a highly visible outlet for corporate and
product information and as the platform for business transactions.
Reputations can be damaged and money can be lost if the Web servers
are subverted.
Although Web browsers are very easy to use, Web servers are relatively
easy to configure and manage, and Web content is increasingly easy to
develop, the underlying software is extraordinarily complex. This complex
software may hide many potential security flaws. The short history of the
Web is filled with examples of new and upgraded systems, properly
installed, that are vulnerable to a variety of security attacks.
Casual and untrained (in security matters) users are common clients for
Web-based services. Such users are not necessarily aware of the security
risks that exist and do not have the tools or knowledge to take effective
countermeasures.
server
● Theft of data
from client
● Info about
network
configuration
● Info about which
client talks to
server
Denial of ● Killing of user Disruptive Difficult to prevent
Service threads Annoying
● Flooding machine Prevent
with bogus user from
requests getting
● Filling up disk or work done
memory
● Isolating machine
by DNS attacks
Authentication .Impersonation of .Misrepresentation Cryptographic
legitimate users of user techniques
● Data forgery ● Belief that false
information is
valid
Another way to classify Web security threats is in terms of the location of the
threat: Web server, Web browser, and network traffic between browser and
server.
Issues of server and browser security fall into the category of computer system
security.
and, to some extent, in the mechanisms that they use, but they differ with
respect to their scope of applicability and their relative location within the TCP/
IP protocol stack.