Kaspersky Internet Security 7.0
Information Technology

Website Security


Website Security is an application that restricts or prohibits access to specific areas within the user’s website.

The Hostname, IP address, username and password are the elements that safeguard a website. A hostname is essentially the site name which is unique and identifies a computer through a network. The IP or Internet Protocol identifies the receiver and sender of the information across the net. As a standard measure, secure connection is used when transmitting sensitive data like for example the user’s personal information. The levels of security currently used in websites are none, 40-, 52-, and 128-bit, where 128-bit is the highest level of page security. In order to protect information, encryption is by far the most effective and powerful tool. The data is scrambled and only the intended recipient may unscramble the data in order to read its contents. While it is highly useful for safeguarding information; it does not necessarily address the privacy issue after the data has been collected.

What exactly constitutes website security

When talking about a “website security”, it essentially implies that the website uses SSL or Secure Sockets Layer and that the traffic is encrypted. It is important to note here however that encryption doe not necessarily secure a website. When submitting sensitive data, any kind of vulnerability on the other end can lead to data been stolen by an attacker. Not everyone is aware of the rules that need to be followed in order to secure a website. It is highly recommended for webmasters to stay well informed about website security news and issues and keep their websites free of badware. The first step is to identify the badware on the website. Another common source of badware on websites is hacking attacks. This allows the third party to insert codes onto weakly secured websites. An example of this can be the “injection attack” in which the hacker utilizes security vulnerability and injects harmful codes into the web pages. This in turn initializes the download of badware in the background of the computer.

Important measures and steps to be taken in order to secure websites

A few basic guidelines and steps can help the webmasters make their websites secure. It is absolutely vital to use strong passwords. Also, it is advisable to use SSH and SFTP protocols, instead of telnet or FTP. Since both Telnet and FTP use plain text protocols, these are considered quite insecure. The SSH ad SFTP are on the other hand based on encrypted protocol which makes it more reliable. Using a vulnerability auditing scanner is recommended in order to scan websites for any kind of security vulnerability. The webmaster can use both free and commercial versions. The security tools must be utilized to identify any missing patches and then apply these patches as soon as possible. All security patches must be updated periodically and ensure that the hosting provider keeps all software updated.

Copyright © 1996-2008 Genesi S.r.l. - E-mail info@genesi.it | VAT ID: IT01680570676