27.01.2014 Views

NIST 800-44 Version 2 Guidelines on Securing Public Web Servers

NIST 800-44 Version 2 Guidelines on Securing Public Web Servers

NIST 800-44 Version 2 Guidelines on Securing Public Web Servers

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

GUIDELINES ON SECURING PUBLIC WEB SERVERS<br />

Pharming—Using technical means to redirect users into accessing a fake <strong>Web</strong> site masquerading as a<br />

legitimate <strong>on</strong>e and divulging pers<strong>on</strong>al informati<strong>on</strong>.<br />

Phishing—Using social engineering techniques to trick users into accessing a fake <strong>Web</strong> site and<br />

divulging pers<strong>on</strong>al informati<strong>on</strong>.<br />

Proxy—A proxy is an applicati<strong>on</strong> that “breaks” the c<strong>on</strong>necti<strong>on</strong> between client and server. The proxy<br />

accepts certain types of traffic entering or leaving a network, processes it, and forwards it. This<br />

effectively closes the straight path between the internal and external networks, making it more difficult<br />

for an attacker to obtain internal addresses and other details of the organizati<strong>on</strong>’s internal network. Proxy<br />

servers are available for comm<strong>on</strong> Internet services; for example, a Hypertext Transfer Protocol (HTTP)<br />

proxy used for <strong>Web</strong> access and a Simple Mail Transfer Protocol (SMTP) proxy used for e-mail.<br />

Service Pack—Microsoft’s term for a collecti<strong>on</strong> of patches integrated into a single large update.<br />

SOCKS Protocol—An Internet protocol to allow client applicati<strong>on</strong>s to form a circuit-level gateway to a<br />

network firewall via a proxy service.<br />

System Administrator—A pers<strong>on</strong> who manages a computer system, including its operating system and<br />

applicati<strong>on</strong>s. A system administrator’s resp<strong>on</strong>sibilities are similar to that of a network administrator.<br />

Virtualizati<strong>on</strong>—The use of an abstracti<strong>on</strong> layer to simulate computing hardware so that multiple<br />

operating systems can run <strong>on</strong> a single computer.<br />

Vulnerability—A security exposure in an operating system or other system software or applicati<strong>on</strong><br />

software comp<strong>on</strong>ent. A variety of organizati<strong>on</strong>s maintain publicly accessible databases of vulnerabilities<br />

based <strong>on</strong> the versi<strong>on</strong> numbers of software. Each vulnerability can potentially compromise the system or<br />

network if exploited.<br />

<strong>Web</strong> Server—A computer that provides World Wide <strong>Web</strong> (WWW) services <strong>on</strong> the Internet. It includes<br />

the hardware, operating system, <strong>Web</strong> server software, and <strong>Web</strong> site c<strong>on</strong>tent (<strong>Web</strong> pages). If the <strong>Web</strong><br />

server is used internally and not by the public, it may be known as an “intranet server.”<br />

<strong>Web</strong> Server Administrator—The <strong>Web</strong> server equivalent of a system administrator. <strong>Web</strong> server<br />

administrators are system architects resp<strong>on</strong>sible for the overall design, implementati<strong>on</strong>, and maintenance<br />

of <strong>Web</strong> servers. They may or may not be resp<strong>on</strong>sible for <strong>Web</strong> c<strong>on</strong>tent, which is traditi<strong>on</strong>ally the<br />

resp<strong>on</strong>sibility of the <strong>Web</strong>master.<br />

<strong>Web</strong>master—A pers<strong>on</strong> resp<strong>on</strong>sible for the implementati<strong>on</strong> of a <strong>Web</strong> site. <strong>Web</strong>masters must be<br />

proficient in HTML and <strong>on</strong>e or more scripting and interface languages, such as JavaScript and Perl. They<br />

may or may not be resp<strong>on</strong>sible for the underlying server, which is traditi<strong>on</strong>ally the resp<strong>on</strong>sibility of the<br />

<strong>Web</strong> administrator (see above).<br />

B-2

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!