Blunder Dome Sighting  
privacy 
 
 
 

Hangout for experimental confirmation and demonstration of software, computing, and networking. The exercises don't always work out. The professor is a bumbler and the laboratory assistant is a skanky dufus.



Click for Blog Feed
Blog Feed

Recent Items
 
Who Can You Trust?
 
Perfecting Secure Coding
 
The Future of Software Tools
 
It's You? Ping You're It!
 
Self-Publishing Boxed Sets
 
How SCO Changed Our Awareness
 
Uh Oh: Time to Refresh Java
 
Open Source: Shrinking the Trust Surface
 
Open-Source: How Trustworthy, How Secure?
 
Trustworthy Software Security: How Do We Get There...

This page is powered by Blogger. Isn't yours?
  

Locations of visitors to this site
visits to Orcmid's Lair pages

The nfoCentrale Blog Conclave
 
Millennia Antica: The Kiln Sitter's Diary
 
nfoWorks: Pursuing Harmony
 
Numbering Peano
 
Orcmid's Lair
 
Orcmid's Live Hideout
 
Prof. von Clueless in the Blunder Dome
 
Spanner Wingnut's Muddleware Lab (experimental)

nfoCentrale Associated Sites
 
DMA: The Document Management Alliance
 
DMware: Document Management Interoperability Exchange
 
Millennia Antica Pottery
 
The Miser Project
 
nfoCentrale: the Anchor Site
 
nfoWare: Information Processing Technology
 
nfoWorks: Tools for Document Interoperability
 
NuovoDoc: Design for Document System Interoperability
 
ODMA Interoperability Exchange
 
Orcmid's Lair
 
TROST: Open-System Trustworthiness

2004-11-30

 

Criteria for Web Application Security

ACM News Service: Group Aims to Create Hallmark of Security.  2004-11-13: The Applications Security Consortium is an industry group that is focused on application firewalls for secure web applications.  A test program is being created but what I find most important is the list of criteria, including:
  • detection and blocking of malicious executable commands
  • prevention of data insertion through illicit control of format and type
  • prevention of cookie tampering
  • protection of application fields from modification
  • protection of URL parameters
Although the group is focused on perimeter defenses and certification of firewalls, this strikes me as something that also requires design attention. Matt Hines and Daw Kawamoto write in the 2004-11-08 CNET News.com article that the programs launch happened at a Computer Security Institute conference in the preceding week.
OK, OK, so now that takes care of the backlog for November.  Now I have the ancients ones to deal with, real soon now.

 
Construction Structure (Hard Hat Area) You are navigating Orcmid's Lair.

template created 2004-06-17-20:01 -0700 (pdt) by orcmid
$$Author: Orcmid $
$$Date: 10-04-30 22:33 $
$$Revision: 21 $