Application Level Security Management / Nejlevnější knihy
Application Level Security Management

Kód: 02415233

Application Level Security Management

Autor Michael Neuhaus

Diploma Thesis from the year 2005 in the subject Computer Science - Internet, New Technologies, grade: 1,3, University of Applied Sciences Constanze (unbekannt), language: English, abstract: Inhaltsangabe:Abstract:§Today, more and ... celý popis

2605


Skladem u dodavatele
Odesíláme za 14-18 dnů
Přidat mezi přání

Mohlo by se vám také líbit

Darujte tuto knihu ještě dnes
  1. Objednejte knihu a zvolte Zaslat jako dárek.
  2. Obratem obdržíte darovací poukaz na knihu, který můžete ihned předat obdarovanému.
  3. Knihu zašleme na adresu obdarovaného, o nic se nestaráte.

Více informací

Více informací o knize Application Level Security Management

Nákupem získáte 261 bodů

Anotace knihy

Diploma Thesis from the year 2005 in the subject Computer Science - Internet, New Technologies, grade: 1,3, University of Applied Sciences Constanze (unbekannt), language: English, abstract: Inhaltsangabe:Abstract:§Today, more and more enterprises are developing business applications for Internet usage, which results in the exposure of their sensitive data not only to customers, and business partners but also to hackers. Because web applications provide the interface between users sitting somewhere within the World Wide Web and enterprises backend-resources, hackers can execute sophisticated attacks that are almost untraceable, aiming to steal, modify or delete enterprises vital data, even when it is protected by passwords or encryption.§As recent viruses and worms such as Nimda, CodeRed or MSBlast have shown, modern attacks are occurring at the application itself, since this is where high-value information is most vulnerable. Such attack scenarios a becoming very problematic nowadays, since traditional network security products such as firewalls or network intrusion detection systems are completely blind to those malicious activities and therefore can not offer any protection at all. Modern protection mechanisms require more sophisticated detection capabilities in order to protect enterprises assets from such attacks now and in the future.§Additionally web application security currently is a highly dynamic and also very emerging field within enterprises IT security activities. Therefore this diploma thesis aims to provide a strong focussed picture on the current state of web application security and its different possibilities to raise the overall security level of already implemented web applications and also of future web applications.§Acting as a basis for further analysis, the currently most common web application vulnerabilities are described to get an overview of what a web application has to be protected of and where the root problems of these weaknesses are lying. Although these generic categories may not be applicable to every actually implemented web application, they may be used as baseline for future web applications.§Armed with the background of the current vulnerabilities and their related root causes, a detailed analysis of currently available countermeasures will provide recommendations that may be taken at each of the certain stages of a web application s lifecycle. Since all further decisions generally should be based upon risk evaluations of specifically considered systems, a possible risk management assessment methodology is provided within the thesis.§Controls and countermeasures are provided from an attack s timeline perspective, describing preventive countermeasures attached to each certain stage within the web application lifecycle and also different protective controls which are actively capable to defend enterprises from being successfully attacked. These countermeasures are analyzed form a functionality point of view, followed by currently available products providing such dedicated mechanisms. If available, such products and technologies were additionally judged with analyst s perspectives for the provision of a more prospective view on current possibilities and future opportunities.§Inhaltsverzeichnis:Table of Contents:§1.Introduction1§1.1The Business Perspective1§1.1.2The Problem inherent to Web Applications2§1.1.3Different Forms of Attacks4§1.2Basics of Web Application Security5§1.2.1The Basic Principles of Security5§1.2.2Common Security Terms Defined6§1.2.3Application Security A Holistic Approach6§1.3Contents of this Thesis8§2.Architecture of a Web Applications9§2.1The Logical View10§2.2The Physical View10§2.3Communication between Web Client and Web Server12§2.3.1The ISO/OSI Reference Model12§2.3.2HTTP13§2.3.3HTTP over SS...

Parametry knihy

Zařazení knihy Knihy v angličtině Computing & information technology Information technology: general issues Internet: general works

2605

Oblíbené z jiného soudku



Osobní odběr Praha, Brno a 12903 dalších

Copyright ©2008-24 nejlevnejsi-knihy.cz Všechna práva vyhrazenaSoukromíCookies


Můj účet: Přihlásit se
Všechny knihy světa na jednom místě. Navíc za skvělé ceny.

Nákupní košík ( prázdný )

Vyzvednutí v Zásilkovně
zdarma nad 1 499 Kč.

Nacházíte se: