27.01.2014 Views

NIST 800-44 Version 2 Guidelines on Securing Public Web Servers

NIST 800-44 Version 2 Guidelines on Securing Public Web Servers

NIST 800-44 Version 2 Guidelines on Securing Public Web Servers

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

GUIDELINES ON SECURING PUBLIC WEB SERVERS<br />

• HTTPS 8<br />

• Internet Caching Protocol (ICP)<br />

• Hyper Text Caching Protocol (HTCP)<br />

• <strong>Web</strong> Cache Coordinati<strong>on</strong> Protocol (WCCP)<br />

• SOCKS 9<br />

• Database services (e.g., Open Database C<strong>on</strong>nectivity [ODBC]).<br />

Identify any network service software, both client and server, to be installed <strong>on</strong> the <strong>Web</strong> server and<br />

any other support servers.<br />

Identify the users or categories of users of the <strong>Web</strong> server and any support hosts.<br />

Determine the privileges that each category of user will have <strong>on</strong> the <strong>Web</strong> server and support hosts.<br />

Determine how the <strong>Web</strong> server will be managed (e.g., locally, remotely from the internal network,<br />

remotely from external networks).<br />

Decide if and how users will be authenticated and how authenticati<strong>on</strong> data will be protected.<br />

Determine how appropriate access to informati<strong>on</strong> resources will be enforced.<br />

Determine which <strong>Web</strong> server applicati<strong>on</strong>s meet the organizati<strong>on</strong>’s requirements. C<strong>on</strong>sider servers<br />

that may offer greater security, albeit with less functi<strong>on</strong>ality in some instances. Some issues to<br />

c<strong>on</strong>sider include—<br />

• Cost<br />

• Compatibility with existing infrastructure<br />

• Knowledge of existing employees<br />

• Existing manufacturer relati<strong>on</strong>ship<br />

• Past vulnerability history<br />

• Functi<strong>on</strong>ality.<br />

Work closely with manufacturer(s) in the planning stage.<br />

The choice of <strong>Web</strong> server applicati<strong>on</strong> may determine the choice of OS. However, to the degree possible,<br />

<strong>Web</strong> server administrators should choose an OS that provides the following [Alle00]:<br />

Ability to restrict administrative or root level activities to authorized users <strong>on</strong>ly<br />

8<br />

9<br />

HTTP transacti<strong>on</strong>s protected via the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocols (see Secti<strong>on</strong> 7).<br />

“SOCKS” is an abbreviati<strong>on</strong> for “SOCKetS”.<br />

3-2

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!