123ArticleOnline Logo
Welcome to 123ArticleOnline.com!
ALL >> General >> View Article

Detection & Handling Of Application Security Threats

Profile Picture
By Author: AkanshaK
Total Articles: 6
Comment this article
Facebook ShareTwitter ShareGoogle+ ShareTwitter Share

Since there are several variations in specific attacks as well as attack techniques, for better detection, it is essential to view the threat in the prospects of how attackers are attempting to achieve.

Application Threats & Countermeasures
A good way of detecting application threats is to arrange them in a vulnerable category. Here is an overview of the various categories and the main threats to the application.

Input validation vulnerability category includes threats like cross-site scripting, buffer overflow, SQL injection, and canonicalization.
Authentication is prone to brute force attacks, cookie replay, dictionary attacks and network eavesdropping.

Authorization includes confidential data disclosure, elevation of privilege, luring attacks and data tampering.

The configuration management category includes the attacks like unauthorized administration interface access, the absence of individual accountability, clear text config data retrieval, over-privileged process and unauthorized configuration stores access.

Sensitive data includes access to sensitive data in storage, ...
... data tampering, and network eavesdropping.

Session management includes session replay, session hijacking, and man in the middle attack.

Cryptography includes poor key management, poor key generation, custom or weak encryption.

Exception Management comprises a denial of service and information disclosure.

Auditing & Logging involves user denies of doing an action, attackers covers his tracks and attacker exploits a vulnerability without a trace.

How To Handle Application Security Threats
Validated Input- Validate the inputs to the application by using fundamental edit checking to ensure that the content submitted through the user interface is proper for each fold.

Bind Variables – take the benefits of bind variables when executing SQL queries.

Restrict the access to the internal resources through various application server config settings.

Update framework on a normal interval.

Qualify entire user input

Filter potentially malicious input

Choose a strong password, which is complex, aren’t regular words, and include a compilation of lowercase, uppercase, numeric & special characters.

Use standard encryption technology to keep sensitive information in configuration databases and files.

Use sturdy ACLs to safeguard Windows resources.

Perform role evaluation before permitting access to the application, which could potentially disclose sensitive data.

Use sturdy authorization with several gatekeepers.

Total Views: 647Word Count: 328See All articles From Author

Add Comment

General Articles

1. Allzone Management Services: Transforming Medical Billing & Revenue Cycle Management For Healthcare Providers
Author: Allzone Management Service

2. What Is The Future Of The Osgood-schlatter Market? Key Insights & Growth Outlook
Author: siddhesh

3. Things To Do In Waikiki, Honolulu, Hawaii: A Tropical Paradise Awaits
Author: Katie Law

4. Top 10 Key Players Transforming The Quaternary Ammonium Salts Disinfectant Market
Author: siddhesh

5. Wprofessional House Party Catering Services Make Parties More Organised, Calmhat To Expect From Professional House Party Catering: Service Walkthrough
Author: Arjun

6. Reddybook — Where Digital Simplicity Meets Smart Experience
Author: reddy book

7. How To Select The Right Channel Straightening Machines Manufacturer In India
Author: ravina

8. Global Microarray Analysis Market Trends: Genomics Research Driving Market Expansion
Author: siddhesh

9. Role Of A Software Development Company India In Custom Software Development For Scaling Businesses
Author: michaeljohnson

10. Reddybook — A Fresh Perspective On Digital Knowledge And Growth
Author: reddy book

11. Rising Gi Disorders Driving The Malabsorption Syndrome Market Worldwide
Author: siddhesh

12. Reddybook1.ac — A Smart Platform For Digital Exploration
Author: reddy book

13. Complete Guide To Tripindi Shradh, Kumbh Vivah Puja & Kaal Sarp Puja At Trimbakeshwar
Author: Narayan Shastri Guruji

14. Helical Insight The Right Enterprise Bi Software For Your Organization
Author: Vhelical

15. Next-gen Therapies Redefining The Eye Infections Treatment Market
Author: siddhesh

Login To Account
Login Email:
Password:
Forgot Password?
New User?
Sign Up Newsletter
Email Address: