Home > Ask the Security Experts > Expert Archive: Security Management Questions & Answers > What Web security initiatives can be taken on a college campus?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What Web security initiatives can be taken on a college campus?

Mike Rothman, past SearchSecurity.com expert EXPERT RESPONSE FROM: Mike Rothman, past SearchSecurity.com expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 29 October 2007
I'm a final-year student of CSE, and I am planning on doing my final project on Web security. Can you suggest what to focus on?


BROWSE BY TAG
Expert Archive: Security Management,   Information Security Jobs and Training,   Information Security Careers, Training and Certifications,   Application and Platform Security,   Web Security Tools and Best Practices,   Web Application Security,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Expert Archive: Security Management
What is the GISP certification and how does it compare to the CISSP certification?
Using a QSA to write up a PCI DSS report on compliance (ROC)
How can gap analysis be applied to the security SDLC?
Comparing low-cost security appliances to bigger, pricier appliances
What are some tips on protecting my security budget in a poor economy?
What value do research firms provide to their subscribing enterprises?
What certificate offers the best ROI for an IT project manager?
Is insider activity or outsider activity a bigger enterprise threat?
How does information security prevent fraud in the enterprise?
Differences between an SAS 70 data center and a Tier III data center

Information Security Jobs and Training
Security jobs survey finds fewer budget cuts, lower security salaries
IT security skills and certification pay
Information security skills must include communication, expert says
Despite recession, pay climbs for top IT security certifications
How do I transition to a career in IT security?
Information security book excerpts and reviews
Security skills pay increases despite economic downturn
Getting the CEH certification to join an ethical hacking network
Finding a security management job after an economic downturn
How to become an information security expert

Web Application Security
Adobe patches ColdFusion vulnerability blocking website attack
nCircle statistics show rising Web application vulnerabilities
Twitter bugs, DNSSEC and broswer security
Month of Twitter Bugs project to document Twitter flaws
Are Web application penetration tests still important?
IT pros can detect, prevent website vulnerabilities, thwart attacks
PCI compliance requirement 6: Systems and applications
Trust eroding as social engineering attacks climb in 2009, says Kaspersky expert
US-CERT warns of Gumblar, Martuz drive-by exploits
XSS bugs, information leakage top list of website vulnerabilities

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Cisco Certified Security Professional (CCSP)  (SearchSecurity.com)
CSO  (SearchSecurity.com)
security clearance  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


Congratulations on your graduation. It's an exciting time to be an information security professional, since there's no lack of new attacks and systems/applications to protect. I also applaud your interest in Web applications. More than 75% of attacks are now targeting applications as opposed to networks or servers directly. Application security specialists have told me it would take them roughly 100 years to fully test all the applications they already have running. There will be great demand for professionals who understand how to attack and protect Web applications.

You've got a choice in what you attempt for your senior project by taking either an offensive stance or a defensive stance. Let me elaborate.

From an offensive standpoint, you can try to discover new attack vectors or prove that an existing attack vector works for a new application type. For example, try to find XSS (cross-site scripting) vulnerabilities on applications running on your campus. Or attempt a SQL injection attack on the registration system. Of course, work with the faculty and the IT team at your school to make sure you don't surprise the powers that be and end up in jail. But if you are going to test something, it may as well benefit the school.

Taking a defensive stance, you could work with the IT team to implement a source code analysis project on any of the applications currently running. Many of the vendors in the space will provide an educational license to use their commercial-grade tools in an academic environment. Again, this is pretty much a "free" way for your university to see how secure the applications are and what issues should be addressed in the near term.
Given the number of data breaches that happen in the education market, I think these would be great projects to undertake.

If you aren't comfortable playing with live ammunition, another possibility could be setting up a test bed by deploying a Web application and securely configuring the devices, implementing Web application firewalls and the like to protect the application. Then try to hack in using tools like the open source Metasploit or commercial ones such as Core Security Technologies' Core Impact. You could even run a "capture the flag" competition to test whether classmates can break into the test bed.

For more information:

  • In this SearchSecurity.com Q&A, Michael Cobb explains which Web services provide the best remote help desk support.
  • Information security threats expert Ed Skoudis discusses which flaws allow users to bypass proxy servers.




  • Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts