« January 2009 | Main | March 2009 »

1 posts from February 2009

February 18, 2009

Apache Security Model

The tough part of securing Apache (or anything else, for that matter) is knowing what you need to defend from. Although my book (Apache Security) enumerates the threats, you need to read through hundreds of pages to learn about them, and even then it may be difficult to remember them as you need them. I've wanted for a long time to make this process easier and now, finally, here it is: the Apache Security Model:

At this time the model is only a draft, but I will polish it in the coming months. It will eventually make an important addition to the second edition of Apache Security.

MY WORK

IronBee is the next generation web application firewall engine, and it's open source too.
ModSecurity Handbok cover
ModSecurity Handbook is the definitive guide to the world's most popular web application firewall.
Apache Security cover
Apache Security is the complete guide to securing your Apache web server.
SSL Labs offers a comprehensive SSL security assessment consisting of 250+ checks. To start, enter your domain name below:

ABOUT ME

Ivan Ristić is an open source advocate, entrepreneur, writer, programmer and web security specialist. He is the principal author of ModSecurity, the open source web application firewall, and the author of Apache Security, a concise yet comprehensive web security guide for the Apache web server.   [LinkedIn Profile]

My Photo

TWITTER

@ivanristic

    FEEDS