Title :
Assessing and Comparing Security of Web Servers
Author :
Mendes, Naaliel ; Neto, Afonso Araújo ; Duraes, Joao ; Vieira, Marco ; Madeira, Henrique
Author_Institution :
CISUC, Univ. of Coimbra, Coimbra, Portugal
Abstract :
This paper presents an approach to assess security of Web servers. This method can be used to compare the security features of different Web servers installations and to determine how secure a given Web server configuration is. The assessment is done by applying a set of tests designed to check if the system under evaluation fulfils a set of security practices defined by an extensive field study. This work targets the most typical issues related to Web servers ranging from classic Web servers misconfiguration to the absence of a secure network infrastructure and of well-defined security policies to respond to security incidents. The effectiveness and usefulness of the proposed approach is illustrated through the security assessment and comparison of five different real Web servers.
Keywords :
Internet; file servers; formal verification; security of data; Web server; formal verification; security assessment; Best practices; IEC standards; ISO standards; Information security; NIST; National security; Performance evaluation; Reproducibility of results; System testing; Web server;
Conference_Titel :
Dependable Computing, 2008. PRDC '08. 14th IEEE Pacific Rim International Symposium on
Conference_Location :
Taipei
Print_ISBN :
978-0-7695-3448-0
Electronic_ISBN :
978-0-7695-3448-0
DOI :
10.1109/PRDC.2008.45