Managed Security: Build It Right the First Time

Managed Security: Build It Right the First Time

roviding a service on the Web entails a wealth of concerns, from system design, network architecture, and application development, to maintenance and security. This last aspect is often overlooked and undervalued because proactive application, system, and network security offer little tangible return. Not until a Web service vulnerability causes loss of money, damage of reputation, and loss of customer confidence does security rise to the fore.

Building and maintaining a strong security environment has two primary phases: initial deployment and ongoing maintenance. The initial deployment is much like building a Middle Ages castle. The defenses for these stone fortresses were not just a wall or a moat but a study in the concept of “defense in depth” with a series of security controls intended to thwart attacks. Most castles had a series of inner walls in addition to their primary outer barriers, which allowed for a controlled retreat into a layered defense. Like the castle, a secure Web environment should be designed to control the movement of malicious, or potentially malicious, persons and slow any attacks that manage to breach one layer of defense.

The second major aspect of security, maintenance, is often neglected because it requires sustained vigilance. Take the castle once again. Without guards in watchtowers, locked gates, and constant vigilance, the walls, moat, and other defenses can be useless. If the drawbridge is left down, or worse a side gate left unlocked, the attackers can simply bypass the wall defenses all together.

Now, consider your environment. You have hardened your servers, configured your routers, and patched all known security vulnerabilities. Your castle is secure and all the doors are locked, so you and all the guards sleep soundly. But is your environment secure? Of course not. If all the systems administrators, network administrators, and application developers don’t keep a watchful eye, your castle will be overrun as soon as an attacker finds a way to bypass all those defenses.

To design secure Web services you must not only build a secure environment but also maintain a strong security stance. One without the other is of no value.

Check It—Constantly
Although occasional checks and fixes provide a relatively strong barrier against known attacks such as worms, viruses, or the latest directory traversal, more insidious attacks often will test the defenses of your Web services. These attacks are often quite dangerous because they rarely are noticed during the course of normal business and are stealthy enough to slip past inattentive network and systems administrators. Maintenance, then, is not merely applying the latest hotfixes and patches, but a frame of mind. Logs are culled for potential signs of danger, port scans and probes of network security are not set aside as unimportant, but instead are monitored and investigated frequently.

Maintenance is one percent applying patches and access control lists (ACLs) and 99 percent vigilance in monitoring, log examination, and traffic-pattern analysis. In short, it can be very dull. However, this vigilance is far more important than building a secure Web service alone. Even if a service is insecure but a vigilant administrator, engineer, or developer monitors its activity, the chances of an attack succeeding are dramatically reduced.

Managed Security Solutions: The Cure for Security Tedium
The most tedious and mind-numbing aspects of the security work, culling log files, performing traffic analysis, and monitoring application and database access, are the most important. So how do you assure the peace of mind of having a secure, well-maintained environment without culling through the proverbial haystack to find a vulnerability needle? Well, this is where managed security solutions (MSS) come in handy.

Managed security solutions will make the jobs of traffic-pattern analysis, log file parsing and examination, and application-use mapping much easier. Security utilities such as WebTrends, Netsaint, Tripwire, Stealth Scanner, and Whisker (see Web Server Scanners: Find Your Vulnerabilities Before Hackers Do), which can be integral parts of a MSS, provide assistance in the aspects of maintenance so often missed by even the most diligent systems, network, and application engineers.

You can design an MSS in-house, outsource it to an MSS provider, or adopt MSS third-party software. The design documents from the initial phases of your Web service construction will help to define your requirements for an MSS. If, for example, you have a very small Web farm with load balancers and only a small Internet-facing presence, perhaps a MSS that performs network assessment primarily and server and application assessment secondarily is not the most fruitful way to go. If a large network presence surrounds your server farms but the farms are well controlled and maintained by an army of systems administrators, then your ideal MSS will focus on the network and application. Footprinting Verifies Strengths and Weaknesses
You can use several methods to verify the security of your Web services and the environment in which they run. These methods entail a strong understanding of the application, the systems, and the network, and if done properly will provide an overall view of the security posture surrounding each aspect of the Web service.

