Windows .Net Server Security Handbook [With CDROM]

Cyrus Peikari, Seth Fogie · 2002

From the Book: Preface Security is the one issue that will either make or break Microsoft Corporation. Microsoft has bet the on their .NET strategy, yet hackers threaten to topple the delicate structure at every turn. Microsoft itself has admitted that it has a long way to go to build public confidence in its security. Unfortunately, it seems that every time Microsoft security takes a step upward, hackers knock it right back down. In fact, the threat to .NET became so critical that Bill Gates himself felt compelled to realign the entire company with security at the forefront. In January 2002 Gates delivered an epochal memo announcing that Microsoft must henceforth make security its highest priority. This Trustworthy Computing memo reflected Gates' anguish over years of stinging criticism. His ultimatum echoed what hackers have been saying for years: Microsoft must get secure, or fail. The .NET vision is built upon three pillars. One pillar that has come under fire from critics is the .NET Framework. This distributed programming technology has pushed software on to the Internet as a service. Even before its official release, independent experts found security flaws in the .NET Framework. Moreover, future vulnerabilities are likely to be worse. At its heart the .NET Framework is distributed programming, which in theory could magnify threats from distributed hacking, viruses, and denial-of-service attacks. The second pillar of .NET is the enhanced user experience. With .NET, Microsoft is attempting to maximize functionality while minimizing hassles. Largely, this is a public relations challenge. .NET does provide an enhanced user experience, but itwill be difficult to market this advantage while security concerns overshadow the technology. The book you are holding deals with the third pillar of the .NET vision, namely, the base operating system forming the cynosure of the .NET vision. .NET Server is not only a pillar, but it is also the impressive foundation upon which the entire .NET Framework rests. This book covers the security architecture of .NET Server and shows you how protect your enterprise from hackers. .NET Server is often used as a generic term that encompasses all of Microsoft's enterprise management tools, including Exchange Server, SQL Server, Biz Talk Server, and more. However, the real Windows .NET Server is the base OS with which we are familiar. It is the next generation of its mighty predecessor, Windows 2000 Server. Since vulnerable clients are the Achilles' heel of secure servers, this book also covers Windows XP Professional, the preferred client for .NET Server. Ironically, the increasing use of IPSec-encrypted tunnels (Virtual Private Networks) means a vulnerable remote client opens a back door through which hackers can reach the very heart of your corporate network. Why attack the castle's ramparts when you can easily slip in through the open postern? Thus, this book also addresses security concerns specific to the Windows XP Pro clients that interface with .NET Server. Windows .NET Server is Microsoft's contender to beat Linux in the server market. Security may be the deciding factor in determining which of these two platforms achieves ascendancy. With the impressive security architecture of .NET Server, Microsoft now has a fighting chance.

Read the paper · More papers on PaperTik