8
INFORMATION SECURITY UNIX & DB2

INFORMATION SECURITY UNIX & DB2. Introduction THE OBJECTIVE IS TO DESIGN SECURITY MEASURES FOR A MILITARY SYSTEM SYSTEM RUNNING A DB2 SERVER ON UNIX FOCUS

Embed Size (px)

Citation preview

Page 1: INFORMATION SECURITY UNIX & DB2. Introduction THE OBJECTIVE IS TO DESIGN SECURITY MEASURES FOR A MILITARY SYSTEM SYSTEM RUNNING A DB2 SERVER ON UNIX FOCUS

INFORMATION SECURITYUNIX & DB2

Page 2: INFORMATION SECURITY UNIX & DB2. Introduction THE OBJECTIVE IS TO DESIGN SECURITY MEASURES FOR A MILITARY SYSTEM SYSTEM RUNNING A DB2 SERVER ON UNIX FOCUS

Introduction• THE OBJECTIVE IS TO DESIGN SECURITY MEASURES

FOR A MILITARY SYSTEM

• SYSTEM RUNNING A DB2 SERVER ON UNIX

• FOCUS IS ON DB2 BACKEND VULNERABILITIES

Page 3: INFORMATION SECURITY UNIX & DB2. Introduction THE OBJECTIVE IS TO DESIGN SECURITY MEASURES FOR A MILITARY SYSTEM SYSTEM RUNNING A DB2 SERVER ON UNIX FOCUS

UNIX VULNERABILITIES BIND DOMAIN NAME SYSTEM

REMOTE PROCEDURE CALLS

APACHE WEB SERVER

Page 4: INFORMATION SECURITY UNIX & DB2. Introduction THE OBJECTIVE IS TO DESIGN SECURITY MEASURES FOR A MILITARY SYSTEM SYSTEM RUNNING A DB2 SERVER ON UNIX FOCUS

STRENGTHENING UNIX FIREWALLS

REGULAR UPDATES

STRINGENT USER ACCOUNT MANAGEMENT

ENCRYPTION

Page 5: INFORMATION SECURITY UNIX & DB2. Introduction THE OBJECTIVE IS TO DESIGN SECURITY MEASURES FOR A MILITARY SYSTEM SYSTEM RUNNING A DB2 SERVER ON UNIX FOCUS

WEB SERVER DEPLOYMENT 2 SERVERS WILL BE DEPLOYED IN 2 LOCATIONS

THE SERVERS WILL BE SET TO AUTOMATICALLY SYNCHRONIZE

THE WEB SERVER WILL NOT USE PORT 80

SECURE FIREWALL CONFIGURATION

Page 6: INFORMATION SECURITY UNIX & DB2. Introduction THE OBJECTIVE IS TO DESIGN SECURITY MEASURES FOR A MILITARY SYSTEM SYSTEM RUNNING A DB2 SERVER ON UNIX FOCUS

APACHE THE MOST POPULAR WEB SERVER WORLD WIDE

HIGH RELIABILITY AND PERFORMANCE

FREE & OPEN SOURCE

CROSS-PLATFORM

MORE SECURE THAN IIS

Page 7: INFORMATION SECURITY UNIX & DB2. Introduction THE OBJECTIVE IS TO DESIGN SECURITY MEASURES FOR A MILITARY SYSTEM SYSTEM RUNNING A DB2 SERVER ON UNIX FOCUS

IIS PRODUCED BY MICROSOFT

SUPPORTS .NET FRAMEWORK AND ASPX SCRIPTS

ONLY RUNS ON WINDOWS

LESS SECURE THAN APACHE

Page 8: INFORMATION SECURITY UNIX & DB2. Introduction THE OBJECTIVE IS TO DESIGN SECURITY MEASURES FOR A MILITARY SYSTEM SYSTEM RUNNING A DB2 SERVER ON UNIX FOCUS

ReferencesRoberta Bragg, C. I. S. S. P., & Rhodes-Oulsey, M. (2004). Network Security: The Complete Reference . The McGraw-Hill/Osborne.