AccessMyLibrary provides FREE access to over 30 million articles from top publications available through your library.

SECURING NETWORK SOFTWARE APPLICATIONS.(Internet/Web/Online Service Information)

Communications of the ACM

| February 01, 2001 | Bashir, Imran; Serafini, Enrico; Wall, Kevin | COPYRIGHT 2001 Association for Computing Machinery, Inc. This material is published under license from the publisher through the Gale Group, Farmington Hills, Michigan.  All inquiries regarding rights should be directed to the Gale Group. (Hide copyright information)Copyright

ASK A SCHOOL-AGE child about Melissa, and instead of hearing about the "red-haired girl in Mrs. Stiefel's class," the most likely answer would point to the Microsoft Word macro virus that wreaked havoc around the world in March 1999. The impact of the ubiquitous World Wide Web, the fastest growing element of the Internet, is mind-boggling. The debate about its social and economic impacts will go on for ages, but one fact remains--the Internet is here to stay. Today we have the ability to conduct online shopping, talking, dating, and even smelling(1) (business-to-consumer; B2C). Similarly, businesses can share and exchange information for more efficient business practices (business-to-business; B2B). And in the same vein, individuals--most of the time complete strangers--exchange useful and sometimes profitable information with each other (individual-to-individual; i2i) [1]. Information sharing over the Internet has become a prevailing practice in every segment of our esociety.

While extremely useful for conducting day-to-day business operations, the proliferation of e-commerce over the Internet has provided a perfect target for computer crackers, script-kiddies, and other such bad guys. Since the Web is being utilized by both small and large corporations, and by governments for conducting their business electronically, people with malicious intent do not have to leave their computers to bring a business to its knees. Although it is a little more difficult to take down a government's computer networks, it can be done. Recent cyber-warfare attacks between the Palestinians and Israelis in the Middle East conflicts indicate this is probably likely to become more common in the future. The reliance of a business on the Internet makes it extremely vulnerable to all sorts of attacks. While some readers may be viewing these words over the Internet, we can safely say that many people are trying to discover illegitimate ways to exploit loopholes in computers around the world.

Completely securing a computer against unauthorized access is extremely difficult--there are many ways for an attacker to gain access. In general, however, an attacker employs the easiest ways to fulfill his or her malicious intentions. Some of these attacks include shoulder surfing, dumpster diving, network sniffing, exploiting code weaknesses (such as buffer overflows), denial-of-service attacks, and others. These attacks can come from outside as well as from within. Hence, it is equally important to provide adequate safeguards for both internal and external threat sources.

At this point, it is important to understand some basic terminology. What exactly is security? According to Descartes, we know what time is until we are asked to define it. Similarly, we know or have a sense of what security is. But regardless of how we define it, security is a multidimensional concept that needs to be explored in detail to understand and measure it. Some of these dimensions include privacy; physical access restrictions, application availability, network confidentiality, content integrity, and access policy. Each of these dimensions is continuously evolving in terms of both scope and solution, but no standards can effectively address the subject. Security is all about managing risks. When people think of security, they generally refer to one or more of the following aspects (definitions as described by the Internet Society [1] are as follows):

* Authentication: The process of verifying an identity claimed by or for a system entity.

* Access control: Protection of system resources against unauthorized access; a process by which use of system resources is regulated according to a security policy and is permitted by only authorized entities (users, programs, processes, or other systems) according to that policy.

* Audit trail: A chronological record of system activities that is sufficient to enable the reconstruction and examination of the sequence of environments and activities surrounding or leading to an operation, procedure, or event in a security-relevant transaction from inception to final results.

Related articles from newspapers, magazines, journals, and more
National University System Announces Commitment to Hawaii; Chancellor Appoints...
Press release article from: Business Wire September 20, 2004 700+ words
...Prior to that, Foster was CEO and president of hotU, an Internet service provider, and founder of Brew Moon Hawaii. She also...institutions dedicated to fulfilling unmet educational needs. Each System entity is committed to providing innovative and relevant educational...
Internet In A Box 2.0 -- the first retail product to integrate a full suite of...
Press release article from: Business Wire June 5, 1995 700+ words
...longer have to choose between an online service or Internet software, Internet In A Box 2.0 provides the best of both worlds. SPRY, the centerpiece of CompuServe's newly formed Internet Division, announced today that Internet In A Box...
internet.com Launches Toronto.internet.com; Continuing Regional Expansion...
Press release article from: Business Wire November 14, 2000 700+ words
Business Editors/Internet Writers NEW YORK--(BUSINESS WIRE)--Nov. 14, 2000 internet.com (Nasdaq:INTM), the Internet Industry Portal, today launched a new bureau to cover the thriving Internet market and community in the greater...
internet.com Expands Global Reach With Foreign Language Web Sites in Belgium,...
Press release article from: Business Wire April 27, 2000 700+ words
...part of its ongoing international expansion, internet.com (Nasdaq: INTM), the Internet Industry Portal, today unveiled four new international business-to-business portals for the Internet industry-- espanol.internet.com (http...
internet.com Announces Content Alliance With Australia's Leading Internet...
Press release article from: Business Wire March 14, 2000 700+ words
...Australia--(BUSINESS WIRE)--March 14, 2000 internet.com (Nasdaq: INTM), The Internet Industry's Portal, today announced a content alliance with Australia's leading Internet portal, ninemsn, a joint venture between...
internet.com Launches Atlanta.internet.com.
Press release article from: Business Wire February 1, 2001 700+ words
...Writers NEW YORK--(BUSINESS WIRE)--Feb. 1, 2001 internet.com Corporation (Nasdaq: INTM), the Internet Industry Portal, today launched a new bureau to cover the thriving Internet business community in the greater Atlanta region. The...
internet.com Launches Phoenix.internet.com, Its Ninth Regional Site, to Serve...
Press release article from: Business Wire October 16, 2000 700+ words
...Editors NEW YORK--(BUSINESS WIRE)--Oct. 16, 2000 internet.com Corporation (Nasdaq: INTM), the Internet Industry Portal, today launched a new bureau to cover the thriving Internet market and community in the greater Phoenix area. The...
internet.com Continues Regional Expansion With Launch of miami.internet.com.
Press release article from: Business Wire September 19, 2000 700+ words
...Editors NEW YORK--(BUSINESS WIRE)--Sept. 19, 2000 internet.com (Nasdaq: INTM), the Internet Industry Portal, today launched a new bureau to cover the thriving Internet market and community in the greater Miami area that will also...
internet.com to Launch 13th International Edition--taiwan.internet.com.
Press release article from: Business Wire January 18, 2000 700+ words
...Editors DARIEN, Conn.--(BUSINESS WIRE)--Jan. 18, 2000 internet.com (Nasdaq: INTM), The E-Business and Internet Technology Network (http://www.internet.com), today announced plans to launch an international edition...
internet.com Expands Global Reach With International Sites in Hong Kong, Italy,...
Press release article from: Business Wire October 25, 2000 700+ words
...BUSINESS WIRE)--Oct. 25, 2000 internet.com Corporation (Nasdaq:INTM), the Internet Industry Portal, today announced the launch...business-to-business portals for the Internet industry -- hongkong.internet.com...
For more facts and information, see all results
©2009 Gale, a part of Cengage Learning. All rights reserved.
About us | FAQs | Contact us | Privacy policy | Terms and conditions
Other Gale sites: Encyclopedia.com | HighBeam Research | Acquire Content | Books & Authors | Goliath | MovieRetriever | Smart QandA