Guidelines on securing public web servers

M C Tracy, Wayne Jansen, Karen A. Scarfone, Theodore Winograd · 2007

The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology (NIST) promotes the U.S. economy and public welfare by providing technical leadership for the Nation's measurement and standards infrastructure.ITL develops tests, test methods, reference data, proof of concept implementations, and technical analysis to advance the development and productive use of information technology.ITL's responsibilities include the development of technical, physical, administrative, and management standards and guidelines for the cost-effective security and privacy of sensitive unclassified information in Federal computer systems.This Special Publication 800-series reports on ITL's research, guidance, and outreach efforts in computer security, and its collaborative activities with industry, government, and academic organizations.Certain commercial entities, equipment, or materials may be identified in this document in order to describe an experimental procedure or concept adequately.Such identification is not intended to imply recommendation or endorsement by the National Institute of Standards and Technology, nor is it intended to imply that the entities, materials, or equipment are necessarily the best available for the purpose. National Institute of Standards andTechnology Special Publication 800-44 Version 2 Natl.Inst.Stand.Technol.Spec.Publ.800-44 Ver. 2, 142 pages (Sep.2007) development, documentation, and implementation of policies, standards, procedures, and guidelines that help to ensure the confidentiality, integrity, and availability of information system resources.To ensure the security of a Web server and the supporting network infrastructure, the following practices should be implemented: Organization-wide information system security policy Configuration/change control and management Risk assessment and management Standardized software configurations that satisfy the information system security policy Security awareness and training Contingency planning, continuity of operations, and disaster recovery planning Certification and accreditation.Organizations should ensure that Web server operating systems are deployed, configured, and managed to meet the security requirements of the organization.The first step in securing a Web server is securing the underlying operating system.Most commonly available Web servers operate on a general-purpose operating system.Many security issues can be avoided if the operating systems underlying Web servers are configured appropriately.Default hardware and software configurations are typically set by manufacturers to emphasize features, functions, and ease of use, at the expense of security.Because manufacturers are not aware of each organization's security needs, each Web server administrator must configure new servers to reflect their organization's security requirements and reconfigure them as those requirements change.Using security configuration guides or checklists can assist administrators in securing systems consistently and efficiently.Securing an operating system initially would generally include the following steps:Patch and upgrade the operating system Remove or disable unnecessary services and applications Configure operating system user authentication Configure resource controlsInstall and configure additional security controls Perform security testing of the operating system.Organizations should ensure that the Web server application is deployed, configured, and managed to meet the security requirements of the organization.In many respects, the secure installation and configuration of the Web server application will mirror the operating system process discussed above.The overarching principle is to install the minimal amount of Web server services required and eliminate any known vulnerabilities through patches or upgrades.If the installation program installs any unnecessary applications, services, or scripts, they should be removed ES-3 GUIDELINES ON SECURING PUBLIC WEB SERVERS immediately after the installation process concludes.Securing the Web server application would generally include the following steps: Patch and upgrade the Web server application Remove or disable unnecessary services, applications, and sample content Configure Web server user authentication and access controls Configure Web server resource controls Test the security of the Web server application and Web content.Organizations should take steps to ensure that only appropriate content is published on a Web site.Many agencies lack a Web publishing process or policy that determines what type of information to publish openly, what information to publish with restricted access, and what information should not be published to any publicly accessible repository.This is unfortunate because Web sites are often one of the first places that malicious entities search for valuable information.Some generally accepted examples of what should not be published or at least should be carefully examined and reviewed before publication on a public Web site include-Classified or proprietary information Information on the composition or preparation of hazardous materials or toxins 2 Sensitive information relating to homeland security Medical records An organization's detailed physical and information security safeguards Details about an organization's network and information system infrastructure (e.g., address ranges, naming conventions, access numbers) Information that specifies or implies physical security vulnerabilities Detailed plans, maps, diagrams, aerial photographs, and architectural drawings of organizational buildings, properties, or installations

Read the paper · More papers on PaperTik