• DocumentCode
    2013968
  • Title

    Assessing and Comparing Security of Web Servers

  • Author

    Mendes, Naaliel ; Neto, Afonso Araújo ; Duraes, Joao ; Vieira, Marco ; Madeira, Henrique

  • Author_Institution
    CISUC, Univ. of Coimbra, Coimbra, Portugal
  • fYear
    2008
  • fDate
    15-17 Dec. 2008
  • Firstpage
    313
  • Lastpage
    322
  • Abstract
    This paper presents an approach to assess security of Web servers. This method can be used to compare the security features of different Web servers installations and to determine how secure a given Web server configuration is. The assessment is done by applying a set of tests designed to check if the system under evaluation fulfils a set of security practices defined by an extensive field study. This work targets the most typical issues related to Web servers ranging from classic Web servers misconfiguration to the absence of a secure network infrastructure and of well-defined security policies to respond to security incidents. The effectiveness and usefulness of the proposed approach is illustrated through the security assessment and comparison of five different real Web servers.
  • Keywords
    Internet; file servers; formal verification; security of data; Web server; formal verification; security assessment; Best practices; IEC standards; ISO standards; Information security; NIST; National security; Performance evaluation; Reproducibility of results; System testing; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Dependable Computing, 2008. PRDC '08. 14th IEEE Pacific Rim International Symposium on
  • Conference_Location
    Taipei
  • Print_ISBN
    978-0-7695-3448-0
  • Electronic_ISBN
    978-0-7695-3448-0
  • Type

    conf

  • DOI
    10.1109/PRDC.2008.45
  • Filename
    4725311