11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 15: Securing Your Network 413Auditing <strong>and</strong> LoggingBy default, a router logs all deny actions; this default behavior should not bechanged. Also secure log files in a central location. Modern routers have an array oflogging features that include the ability to set severities based on the data logged.An auditing schedule should be established to routinely inspect logs for signs ofintrusion <strong>and</strong> probing.Intrusion DetectionWith restrictions in place at the router to prevent TCP/IP attacks, the router shouldbe able to identify when an attack is taking place <strong>and</strong> notify asystem administratorof the attack.Attackers learn what your security priorities are <strong>and</strong> attempt to work around them.Intrusion Detection Systems (IDSs) can show where the perpetrator is attemptingattacks.Firewall ConsiderationsA firewall should exist anywhere you interact with an untrusted network, especiallythe Internet. It is also recommended that you separate your <strong>Web</strong> servers fromdownstream application <strong>and</strong> database servers with an internal firewall.After the router, with its broad filters <strong>and</strong> gatekeepers, the firewall is the next pointof attack. In many (if not most) cases, you do not have administrative access to theupstream router. Many of the filters <strong>and</strong> ACLs that apply to the router can also beimplemented at the firewall. The configuration categories for the firewall include:●●●●●Patches <strong>and</strong> updatesFiltersAuditing <strong>and</strong> loggingPerimeter networksIntrusion detectionPatches <strong>and</strong> UpdatesSubscribe to alert services provided by the manufacturer of your firewall <strong>and</strong>operating system to stay current with both security issues <strong>and</strong> service patches.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!