IHS Inc. The Source for Critical Information and Insight
Electronics |  Change

Advanced Search
 
 

NIST Guide Provides Blueprint to Safer Web 2.0

October 30, 2007 // Published as a news service by IHS

 
Electronics & Telecom Docs
IHS sells a full selection of standards documents & collections from the industry's top organizations.
To learn more, and for a free quote, please complete the form below.
TIA Collection
NEMA Collection
CEA Collection
EIA Collection
ITU Collections
IEEE Collections
EU EMC Collections
IEC Collections
First Name:

Last Name:

Email address:
The National Institute of Standards and Technology (NIST) released NIST Special Publication 800-95, Guide to Secure Web Services, which provides details on how to make "Web 2.0" more secure, while maintaining its flexible and convenient features.

Many web-based services allow computer programs to talk to each other and exchange user data across several web sites without human intervention.

Many of the attractive features of this Web 2.0, including greater access to information and one-stop transactions that process information from several web sites, are at odds with traditional ways of maintaining computer security.

According to NIST, the security challenges presented by the web services approach are formidable and unavoidable. Difficult and unsolved problems exist, including maintaining confidentiality and integrity in data that is transmitted via intermediary web sites.

Firewalls, which often protect single computers or networks from certain types of attack, are often inadequate to safeguard web services data traveling between web sites.

The publication recommends several steps to make web services more secure, including a measure for content providers to replicate their data and services at backup sites.

Experts said this would improve the availability of their services in the event of denial of service (DoS) attacks intended to shut down a target web site.

Another recommendation is better and more uniform logging of visitors and actions on web sites. The publication also outlines several existing security techniques for making web services more secure, such as adding encryption to data transmitted through eXtensible Markup Language (XML), a protocol that allows the sharing and manipulation of data across different computer platforms.

The free NIST publication is available at http://csrc.nist.gov/publications/nistpubs/800-95/SP800-95.pdf.

Source: National Institute of Standards and Technology (NIST).

ELECTRONICS AND TELECOMMUNICATIONS STANDARDS NEWS
August 18, 2008
NIST Model Predicts Network Security
Data breaches are a recurring problem for IT managers responsible for securing their company’s confidential data, as well as sensitive information ... more
August 18, 2008
Frost: Standardization, Technology Optimization Trigger Growth in Asia-Pacific RFID Inlays Market
The market for radio frequency identification (RFID) tags is set to see considerable growth, according to Frost & Sullivan, gaining traction ... more
August 18, 2008
Frost: Tech Innovations, Gov't Regs Drive Border Control Biometrics Use
The post-9/11 effort to clamp down on fraudulent activities and illegal immigration greatly increased the use of biometrics' usage in border ... more
August 18, 2008
Frost: Cost Benefits, Broadband Penetration Driving VoIP in Latin America
Traditional local and long distance telephony operators in Latin America are facing increasing competition from voice over Internet protocol ... more
August 14, 2008
IEC Publishes Standard for Home DRM Interoperability - IEC 62227
The International Electrotechnical Commission (IEC) published a standard on digital rights permission codes for multimedia home server systems, ... more
Show All..