11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 2: <strong>Threats</strong> <strong>and</strong> Countermeasures 43This chapter has shown you the top threats that have the potential to compromiseyour network, host infrastructure, <strong>and</strong> applications. Knowledge of these threats,together with the appropriate countermeasures, provides essential information forthe threat modeling process It enables you to identify the threats that are specific toyour particular scenario <strong>and</strong> prioritize them based on the degree of risk they pose toyour system. This structured process for identifying <strong>and</strong> prioritizing threats isreferred to as threat modeling. For more information, see Chapter 3, “ThreatModeling.”Additional ResourcesFor further related reading, see the following resources:● For more information about network threats <strong>and</strong> countermeasures, see Chapter 15,“Securing Your Network.”● For more information about host threats <strong>and</strong> countermeasures, see Chapter 16,“Securing Your <strong>Web</strong> Server,” Chapter 17, “Securing Your <strong>Application</strong> Server,”Chapter 18, “Securing Your Database Server,” <strong>and</strong> Chapter 19, “Securing YourASP.NET <strong>Application</strong>.”● For more information about addressing the application level threats presentedin this chapter, see the Building chapters in Part III, “Building Secure <strong>Web</strong><strong>Application</strong>s” of this guide.● Michael Howard <strong>and</strong> David LeBlanc, Writing Secure Code 2nd Edition.Microsoft Press, Redmond, WA, 2002● For more information about tracking <strong>and</strong> fixing buffer overruns, see theMSDN article, “Fix Those Buffer Overruns,” at http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dncode/html/secure05202002.asp

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!