11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

98 Part II: Designing Secure <strong>Web</strong> <strong>Application</strong>sSummary<strong>Security</strong> should permeate every stage of the product development life cycle <strong>and</strong> itshould be a focal point of application design. Pay particular attention to the design ofa solid authentication <strong>and</strong> authorization strategy. Also remember that the majority ofapplication level attacks rely on maliciously formed input data <strong>and</strong> poor applicationinput validation. The guidance presented in this chapter should help you with these<strong>and</strong> other challenging aspects of designing <strong>and</strong> building secure applications.Additional ResourcesFor more information, see the following resources:●●●●The current guide is Volume II in a series dedicated to helping customersimprove <strong>Web</strong> application security. For more information on architecting,designing, building <strong>and</strong> configuring authentication, authorization, <strong>and</strong> securecommunications across tiers of a distributed <strong>Web</strong> applications, see “Microsoftpatterns & practices Volume I, Building Secure ASP.NET <strong>Application</strong>s: Authentication,Authorization, <strong>and</strong> Secure Communication” at http://msdn.microsoft.com/library/en-us/dnnetsec/html/secnetlpMSDN.aspThe MSDN article “<strong>Security</strong> Models for ASP.NET <strong>Application</strong>s” athttp://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnnetsec/html/SecNetch02.asp?frame=trueThe MSDN article “Designing Authentication <strong>and</strong> Authorization” athttp://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnnetsec/html/SecNetch03.asp?frame=true“Checklist: Architecture <strong>and</strong> Design Review” in the “Checklists” section ofthis guide.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!