论文部分内容阅读
1.建立防火墙。如果你还没有安装防火墙来保护运行你的站点的Web服务器,那么应该立刻安装。这是抵御黑客侵袭的第一道防线。2.将公共网络与专用网络分开。确保运行公共Web站点的Web服务器在物理上与企业内部网络相分离,而且从内部网对它进行独立的保护。如果有人想侵入你的Web站点,你一定不希望那个人找到获取企业内部敏感数据的突破点。3.从开始就正确配置。ICSA(www.icsa.net)报告称,采用经过认证的防火墙的站点中有70%由于错误的配置和不当的布署,仍然容易受到攻击。配置有问题的防火墙保护效果不会太好。另外,Web、电子邮件、FTP和新闻服务器都有人所共知的漏洞(版本过时、错误配置、不合理的权限等),这些都需要全面考虑,因此需要专家来帮助你完成每一个步骤。
Create a firewall If you have not installed a firewall to protect your web server running your site, you should install it now. This is the first line of defense against hacking. 2. Separate the public network from the private network. Make sure that the Web server running the public Web site is physically separate from the corporate intranet and is independently protected from the intranet. If someone wants to hack into your Web site, you certainly do not want that person to find a breakthrough point in getting sensitive data inside your organization. 3 from the beginning on the correct configuration. ICSA (www.icsa.net) reports that 70% of sites using certified firewalls are still vulnerable due to incorrect configuration and improper deployment. Configure the firewall protection problem will not be too good. In addition, there are well-known vulnerabilities in Web, email, FTP, and news servers (outdated, misconfigured, unreasonable permissions, etc.) that need to be fully considered and require experts to help you with every step of the way.