IIS / Web Services Security threats



Hi,

My security team thinks allowing communication between the two IIS instances
leads to severe security risks. Basically, we want to put our presentation
tier on the perimeter network and the business tier inside the fire wall or
internal network. The biz tier will be developed and deployed as web services
on IIS.

I know microsoft recommends this architecture but I am not able to convince
my security team. They say IIS is vulnerable to viruses and worms even though
the communication between the web and app servers are secure with a
firewall/SSL/IPSec. Even though we will open specific ports for accessing the
web services, is it true that IIS is not a secure environment to access it
from the perimeter network.

If my security team is true, I wonder what would be the alternative to IIS.
If they are not, how should we protect our network while allowing web service
to run on IIS.

I have read all security related recommendations published by Micrososft but
no luck with my security team yet. Esp. the entire document from patterns &
pratices:
Improving Web Application Security - Threats and Countermeasures

How are secure .NET enterprise applications developed and hosted in IIS? Are
there any companies out there which uses this MS recommended architecture and
yet have a secure network?

Thanks,
Magdelin
.



Relevant Pages

  • Re: IIS / Web Services Security threats
    ... > believe the weblogic designated ports are open in firewall. ... > Sec configuration may make the network little secure. ... >>> My security team thinks allowing communication between the two IIS ...
    (microsoft.public.dotnet.framework.webservices)
  • Re: IIS / Web Services Security threats
    ... virus attack on the perimeter network, the common ports have been closed too. ... Sec configuration may make the network little secure. ... >> My security team thinks allowing communication between the two IIS ...
    (microsoft.public.dotnet.framework.webservices)
  • Re: IIS / Web Services Security threats
    ... > You use the phrase 'My security team'. ... >> My security team thinks allowing communication between the two IIS ... >> tier on the perimeter network and the business tier inside the fire wall ... is it true that IIS is not a secure environment to access ...
    (microsoft.public.dotnet.framework.webservices)
  • Re: IIS / Web Services Security threats
    ... You use the phrase 'My security team'. ... > My security team thinks allowing communication between the two IIS ... > tier on the perimeter network and the business tier inside the fire wall ... is it true that IIS is not a secure environment to access it ...
    (microsoft.public.dotnet.framework.webservices)
  • Re: IIS / Web Services Security threats
    ... The security team is at my company and I ... >> My security team thinks allowing communication between the two IIS ... >> tier on the perimeter network and the business tier inside the fire wall ... is it true that IIS is not a secure environment to access it ...
    (microsoft.public.dotnet.framework.webservices)

Loading