Custom Search
|
|
Web Application Security: Expecting Threats!
• S stands for Spoofing or the attempt to gain access to a particular system by using false information to represent false user identity. This is easily achieved by simply utilizing stolen user untrue IP address. • T stands for tampering which basically speaks of altering data. • R stands for Repudiation which is the ability of a certain user to easily decline specific transactions. The absence of auditing makes this activity difficult to uncover. • I is for Information disclosure or simply the unwanted or intentional exposure of pertinent private personal data. • D, on the other hand, is the Denial of service which can be easily done is merely forcing them to be unavailable. Bombarding the server is the most common tool used by hackers and manipulators. • Lastly, E is for Elevation of privilege which can be done by merely using the identity of a privileged user. Thus it compromises and the entire trusted account or financial procedure. Strengthening the web application security can be done by counter measuring the entire STRIDE group. One way is by using a much stronger authentication procedure. Avoiding using plaintext for passwords can also be very useful. Using tools which are tamper-proof such as digital signature is always a smart idea to combat the effects. Article Directory: http://www.articledashboard.com Paul Walsh is writer of many websites and he enjoys writing on wide range of topics such as Web Application Security and Web Application Security strategies. You may visit for more details. |
|
© 2005-2011 Article Dashboard