Web Security
- Virtually all businesses including government agencies as well as individuals have web sites now-a-days.
- The number of users of web sites and web applications increase rapidly day by day.
- Web browsers are easy to use, web servers are relatively easy to configure and manage, and web content is increasingly easy to develop.
- But, Internet and World Wide Web (WWW) are vulnerable to compromises of various security threats that may challenge the web traffic security of an organisation or an individual.
- The World Wide Web (WWW) provides the platform for client/server applications to run over the Internet and TCP/IP intranets.
- Casual and untrained (in security matters) users are common clients for web based services. Such users are not necessarily aware of the security risks that exist and do not have the tools or knowledge to take effective countermeasures
Web Security Threats:
- One way of classifying attacks on Web can be in terms of their impact on the web: passive attack and active attack
- Passive attacks include eavesdropping on network traffic between browser and server and gaining access to information on a Web site that is supposed to be restricted
- Active attacks include impersonating another user, altering message in transit between client and server, and altering information on a web site.
- Another way of classifying the attack on the Web can be done in terms of the location of its occurrence on the web: web server, web browser, and network traffic between browser and the server.
Web Traffic Security Approaches:
- One way of providing web security is to use IP Security (IPSec) protocol as shown in Figure (a). IPSec is a general-purpose solution for providing security on the internet, which is transparent to end users and applications.
- Another way of implementing web security is to implement security just above TCP (Figure b). In this approach, the protocols such as Secure Socket Layer (SSL) and Transport Layer Security (TLS) could be used on top of the Transport Layer.
- The third approach is providing security at the application layer. In this approach, the application-specific security service such as Kerberos is embedded within the particular application for securing its data transmission on the web.
- One of the most widely used security services for web security is Transport Layer Security (TCL)
- TCL is an Internet standard that evolved from a commercial protocol known as Secure Socket Layer (SSL)
- TLS is a general-purpose service implemented as a set of protocols that rely on TCP
- TLS can be used for web security in two ways:
- TLS could be provided as part of the underlying protocol suit and therefore transparent to applications running above it
- TLS can be embedded in specific application packages, such as web browsers on which web clients are running
- TLS is designed to make use of TCP to provide a reliable end-to-end secure service for the applications running on the application layer

.png)
.png)


No comments:
Post a Comment