|
|
|
|
|
|
|
New Term: Access control is an object whose responsibility it is to secure any access checkpoint, such as the client application, the request for remote data from a database server, request for services from remote server objects, and so on. |
|
|
|
|
|
|
|
|
Most viruses are harmless in that they only display social messages or, at most, crash your computer system. Harmful viruses are those that delete files or stay resident and eventually render your machine useless unless you reformat your hard disk. |
|
|
|
|
|
|
|
|
Like human viruses, computer viruses spread as you and I use our computers regularly. Viruses that are time-sensitive are sometimes easy to circumvent: simply reset your computer's clock. Of course, if you don't know the virus is resident, you're unlucky. That's what makes viruses potentially devastating for companies. What can you do about this? At the risk of sounding pessimistic, not much. As long as human nature remains unpredictable, expect viruses to live on in cyberspace. Nonetheless, although it's difficult to prevent every virus or security violation, you can help prevent potential hackers from grabbing passwords. This subsystem has an encryption algorithm for ciphering a password. |
|
|
|
|
|
|
|
|
Understanding Security Issues for Internet Applications |
|
|
|
|
|
|
|
|
As mentioned earlier, if you develop software for families, your application will need to keep their young children from accessing certain Web sites that might be harmful to them. Of course, developing applications to keep track of young children doesn't compare to developing an application for a large organization where security violations can cost millions of dollars. |
|
|
|
|
|
|
|
|
For instance, if you fail to track how long a user is not actively interacting with your application, the session may be vulnerable to unauthorized passersby if the user is in fact away from his or her desk. A session unchecked can also leave the intranet environment vulnerable to spying applications that might continuously poll for unattended sessions. For Web-based applications, using a method for checking unattended sessions can help to prevent such snooping. You could create a class called SessionAuditor. It would have a method, trackNonUse, that uses a Variant argument, argMessage, to allow for polymorphic calls. For a Web application, the method implementation would look like the following: |
|
|
|
|
|