The security of information systems is a wide area. Its development followed that of information systems, whose development in turn followed advances in hardware. As computers and software have developed real fast: “To put it quite bluntly: as long as there were no machines, programming was no problem at all; when we had a few weak computers, programming became a mild problem, and now we have gigantic computers, programming had become an equally gigantic problem.” [1], so have developed the possibilities for security breaches.
Security and protection are very important areas of computers science and IT industry. One way to describe this area is: “Security can be defined as set of methods and techniques which control data accessed by executing applications. Even wide definition includes a set of methods, techniques and legal standards which control data access by applications and humans, and protect the physical integrity of whole computer system, no matter if it is distributed or not, or if it is centralized or decentralized.”
According to the American Computer Security Institute (CSI)’s 2005 Computer Crime and Security Survey, which enclosed big corporations, 56% of the subjects reported the detection of unauthorized use of their computer systems in last year. Also, according to the same survey, more than 95% of responding organizations experienced more than 10 Web site incidents. [3]. Today IT security has many sub areas focusing on different aspects of security, from lower levels of ISO OSI model, all the way to the application layer. Since security in lower levels has made significant improvements in past time, hackers try to get their way into system using the topmost layer. The application layer is specially exposed when used on the Internet in the form of the Web applications.
This paper will try to shed some light on making the Web applications more secure, since this area is mostly the responsibility of developer or is an effect of joint effort of developers and administrators.
Download pdf Common Web Application Attack Types and Security Using ASP.NET
Related Searches: computer security institute, security breaches, physical integrity, topmost layer, significant improvements
RSS feed for comments on this post · TrackBack URI
Leave a reply