Home > Ask the Security Experts > Identity Management and Access Control Questions & Answers > How to improve Web access controls
Ask The Security Expert: Questions & Answers
EMAIL THIS

How to improve Web access controls

Joel Dubin EXPERT RESPONSE FROM: Joel Dubin

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 11 May 2006
I need to control user access to different Web sites. For example, permit user1 to access www.yahoo.com after providing a username and password, but deny access for user2 (or require an admin password). In other words, I need software that stores different users' profiles and what they can and cannot access. What proxy server or firewall would give me such facility?

>
EXPERT RESPONSE
To provide granular access to specific Internet sites for specific users, you need to augment your existing proxy server, or firewall, with a Web filtering appliance. While you can tune proxies and firewalls to block certain kinds of traffic and Web sites, they don't work as well for individual user profiles.

Web filtering products, such as Websense, Blue Coat and 8e6, operate as appliances meshed into your firewall system, but unlike firewalls, they are deployed to block specific content. You can tailor Web filters to your company's particular policies for employee Internet use. They can use white and black lists to control what users can and cannot access.

The obvious targets, like pornography and gambling sites, would most likely be on most companies' hit list for the deployment of Web filtering proxies. However, if your company has a policy against employees accessing personal email accounts on company time, these products can do the job.

Again, unlike firewall rules, which are based on traffic, these products can be adjusted to allow selective access to individual employees or groups of employees that may need special access for business reasons. Websense, for example, has a User Service software component that calls your directory service, whether Active Directory (AD) or LDAP, to filter users based on any size and type of organizational unit from domains down to individual users. Blue Coat and 8e6 both offer similar user authentication schemes in their products that work with AD and LDAP, as well.

Although these filtering products don't store profiles, they do work with the profiles in your existing authentication systems to allow or block individual and group access. That's why it's important to check how these products work with your directory services, before purchasing one.

For More Information

  • Visit our resource center and learn how to improve your enterprise Web access controls.
  • .


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Identity Management and Access Control
    Should a new user have to confirm his or her email address before gaining access?
    Can home PCs provide a way for viruses and spyware to enter a corporate LAN?
    What should an enterprise look for in a password token, and in a vendor?
    Is it possible to write a batch file that allows user access to the local admin group for a short time?
    IAM best practices for employees with varying degrees of access to the same computer
    What are some good pre-boot biometric user authentication tools or strategies?
    If the encryption on the Mifare Classic RFID has been cracked, are smart cards insecure?
    How does the Group Policy Object interact with the 'Password Never Expires' flag?
    How do RFID-blocking passport wallets work?
    What are the benefits of identity managed as a service?

    Web Access Control
    Sun launches open source OpenSSO for identity management
    Should a new user have to confirm his or her email address before gaining access?
    Shared Identity Providers Could Soothe Password Chaos
    Users are complaining that they can no longer reach any login site belonging to Microsoft. Any ideas?
    Vista WIL: How to take control of data integrity levels
    Video: Changes ahead for MIT Kerberos Consortium
    Kerberos security evolves for B2B, mobile tech
    Kerberos: Authentication with some drawbacks
    Sun shifts strategy with GRC push
    CardSpace vs. user IDs and passwords

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    access log  (SearchSecurity.com)
    anonymous Web surfing  (SearchSecurity.com)
    authentication, authorization, and accounting  (SearchSecurity.com)
    identity chaos  (SearchSecurity.com)
    multifactor authentication (MFA)  (SearchSecurity.com)
    walled garden  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts