Storage News
Security News
Networking News 
FREE NEWSLETTERS
search
 

internet.commerce
Partner With Us














internet.com
IT
Developer
Internet News
Small Business
Personal Technology

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers




Latest Headlines
Security News
IBM, No. 1 in Privacy Security Practices
Security Breaches Plagued Enterprises Worldwide in 2009

Security

Anti-spam | Anti-virus | Biometrics | Encryption | Filtering/Monitoring | Firewalls | Identity | Intrusion Detection/Prevention | Privacy | Security Administration Tools | Tools
Submit Products *

SecureIIS

Intrusion Protection Especially For IIS Based Web Servers

SecureIIS operates as an ISAPI filter for Microsoft's IIS (Internet Information Services) Web server, examining network requests in an attempt to identify potential attacks or intrusions.

SecureIIS examines information received by the server in real time; the vendor states that the product inspects the data from its receipt to the point where it is passed to the kernel "...and at every level of processing in between." The module relies not on a specific "attack signature" database, that is, a listing of specific, known programs used in the past by hackers to gain access to the Web server; but instead identifies and prevents attacks based on their attack methods - i.e., the means by which the individual programs gain access to the system. Such methods that are identified by SecureIIS include buffer overflow attacks (SecureIIS compares the length of provided data to that of all defined client-supplied buffers, dropping the connection if the maximum size is exceeded); checking for the existence of special characters within passed parameters that may lead to the execution of server-side commands; and directory traversal attacks (again, the presence of special characters that may allow an attacker to access directories outside of the document root are checked for; and access to specific directories can be completely blocked).

Other key features of the SecureIIS module include support for both standard and secure (HTTPS, or SSL) Web traffic analysis; logging features allowing administrators to see all requests denied by SecureIIS and the source of the request; and the ability to block requests containing characters with high bits, which are often used to gain access to the Web server shell.

New in the latest release of SecureIIS is support for the blocking of SQL Injection attacks; which the vendor states is accomplished through the filtering of common commands and characters used in such attacks.

SecureIIS is available now, with a price of $995. Visit the eEye Digital Security Web site for further information.

product submission by DPW Staff

Suggest a link
for the SecureIIS fact sheet

fact sheet
ID#: 1000917226
date posted: Dec. 16, 2008
category: Security:Intrusion Detection/Prevention
platform: Windows NT4(sp6a+) w/IIS4; Windows 2000(sp1+) w/IIS5; Windows 2003 w/IIS6.
vendor: eEye Digital Security
(www.eeye.com)
vendor's information:
about SecureIIS
about eEye Digital Security


Security

Anti-spam | Anti-virus | Biometrics | Encryption | Filtering/Monitoring | Firewalls | Identity | Intrusion Detection/Prevention | Privacy | Security Administration Tools | Tools
Submit Products *

RSSLatest category updates via our RSS feed



Jupiter Online Media: internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and Jupiter Online Media

Jupitermedia Corporate Info


Legal Notices, Licensing, & Permissions, Privacy Policy.

Web Hosting | Newsletters | Tech Jobs | Shopping | E-mail Offers