Footprinting, the process of gathering data regarding a specific network environment, provides a snapshot of the entire Web service environment’s security posture. By the environment, I mean not just the application, the network, and the servers, or the patch levels, hotfix levels, and service-pack levels, but all of these things and more. For example, footprinting often will detect that rogue Web server in the marketing department running an unpatched version of the OS, Web server, or application server, an inviting target that could lead to a compromise of the primary Web service platform (depending on trust issues within the corporate network environment). (see Build a Managed Security Solution for Your Web Servers with Open Source Tools for a guide to footprinting with open source scanners.)

Footprinting also will show the state of the network, the routers, and the ACLs that surround the applications and servers. Do these routers allow access to the internal network if a certain TCP/IP source port is used? Perhaps DNS zone transfers are performed regularly, and as such port 53/TCP is allowed to enter into the network. These sorts of exceptions often are inroads for an attacker. By footprinting the environment regularly and making sure to examine the results, the chances are much higher for someone within the organization to discover that rogue Web server or notice that anomalous traffic before an outsider breaks through the defenses.

Build It Right the First Time
Let’s look at a simple example of a Web application architecture and its surrounding infrastructure: online stock trading in the nascent design state. The systems engineers and administrators decide on a platform, operating system (OS), and Web server. The network engineers and administrators decide on a network architecture and infrastructure. Finally, the application developers develop an application to utilize the system and network architecture. Initially, the systems engineers and administrators design a secure platform for the software. Realizing the need for strong security, they apply all available service packs, patches, and hotfixes as part of the system design specification and configure their servers and software to secure the platform at an application server level.

In tandem with the systems engineers, the network engineers design a secure network architecture that will meet the needs of the business. This architecture also incorporates patches and hotfixes for the network hardware, and includes configuration changes to control the flow of traffic between the inside and outside networks. The network is now secure for traffic to flow to and from the servers.

Finally, the developers design a secure application. They perform proper input validation, manage sessions in a viable, secure manner, and use encrypted transport mechanisms. Moreover, they place no trust on the client, a practice in application design that leads to many pitfalls.

If any of these three aspects were designed poorly: a hotfix missed, a router not configured properly, or an error in application development allowed the use of clear-text protocols, then the entire design’s security will fail.

devx-admin

devx-admin

Share the Post:
Software Development

Top Software Development Companies

Looking for the best in software development? Our list of Top Software Development Companies is your gateway to finding the right tech partner. Dive in

India Web Development

Top Web Development Companies in India

In the digital race, the right web development partner is your winning edge. Dive into our curated list of top web development companies in India,

USA Web Development

Top Web Development Companies in USA

Looking for the best web development companies in the USA? We’ve got you covered! Check out our top 10 picks to find the right partner

Clean Energy Adoption

Inside Michigan’s Clean Energy Revolution

Democratic state legislators in Michigan continue to discuss and debate clean energy legislation in the hopes of establishing a comprehensive clean energy strategy for the

Chips Act Revolution

European Chips Act: What is it?

In response to the intensifying worldwide technology competition, Europe has unveiled the long-awaited European Chips Act. This daring legislative proposal aims to fortify Europe’s semiconductor

Revolutionized Low-Code

You Should Use Low-Code Platforms for Apps

As the demand for rapid software development increases, low-code platforms have emerged as a popular choice among developers for their ability to build applications with

Software Development

Top Software Development Companies

Looking for the best in software development? Our list of Top Software Development Companies is your gateway to finding the right tech partner. Dive in and explore the leaders in

India Web Development

Top Web Development Companies in India

In the digital race, the right web development partner is your winning edge. Dive into our curated list of top web development companies in India, and kickstart your journey to

USA Web Development

Top Web Development Companies in USA

Looking for the best web development companies in the USA? We’ve got you covered! Check out our top 10 picks to find the right partner for your online project. Your

Clean Energy Adoption

Inside Michigan’s Clean Energy Revolution

Democratic state legislators in Michigan continue to discuss and debate clean energy legislation in the hopes of establishing a comprehensive clean energy strategy for the state. A Senate committee meeting

Chips Act Revolution

European Chips Act: What is it?

