Question Description
Discussion……
Much has been made of the new Web 2.0 phenomenon, including social networking sites and user-created mash-ups. How does Web 2.0 change security for the Internet? How do secure software development concepts support protecting applications?
Note:-
- Students are required to post one original response to the discussion questions each week, as well as a response to one classmate. Original responses should not be a word for word rehashing of what is stated in the readings, but rather an integration of the concepts and additional insights, either from real world experience or additional sources. It should be a 250 word response to the question.Your primary posting may end with a tag-line or a related question of your own. Your secondary posting is a response to one classmate's post. Each answer/response should be supported with research. Responses to classmates should not be "I agree” or "I like the way you stated that.” These responses should again be insightful, offering an opinion or facts based on your research and experiences. The response to one classmate should be a minimum of 125 words. See APA criteria for citing resources. You must provide a minimum of a reference, in APA format, in your original response.include references and no plagiarism.send the files separately as one is discussion of 250 words with references and two replies each of 125 words.
Reply to topic 1:-
Web 2.0 stages empower anybody to transfer content, these sites are effortlessly helpless to programmers wishing to transfer malignant substance. Once the pernicious substance has been transferred, pure guests to these locales can likewise be tainted, and the site proprietors could be conceivably in charge of harms brought about. From a specialized outlook also, Web 2.0 locales are more inclined to attacks since they have more communications with the program and require running complex Javascript code on client machines. What exacerbates the situation is that most by far of these destinations (e.g., Wikipedia, MySpace, Flicker) are viewed as "trusted" by URL sifting and arrangement items, and thusly will likely not be hindered in spite of the way that they may contain pernicious code.
Web 2.0 security threats:
· Web 2.0 is using technologies such as asynchronous JavaScript and XML (AJAX) which expands both the target area and the security gaps available to cybercriminals.
· As web 2.0 platforms allow anyone to upload content, these sites are readily susceptible to hackers wishing to upload malicious content. Once this content has been uploaded, innocent visitors to this site can also be infected.
· One of the top web 2.0 security vulnerability is cross-site scripting. With this malicious input sent by an attacker is stored in the system used by other susceptible users to such attacks. One of these methods used by hackers is to implement malicious JavaScript code to steal session cookies from victims.
Therefore, web 2.0 lead to new developments on the internet but still security risks have to be taken into account. Attackers might shift their focus from server side to client side which is the weakest link in security. Various security measures, processes, and controls should be in place before any application is deployed. Security assessments should be conducted to identify vulnerabilities.
Most enterprises don't typically piece clients from going by Web 2.0 destinations, which could turn into an IT security hazard. Web 2.0 locales harboring pernicious code raise a plenty of issues for undertakings: inner and outside security; legitimate risk (immediate, roundabout and noteworthy); and administrative consistence issues.
The use of a Web 2.0 stage for noxious reasons for existing was found on a known U.S.- based site offering workmanship catalog benefits in April 2007 by Finjan's Malicious Code Research Center. The pernicious code on this site was jumbled to empower it to sidestep hostile to infection arrangements. It misuses different program vulnerabilities and utilizations AJAX innovation to download and execute a possibly malevolent trojan from a remote server. Basically by going to this page, without making any move, the guest's machine is contaminated.
Reply 2:-
How web 2.0 change securities for internet:
Web 2.0 is the current version of web-based technology characterized by greater user interactivity and collaboration with enhanced communication channels. User collaboration, social networking and user generated content are major differences when compared with traditional world-wide web (www). This social nature of Web 2.0 technologies offer many advantages in items of enriching the internet and improving the user experience but they are also bringing a number of security concerns. But Web 2.0’s convenience upgrades nature provided it longer sustainability in internet platform though there are some concerns with security.
There are different possible threats and concerns with Web 2.0 such as threats related to Web Feeds, threats related to AJAX, threats due to high participation systems such as social web platforms and when users are involved data privacy is also major concern.
Cross Site Scripting (XSS)Lacking Authentication Controls:
In a put away cross site scripting (XSS) weakness, malevolent information sent by an aggressor is put away in the framework at that point showed to different clients. Frameworks that enable clients to enter arranged substance – like HTML for instance – are particularly helpless to this assault. In danger are online journals, interpersonal organizations, and wikis. A case of this assault from a year ago was the Yahoo Hot Jobs XSS defenselessness abuse, where programmers jumbled JavaScript to take session treats of casualties.
Lacking Authentication Controls:
In numerous Web 2.0 applications, content is confided in the hands of numerous clients, not only a select number of approved staff. That implies there's a more noteworthy shot that a less-experienced client will roll out an improvement that will adversely influence the general framework. This adjustment in a framework's plan can likewise be abused by programmers who now approach a more noteworthy number of "regulatory" records whose passwords can frequently be effortlessly split if the right security controls are not set up.
Secure software development concepts support protecting applications:
The issue is that most data security experts don't originate from a solid improvement foundation particularly foundations in present day Web application advancement conditions. This makes it trying for them to successfully speak with the advancement group. Hence, security experts shouldn't be reluctant to state "I don't have the foggiest idea" while talking about profoundly specialized issues, yet they can't give designers a chance to forget about them or muddle critical issues with specialized gibberish. Evangelism is, along these lines, an exercise in careful control.
Security experts can enhance their believability with designers by giving data on genuine dangers and security-related business requests that is altered for the associations and improvement group needs. Organizations fall under an assortment of administrative and consistence prerequisites, extending from the Payment Card Industry Data Security Standard (PCI DSS) for those tolerant Visa exchanges, Health Insurance Portability and Accountability Act (HIPAA) for those managing individual therapeutic data and the different client information break warning laws.
Our website has a team of professional writers who can help you write any of your homework. They will write your papers from scratch. We also have a team of editors just to make sure all papers are of HIGH QUALITY & PLAGIARISM FREE. To make an Order you only need to click Ask A Question and we will direct you to our Order Page at WriteDemy. Then fill Our Order Form with all your assignment instructions. Select your deadline and pay for your paper. You will get it few hours before your set deadline.
Fill in all the assignment paper details that are required in the order form with the standard information being the page count, deadline, academic level and type of paper. It is advisable to have this information at hand so that you can quickly fill in the necessary information needed in the form for the essay writer to be immediately assigned to your writing project. Make payment for the custom essay order to enable us to assign a suitable writer to your order. Payments are made through Paypal on a secured billing page. Finally, sit back and relax.
About Writedemy
We are a professional paper writing website. If you have searched a question and bumped into our website just know you are in the right place to get help in your coursework. We offer HIGH QUALITY & PLAGIARISM FREE Papers.
How It Works
To make an Order you only need to click on “Place Order” and we will direct you to our Order Page. Fill Our Order Form with all your assignment instructions. Select your deadline and pay for your paper. You will get it few hours before your set deadline.
Are there Discounts?
All new clients are eligible for 20% off in their first Order. Our payment method is safe and secure.