Technology Industry
Industry: Email Alert RSS FeedA GUIDE TO E-commerce Security
Software Magazine, Sept, 1999 by Paul Desmond
Authentication is only half the battle, however. Once a user gains access to a Web site, it's likely that some sort of data will be flowing back and forth. When that data is of a sensitive nature, it's got to be protected. That's where encryption comes into play.
VPNs typically provide encryption for data flowing over the wire, but companies also have to think about sensitive data stored in databases, such as a pool of credit card numbers. That's the type of valuable data hackers will spend time looking for.
Most RecentTechnology Articles
- The Google Manifesto: Dr. Open and Mr. Closed
- RIM Is Getting Too Successful for Its Customers' Good
- Tech Law: Google Loses in France, GPL Suits Target Many, IBM Sued, More
- Microsoft Moves Fast, Already Has Custom XML Patch for Word
- Microsoft Might Get Advantage or Pain from Order To Not Sell Word
- More »
Another category of product is intrusion detection systems (IDS), which can issue an alert when someone is trying to break into the network and thwart the attack. Available from vendors including ISS, Axent Technologies, and Network Flight Recorders, an IDS monitors network traffic, looking for telltale patterns that denote most known types of attacks, such as a repetitious flood of packets typical of a denial of service attack meant to overload a Web site.
Authorization Angst
Once the perimeter is secure and only authorized users can get into an e-commerce site, the next step requires tools that authorize different users to do different things. As Forrester's report notes, to date most companies have been using an exception policy, whereby access to resources is denied except to those who are explicitly allowed. "But as enterprise assets become intertwined with partner business processes, exception management will become untenable," the report says.
The alternative is to grant broad access to resources, with limited exceptions. Forrester recommends using only four data classifications, based on the audience for which the data is intended: public, employee, partner, and executive.
Companies including Netegrity and enCommerce make tools that help implement policies that ensure certain individuals or groups get access only to specific resources. Netegrity's SiteMinder, for example, lets organizations store the rules and policies governing who can access what resources in the SiteMinder Policy Server. The server, in turn, is connected to various databases, applications, and Web servers. Users are authenticated once by the server and can then access any resource for which they are authorized, without having to log in to each one individually.
SiteMinder doesn't store information about users itself, however, according to product manager Sumner Blount. Rather, it ties in to most types of existing corporate directories, including Novell NDS, Netscape Directory Server, NT Domains, and Banyan StreetTalk.
The Policy Server also makes it possible to customize content to different groups. For example, a bank customer with a balance above a certain threshold may get a different screen when accessing the bank's Web site than a user with a smaller account, enabling banks to give their larger customers premium services, Blount says.
The product also has a series of application programming interfaces (APIs) that enable it to tie in with various server operating systems, directories, application development tools, authentication products, and firewalls.
CXO UnpluggedSmart Business interviews on BNET
Brought to you by CBS MoneyWatch.com
- Best- and Worst-Paid College Degrees
- 6 Things You Should Never Do on Twitter or Facebook
- How Much Sleep Do You Really Need?
- 6 Big Myths about Gas Mileage
- 5 Rules for Immediate Annuities
- Death in the Family: 12 Things to Do Now
- Dumbest Things You Do With Your Money
- 6 Online Networking Mistakes to Avoid
- 401(k) Mistakes to Avoid
- 5 Economic Scenarios to Keep You Up at Night
- The Real ‘Best Places to Retire’
- Best Credit Cards for You
- 12 Tough Questions to Ask Your Parents
- The Real ‘Best Colleges’
- Home Buyer Tax Credit: How to Cash In
- Why You Shouldn't Bash Cash
- 8 Phony 'Bargains' and Better Alternatives
- Danger: 3 Debit Card Scams to Avoid
- 6 Myths About Gas Mileage
- 29 Fees We Hate Most
- Quick and Easy Ways to Boost Returns
- Best Stocks to Buy Now
- Lower Your Taxes: 10 Moves to Make Now
- New Jobs: 8 Lessons from Real-Life Career Switchers
- The New Job Market: Who Wins and Who Loses?
- Health Care Reform's Public Option: Everything You Need to Know
- Volunteer Work When Unemployed: Should You Work for Free?
- Whose Recovery Is This?
- Long-Term-Care Insurance: 4 Biggest Risks to Avoid
Content provided in partnership with
Most Recent Technology Articles
Most Recent Technology Publications
Most Popular Technology Articles
- BizRate to monitor in-store customer satisfaction for Office Depot stores - Market Intelligence
- Speed control of separately excited DC motor
- Effects of creative, educational drama activities on developing oral skills in primary school children
- Political stability and economic growth in Asia
- Failed businesses in Japan: a study of how different companies have failed, and tips on how to succeed, in the Japanese market



