Question

What is a Positive Security Model and is it important? Justify your answer?

What is a Positive Security Model and is it important? Justify your answer?

0 0
Add a comment Improve this question Transcribed image text
Answer #1

In the past web security is based on negative security model,they allowed all incoming https requests through except those that match predefined criteria for exclusion(i.e..,threat signatures)

More recently some solutions adopted positive security model they deny access all to all incoming traffic except those that match predefined criteria of legitimacy

Positive security model is better as compared to negative security model because

Negative security model is only good as data base model that defines what is bad

Negative security model is protect against certain types of attacks

A2(broken authentication),A5(broken access control),A7(cross site scripting) are not covered under negative security model

Negative security model has weekness related to administration related to delay of indentification of threat

Conclusion: negative security model is not going to protect against the volume, velocity and sophisticated attacks on ur web assets

Add a comment
Know the answer?
Add Answer to:
What is a Positive Security Model and is it important? Justify your answer?
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT