Week 7:�Web Server - Hardening Basics�
SEC 260
Web Server Security and CIA
CIA
Confidentiality: Hardening Topics
Web traffic in transit?
Authentication
Least Privilege
Confidentiality: Hardening Topics (cont…)
File System Protections
Data Store Protections
Server-Side Script Protections
Integrity: Hardening Topics
Ensuring data doesn’t change:
Prevent File System Changes
Server-Side Script Protections
Availability: Hardening Topics
Configuration Settings:
Unload unneeded modules/services
Other Hardening Topics
Updates!
Security-Specific Technologies