Internet Security: A Jumpstart for Systems Administrators and IT Managers

For several significant reasons, web-based information systems present unique challenges from a security standpoint.
First, web-based systems often force organizations to violate some of the most basic tenets of information security. For example, many e-Business applications require that unknown and, therefore, untrusted users be allowed to interact with critical information systems on internal networks. Anonymous prospects must be able to browse catalogs, check inventory and prices, and even fill "shopping carts." From a technical perspective, not only must firewall ports be opened to allow such communications, but web servers performing real-life business functions must process application-level requests emanating from unidentified sources. If not properly implemented, remote access web-based systems such as SSL VPNs designed for mobile employees to access key systems and file repositories while out of the office require communication channels to be created from the Internet to sensitive systems and data such as e-mail and corporate directories again often forcing organizations to violate sound security policies.
Additionally, web-based systems are accessible from public Internet kiosks, shared or borrowed computers, and other machines over which no organizational control exists generating a whole slew of previously unconsidered problems related to access from "insecure" locations. Temporary files, user credentials, and other sensitive data is often left on machines after users complete their activities. Through the exploitation of various weaknesses, hackers can sometimes even reinstate user sessions that is reestablish sessions of legitimate users who previously used the same computer and wreak tremendous havoc...