How to Hack Proof Your Web Server

A dedicated server is a sign of success for anyand block malicious traffic while allowing legitimate
SMB. The reasons to move into a dedicatedtraffic through. It does this in a way that
server are varied - a high volume of web traffic,minimizes latency and slowdowns, so that the
a transaction heavy database, complex applicationprocess is transparent to end users.
requirements, or a combination of those andIntrusion protection takes a slightly more
other requirements- but whatever the reason, asophisticated approach to this, blocking harmful
dedicated server brings powerful capabilities totraffic at the source, placing compromised hosts
growing and established businesses alike.in quarantine and routing qualified user traffic
That power comes with an additional level ofquickly and efficiently. If your firewall represents
responsibilities. Protecting your server from beingyour front line defenders, your IPS (intrusion
hacked is a serious concern requiring completeprotection service) in effect goes behind enemy
attention. In most cases you're going to needlines. The combination lets you shift your security
help, and if you've chosen your server providermeasures from reactive to proactive, but there's
carefully, you're going to have it.a catch.
Securing any network attached web or applicationHaving firewall and IPS protection in place is only
server (and really, a web server is just athe first step. This isn't "set it and forget it" stuff,
specialized application) is a tricky proposition. Itstaying ahead of hackers and corporate
needs to be accessible to legitimate users andsaboteurs requires constant vigilance and regular
locked down to the malicious ones. Consider aupdates to blacklists, filters, patches and more. It's
large concert or sporting event.one thing to purchase and install a couple of
The idea is to have a large attendance of happysecurity appliances, it's quite another to properly
fans, but every step taken to bolster securitymanage them, and for too many SMBs, it's a
usually has a negative impact on the experience-budget busting proposition. This is where your
long lines for screenings, no bags or carry-allsservice provider comes in.
allowed and so on. As with secure e-mail service,The overlooked word for too many dedicated
it would seem that the two goals of access andserver providers is 'managed'. If your provider
security are somewhat diametrically opposed, butoffers managed services, you are a step ahead
a solid server protection scheme will actually workof the game. A high end provider already has 24
to support both ends.7/365 staffing. They already have a massive
It starts with a two layer "bullet proof vest" ofinvestment in hardware and network resources.
technology in the form of a managed firewall andMost importantly, they already have a team of
an intrusion protection service. A firewall is neededhighly trained, certified engineers who can help
to help stop brute force, denial of service styleyou stay running at peak optimization, fully
attacks. Typically emanating from multipleprotected. If your provider offers managed
unsecured servers located overseas, a DoSfirewall and intrusion protection, it's a no brainer to
attack will pound your server with useless traffic,add those services to your IT arsenal. If your
overwhelming resources and rendering the serverprovider doesn't offer firewall and IPS, maybe it's
unavailable for real users.time to start looking at other providers.
A quality firewall uses rules based access to filter