11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

xliv<strong>Improving</strong> <strong>Web</strong> <strong>Application</strong> <strong>Security</strong>: <strong>Threats</strong> <strong>and</strong> CountermeasuresWith that array of feature choices comes a corresponding array of decisions, <strong>and</strong>with each <strong>and</strong> every decision in the process of designing, developing, deploying,<strong>and</strong> maintaining a site can have significant security impact <strong>and</strong> implications.<strong>Improving</strong> <strong>Web</strong> <strong>Application</strong>s <strong>Security</strong>: <strong>Threats</strong> <strong>and</strong> Countermeasures provides an excellent<strong>and</strong> comprehensive approach to building highly secure <strong>and</strong> feature-rich applicationsusing the .NET Framework. It accurately sets the context — that securityconsiderations <strong>and</strong> issues must be addressed with application design, development,deployment, <strong>and</strong> maintenance in view, not during any one of these phases inisolation. It cleverly walks you through a process, prescribing actions <strong>and</strong> makingsuggestions along the way. By following the guide from start to finish you will learnhow to design a secure application by underst<strong>and</strong>ing what’s important to you, whowill attack you, <strong>and</strong> what they will likely look for, <strong>and</strong> build countermeasures toprotect yourself. The guide provides frameworks, checklists, <strong>and</strong> expert tips forthreat modeling, design <strong>and</strong> architecture reviews, <strong>and</strong> implantation reviews to helpyou avoid common mistakes <strong>and</strong> be secure from the start. It then delves into the.NET security technology in painstaking detail, leading you through decisions youwill need to make, examining security components <strong>and</strong> things you should be awareof, <strong>and</strong> focusing on issues that you cannot ignore.This is the most comprehensive <strong>and</strong> well-written guide to building secure <strong>Web</strong>applications that I have seen, <strong>and</strong> is a must read for anyone building a secure <strong>Web</strong>site or considering using ASP.NET to provide security for their online businesspresence.Mark CurpheyMark Curphey has a Masters degree in Information <strong>Security</strong> <strong>and</strong> runs the Open <strong>Web</strong><strong>Application</strong> <strong>Security</strong> Project. He moderates the sister security mailing list to Bugtraqcalled webappsec that specializes in <strong>Web</strong> application security. He is a former Directorof Information <strong>Security</strong> for Charles Schwab, consulting manager for Internet <strong>Security</strong>Systems, <strong>and</strong> veteran of more banks <strong>and</strong> consulting clients than he cares toremember. He now works for a company called Watchfire. He is also a formerJava UNIX bigot now turned C#, ASP.NET fan.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!