2007
DOI: 10.6028/nist.sp.800-44ver2
|View full text |Cite
|
Sign up to set email alerts
|

Guidelines on securing public web servers

Abstract: The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology (NIST) promotes the U.S. economy and public welfare by providing technical leadership for the Nation's measurement and standards infrastructure. ITL develops tests, test methods, reference data, proof of concept implementations, and technical analysis to advance the development and productive use of information technology. ITL's responsibilities include the development of technical, physical, administrative, and m… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
11
0

Year Published

2008
2008
2023
2023

Publication Types

Select...
4
1
1

Relationship

0
6

Authors

Journals

citations
Cited by 11 publications
(11 citation statements)
references
References 12 publications
0
11
0
Order By: Relevance
“…Conforming to best practice provides confidence that a security policy is upheld. For example, the National Institute of Standards and Technology (NIST) provide a set of recommended guidelines for securing public Web servers [64], recommending that "all traffic between the Internet and Web server" should be controlled and that "all inbound traffic to the Web server except traffic which is required, such as TCP ports 80 (HTTP) and/or 443 (HTTPS)" should be denied.…”
Section: Best Practice Cataloguesmentioning
confidence: 99%
See 3 more Smart Citations
“…Conforming to best practice provides confidence that a security policy is upheld. For example, the National Institute of Standards and Technology (NIST) provide a set of recommended guidelines for securing public Web servers [64], recommending that "all traffic between the Internet and Web server" should be controlled and that "all inbound traffic to the Web server except traffic which is required, such as TCP ports 80 (HTTP) and/or 443 (HTTPS)" should be denied.…”
Section: Best Practice Cataloguesmentioning
confidence: 99%
“…. and is configured to perform the following" [64]. The RFC2119-style classification provides a basis with which to construct a concept hierarchy of best practice recommendations (firewall rules).…”
Section: Classification Of Best Practice Recommendationsmentioning
confidence: 99%
See 2 more Smart Citations
“…For example, bogon firewall rules [11,12,13] are best-practice protection against spoofing-threats for internal servers and end-user workstations, while NIST recommend multiple countermeasures over an n-tier network hosting a Web-server [14]. This knowledge-base is searchable-a suitable countermeasure/policy can be found for a given threatand provides the basis for autonomic security configuration.…”
Section: Introductionmentioning
confidence: 99%