Small Business Resources, Business Advice and Forms from AllBusiness.com
 

Strategies to Keep Your Servers Safe

By Scarlet Pruitt

For most modern businesses, data security is just as important as physical security. Just think about all of the critical business information, intellectual property, and client data that you store on your computer servers. You wouldn't leave that information sitting on your desk with the door unlocked,

and you shouldn't leave it stored on your servers without putting adequate security measures in place.

Most of us know how to protect our computers with firewalls and antivirus software but we may not know how to sufficiently protect our servers. This article should give you a good idea of where to start.

Just like with your desktop, you'll want to protect your server with a firewall. Make sure your server's built-in firewall is running, and you'll want to add a network firewall if you connect it to a network. The network firewall will control traffic and enforce security policies between networks that have different levels of trust, such as your office network and the Internet.

Harden Your System

Focus your attention on the server's ports. Each port is an open invitation for an unwanted intruder so it's important to turn off all unused ports. With your windows and doors locked, it's time to reduce the amount of vulnerabilities you have within your server. This is called "hardening" or strengthening your system.

There are a number of steps you can take to strengthen your system, but one of the most important is scrubbing your server of all unneeded software.

Trimming software is a surefire way to harden your system since each application has its own set of vulnerabilities. By deleting unnecessary programs, you reduce the ways in which the system can be attacked. If you're running a Web server, for example, you would want to delete the unnecessary office and entertainment software so you aren't vulnerable to exploits of those applications.

If you have multiple servers, some experts recommend that you dedicate each system to a single task because it greatly reduces the amount of vulnerabilities on each machine. This may not be an option for small businesses that want to save money through server consolidation, but for larger companies where security is a foremost concern dedicated servers may be the right choice.

Other tips include not allowing anonymous users onto your network, insisting on difficult 15 character passwords, blocking extensions to problematic scripts (such as .exe), and quarantining clients until you can scan their system attributes before allowing them access to the server's resources. Talk to your IT consultant about these and other measures that will strengthen the security if your system.

Audit Vulnerabilities

Once you've taken all the necessary steps to harden your server, you may want to use an auditing tool to check for vulnerabilities you may have missed. The Center for Internet Security is a great resource which offers dozens of free auditing tools for operating systems, applications, and network devices. These tools will scan your system to find possible exploits and open ports you may have missed.

With your server firewalled, hardened, and audited, it's time to install your intrusion protection software and make a plan for ongoing maintenance. Unfortunately, securing your server is not a one-time procedure — you'll need to get into a routine of regularly scanning your system and updating your security software. You'll also need to keep on top of security patches released by your software vendors and plan for regular security audits.

While it may take some diligence to get into a maintenance routine, it's the only real way to stay on top of emerging threats.


Scarlet Pruitt is a freelance writer and business consultant based in San Francisco. She has covered business and technology for publications in the U.S., Europe, and Latin America.

In addition, make sure to read these articles:

  • Is Your Office Ready for a Dedicated Server Room?
  • If your business has so many computer servers that their heat and constant buzzing are getting to you, it may be time to set up ......
  • The Benefits of a Fax Server
  • E-mail may be the transfer method of choice these days, yet somehow the fax has endured. If you're a fax user, be savvy and take ......
  • Computer Server Backup Options
  • With so much of today's critical business information in electronic form, server backup should be a regular part of your company's routine business operations.
  • Server patch scheduling.
  • The PatchPoint System is an in-line patch proxy for enterprise servers that instantly fixes software vulnerabilities and preserves business uptime, while eliminating the cost and ......
  • A hacker-proof server
  • HYDRA, from Bodacion Technologies of Barrington, Illinois, is an Internet server that can defeat all known network penetration attacks. It is immune to viruses and ......
  • Nearly 100 Hackers Fail to Crack WireX Immunix...
  • Business Editors, High Tech Writers DefCon PORTLAND, Ore.--(BUSINESS WIRE)--Aug. 26, 2002 WireX, a developer of unique security technologies for large server computers, captured 2nd place ......
  • Threats on the 'Net and the tools to fight them
  • HEADNOTE Technology has brought us such wonders as electronic mail, the fastest, easiest and most economical way to exchange information between branches, correspond with your ......
  • HP Raises the Bar for Securing NT-Based E-Services;...
  • High Tech Writers RSA Conference 2000 SAN JOSE, Calif.--(BUSINESS WIRE)--Jan. 17, 2000 Hewlett-Packard Company today introduced HP Praesidium WebEnforcer for NT, a new solution for ......
  • Whale's e-Gap System Protects Against...
  • Business Editors & High-Tech Writers Networld+Interop 2001 Booth No. 7215 FORT LEE, N.J.--(BUSINESS WIRE)--May 7, 2001 Whale Communications today revealed that its e-Gap(TM) System could ......
  • Threats on the Net and the tools to fight them
  • Technology has brought us such wonders as electronic mail, the fastest, easiest and most economical way to exchange information between branches, correspond with your customers ......
  • Declude Interceptor First Unified Gateway Solution...
  • NEWBURYPORT, Mass. -- Declude (www.declude.com), an Email security company, today unveiled Declude Interceptor(TM), a unified, layered Email security software solution that offers anti-virus, anti-spam, ......
  • Suspicious activity reveals compromised server.
  • Computer security requires constant vigilance. Securing a server before it is deployed is just the first step. Monitoring a system's services and keeping abreast of ......
  • Leading Security Expert from OKENA Available...
  • Business/Technology Editors WALTHAM, Mass.--(BUSINESS WIRE)--June 10, 2002 A new type of buffer overflow attack is circulating in the wild--the "heap" buffer overflow attack. Current exploits ......