Penetration Testing and Network Defense
| < Day Day Up > |
| Detecting server attacks can be a never-ending task of implementation, monitoring, testing, and then reimplementing new or updated methods. Servers, or any computer for that matter, can be attacked in several ways, and implementing a single detection method is impractical. For example, if you install a firewall to protect against external network attacks, the server is still vulnerable to internal network attacks, viruses, application flaws, or even physical theft of the server to name only a few. You should apply detection and prevention methods to all possible areas that might affect or come into contact with your servers. Table 13-3 displays possible attack avenues to your server and some basic recommendations to help detect such attacks against them.
Tip Microsoft contains several security tools that greatly assist in identifying weak areas within your organization. See http://www.microsoft.com/technet/Security/tools/default.mspx for tools such as Security Risk Self Assessment tool, which produces a detailed report with recommendations on your overall security environment.
|
| < Day Day Up > |