< previous page page_287 next page >

Page 287
Planning for security encompasses several areas of potential weaknesses. One such weakness is where buggy software at the server site inadvertently permits external hackers to issue sensitive commands to server applications. Such unauthorized access can ultimately destroy the server, which can cost a company not only lost productivity, but potentially millions of dollars in publicly available trade secrets. Individual users can lose privacy in the form of exposed credit card numbers, Social Security numbers, and bank account numbers not only on the Internet, but in any company that processes sensitive financial information about millions of people.
Other security concerns include the interception of very sensitive information from the user's machine to the server machine, configuration information leaking from the server that a hacker could use to break into and possibly mimic the host, unauthorized access to business Web pages where the hacker could edit them, and unauthorized access to personal Web pages that could be as libelous as having your phone number written on the wall of a public bathroom. It is definitely worthwhile to hire capable, competent network administrators who are experienced in setting up Internet and intranet site servers. It is also advisable to encrypt passwords and other vital information that passes along an organization's network.
One reason that may lend itself to the need for tedious Internet security planning is the fact that the Internet Protocol, commonly referred to as IP, is an open, nonproprietary, Internet-working protocol. All those words simply mean that when something goes wrong with IP security, there is no one company to blame (so you can't blame big software companies like Oracle or Microsoft). Of course, the Transmission Control Protocol (TCP) supplements IP by providing end-to-end reliability over a full-duplex connection.
You should be aware of two areas of network security. Transmission security centers on the flow of data across a network. You implement this kind of security at various network access points, such as encoded transmission devices and modems that are password-protected. Access security tries to control user access to a server's software, hardware, and system services. You filter access control at three layers of the OSI reference model: application, network, and data link. Test the system for security leaks and educate users on the importance of maintaining security before going into production with it. Again, make it a habit to truly encrypt passwords after users enter them into your application.
New Term: Transmission security is the level of protection given to the flow of data across a network.
New Term: Access security is the level of control of user access to a server's software, hardware, and system services.

 
< previous page page_287 next page >

If you like this book, buy it!