DocumentCode
2013968
Title
Assessing and Comparing Security of Web Servers
Author
Mendes, Naaliel ; Neto, Afonso Araújo ; Duraes, Joao ; Vieira, Marco ; Madeira, Henrique
Author_Institution
CISUC, Univ. of Coimbra, Coimbra, Portugal
fYear
2008
fDate
15-17 Dec. 2008
Firstpage
313
Lastpage
322
Abstract
This paper presents an approach to assess security of Web servers. This method can be used to compare the security features of different Web servers installations and to determine how secure a given Web server configuration is. The assessment is done by applying a set of tests designed to check if the system under evaluation fulfils a set of security practices defined by an extensive field study. This work targets the most typical issues related to Web servers ranging from classic Web servers misconfiguration to the absence of a secure network infrastructure and of well-defined security policies to respond to security incidents. The effectiveness and usefulness of the proposed approach is illustrated through the security assessment and comparison of five different real Web servers.
Keywords
Internet; file servers; formal verification; security of data; Web server; formal verification; security assessment; Best practices; IEC standards; ISO standards; Information security; NIST; National security; Performance evaluation; Reproducibility of results; System testing; Web server;
fLanguage
English
Publisher
ieee
Conference_Titel
Dependable Computing, 2008. PRDC '08. 14th IEEE Pacific Rim International Symposium on
Conference_Location
Taipei
Print_ISBN
978-0-7695-3448-0
Electronic_ISBN
978-0-7695-3448-0
Type
conf
DOI
10.1109/PRDC.2008.45
Filename
4725311
Link To Document