Search and DocFinder
 
Search help/advanced search
 

Vendor Product Showcase



News NetFlash: Daily News Internat'l News This Week in NW The Edge Features Research Buyer's Guides Reviews Technology Primers Vendor Profiles Forums Columnists Knowledgebase Help Desk Dr. Intranet Gearhead Careers Free Newsletters Subscription Center Seminars/Events Reprints/Links White Papers Partner with Us Site Map Contact Us Home









News

Ten ways to protect your Web commerce sites
    1. Limit the number of people who have remote access to your Web site for administration purposes and manage this process closely. Remote administration - the equivalent of root access - gives hackers a great opportunity to sneak in.

    2. Make sure your access control lists are properly configured and constantly updated to reflect the day-to-day needs of your business, such as adding new employees and customers and deleting old ones.

    3. Isolate your commerce server from as many services as possible to avoid vulnerabilities. Harden the server by closing down all extraneous features in the applications and operating system. If you can't do this, seriously consider outsourcing.

    4. Implement an intrusion detection system that immediately alerts managers of problems that need to be corrected. After all, detecting a hacker does nothing; stopping him is the goal.

    5. Make sure your intrusion detection software looks for anomalous behavior on your servers. You can't stop the bad guys if you can't see what they're doing.

    6. Perl and Common Gateway Interface scripts can cause security holes if they're improperly written, configured or installed. Use these development tools sparingly and make sure experienced developers test them.

    7. Passwords just aren't strong enough for some commerce sites. Consider giving customers physical and electronic tokens that cost about $50 each.

    8. Likewise, you want to make sure administrators who have root authority are who they say they are. Biometric solutions to identify voice, fingerprints or retinas are moving to the masses at a cost of roughly $300 per user.

    9. Your site relies on other networks and systems to move money, whether it accepts credit cards or uses a mainframe to complete remote banking transactions. Use secure agents such as Secure Sockets Layer, Secure Hypertext Transfer Protocol or Kerberos to communicate with critical systems.

    10. Think about installing integrity wrappers around critical data and related system files. Cryptographic seals around these files prevent modification or the introduction of malicious code.

- Winn Schwartau

For more info:
Back to the main article

Ten low-cost ways to strengthen your internal security

Five basic security necessities

Ten ways to maintain security vigilance

Security resources from Network World Today's News

ICANN board approves reform agenda

House committee subpoenas WorldCom executives

KPMG Consulting to hire Andersen IT staff, not unit

Xerox accounting troubles may total $6 billion

Analysis: Ciena/ONI deal done


All of today's news

Compendium

A good .plan
Plus: Porn credit-card site hacked.

nutter

Prioritizing voice over data in VoIP
Nutter helps a user make sure voice gets priority on a Cisco net.

Research

E-comm Innovator of the Year Award
Know someone with a groundbreaking e-commerce project? Nominate him or her for our annual award.




  Home
Contact us
Site Map
Today's news
This week in NW
Research
Free newsletters
Forums
Opinions
Careers
Terms of Service
Network World, Inc.
Seminars & Events
Advertiser Index
Product Showcase
Vendor white papers
NW Subscriptions

  Copyright, 1995-2001 Network World, Inc. All rights reserved.