首页> 外文会议>International Conferece For Internet Technology And Secured Transactions >Securing Internet Information Services (IIS) configuration files
【24h】

Securing Internet Information Services (IIS) configuration files

机译:保护互联网信息服务(IIS)配置文件

获取原文

摘要

Internet Information Services (IIS) is a modular TCP/IP network server application and a Software Development Kit from Microsoft. As a web server, it provides a platform for hosting and managing web applications and as a software development kit, it facilitates the developers to create applications to manage IIS server, or web applications that run on an IIS server. IIS stores all its configuration settings (server and site level) in plaintext XML files. The reliable functioning of IIS relies heavily on the integrity and confidentiality of these files. The protection provided to these files is; they can be accessed under the administrator's account only and the passwords are stored in encrypted form. But all other configurations relating to sites and the server are present in plaintext and are always accessible to the logged-in administrator. As there is no other protection layer except the administrator account login, therefore if someone manages to get into the system by some means, he can easily modify the files the way, he wants. As the web server is always running (or runs for long time intervals), these files are almost; constantly subjected to threats of integrity and confidentiality. This paper proposes and presents that another security layer be applied on these files, so that the threats to integrity and confidentially be minimized when the configuration files are not being edited by the administrator.
机译:Internet信息服务(IIS)是一个模块化的TCP / IP网络服务器应用程序以及来自Microsoft的软件开发套件。作为Web服务器,它提供了一个用于托管和管理Web应用程序并作为软件开发套件的平台,它促进了开发人员创建应用程序来管理IIS服务器或在IIS服务器上运行的Web应用程序。 IIS将其所有配置设置(服务器和站点级别)存储在明文XML文件中。 IIS的可靠功能严重依赖于这些文件的完整性和机密性。提供给这些文件的保护是;可以在管理员的帐户下访问它们,密码存储在加密的表单中。但是,与站点和服务器相关的所有其他配置都以明文存在,并且始终可以访问登录的管理员。由于没有其他保护层除了管理员帐户登录,因此如果有人通过某种方式管理进入系统,他可以轻松修改文件的方式,他想要。随着Web服务器始终运行(或长时间间隔运行),这些文件几乎;不断受到完整性和保密的威胁。本文提出并提出了另一个安全层应用于这些文件,使得当管理员未编辑配置文件时,可以最小化到完整性和保密的威胁。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号