In response to the intensifying worldwide technology competition, Europe has unveiled the long-awaited European Chips Act. This daring legislative proposal aims to fortify Europe’s semiconductor supply chain and enhance its

Revolutionized Low-Code

You Should Use Low-Code Platforms for Apps

As the demand for rapid software development increases, low-code platforms have emerged as a popular choice among developers for their ability to build applications with minimal coding. These platforms not

Cybersecurity Strategy

Five Powerful Strategies to Bolster Your Cybersecurity

In today’s increasingly digital landscape, businesses of all sizes must prioritize cyber security measures to defend against potential dangers. Cyber security professionals suggest five simple technological strategies to help companies

Global Layoffs

Tech Layoffs Are Getting Worse Globally

Since the start of 2023, the global technology sector has experienced a significant rise in layoffs, with over 236,000 workers being let go by 1,019 tech firms, as per data

Huawei Electric Dazzle

Huawei Dazzles with Electric Vehicles and Wireless Earbuds

During a prominent unveiling event, Huawei, the Chinese telecommunications powerhouse, kept quiet about its enigmatic new 5G phone and alleged cutting-edge chip development. Instead, Huawei astounded the audience by presenting

Cybersecurity Banking Revolution

Digital Banking Needs Cybersecurity

The banking, financial, and insurance (BFSI) sectors are pioneers in digital transformation, using web applications and application programming interfaces (APIs) to provide seamless services to customers around the world. Rising

FinTech Leadership

Terry Clune’s Fintech Empire

Over the past 30 years, Terry Clune has built a remarkable business empire, with CluneTech at the helm. The CEO and Founder has successfully created eight fintech firms, attracting renowned

The Role Of AI Within A Web Design Agency?

In the digital age, the role of Artificial Intelligence (AI) in web design is rapidly evolving, transitioning from a futuristic concept to practical tools used in design, coding, content writing

Generative AI Revolution

Is Generative AI the Next Internet?

The increasing demand for Generative AI models has led to a surge in its adoption across diverse sectors, with healthcare, automotive, and financial services being among the top beneficiaries. These

Microsoft Laptop

The New Surface Laptop Studio 2 Is Nuts

The Surface Laptop Studio 2 is a dynamic and robust all-in-one laptop designed for creators and professionals alike. It features a 14.4″ touchscreen and a cutting-edge design that is over

5G Innovations

GPU-Accelerated 5G in Japan

NTT DOCOMO, a global telecommunications giant, is set to break new ground in the industry as it prepares to launch a GPU-accelerated 5G network in Japan. This innovative approach will

AI Ethics

AI Journalism: Balancing Integrity and Innovation

An op-ed, produced using Microsoft’s Bing Chat AI software, recently appeared in the St. Louis Post-Dispatch, discussing the potential concerns surrounding the employment of artificial intelligence (AI) in journalism. These

Savings Extravaganza

Big Deal Days Extravaganza

The highly awaited Big Deal Days event for October 2023 is nearly here, scheduled for the 10th and 11th. Similar to the previous year, this autumn sale has already created

Cisco Splunk Deal

Cisco Splunk Deal Sparks Tech Acquisition Frenzy

Cisco’s recent massive purchase of Splunk, an AI-powered cybersecurity firm, for $28 billion signals a potential boost in tech deals after a year of subdued mergers and acquisitions in the

Iran Drone Expansion

Iran’s Jet-Propelled Drone Reshapes Power Balance

Iran has recently unveiled a jet-propelled variant of its Shahed series drone, marking a significant advancement in the nation’s drone technology. The new drone is poised to reshape the regional

Solar Geoengineering

Did the Overshoot Commission Shoot Down Geoengineering?

The Overshoot Commission has recently released a comprehensive report that discusses the controversial topic of Solar Geoengineering, also known as Solar Radiation Modification (SRM). The Commission’s primary objective is to

Remote Learning

Revolutionizing Remote Learning for Success

School districts are preparing to reveal a substantial technological upgrade designed to significantly improve remote learning experiences for both educators and students amid the ongoing pandemic. This major investment, which

Revolutionary SABERS Transforming

SABERS Batteries Transforming Industries

Scientists John Connell and Yi Lin from NASA’s Solid-state Architecture Batteries for Enhanced Rechargeability and Safety (SABERS) project are working on experimental solid-state battery packs that could dramatically change the

Build a Website

How Much Does It Cost to Build a Website?

Are you wondering how much it costs to build a website? The approximated cost is based on several factors, including which add-ons and platforms you choose. For example, a self-hosted

Battery Investments

Battery Startups Attract Billion-Dollar Investments

In recent times, battery startups have experienced a significant boost in investments, with three businesses obtaining over $1 billion in funding within the last month. French company Verkor amassed $2.1