Web Servers White Papers
Intrusion Detection Preliminaries: Sanitizing Your E-Commerce Web Servers
Overview
Intrusion Detection involves detecting unauthorized access and destructive activity on your computer system. Intrusion Detection is a clear requirement for all e-commerce merchants. According to the annual study released March 22, 2000 by the Computer Security Institute and the FBI, 90% of the survey respondents detected a computer security breach within the last twelve months. The study showed that the most serious financial losses were caused by activities that concern e-commerce merchants directly: theft of proprietary information (e.g., stealing customer credit card numbers), and financial fraud (e.g., setting up a bogus storefront).
For e-commerce merchants, the focus of Intrusion Detection is on the web servers, and their associated database management systems. E-commerce requires that the web servers communicate quickly and accurately with large databases of product and customer information. To optimize performance, these critical databases are, in most cases, placed on the same network segment as the web server, or even on the web server machine itself. For malicious hackers, this is a tempting prize. For hard-core cyber criminals, these databases are paydirt. They will break in to the web server, gain administrator-level access, locate the database, and then go to work on breaking into the database and downloading customer information.
| Publisher | CSCL - Client/Server Connection Ltd. | File Format | HTML |
|---|---|---|---|
| Date Published | April 2000 | Downloads | 14 |
| Format | White Papers | ||
| Topics | |||



