Jan 19

Most people never go through the experience of dealing with a cyber attack, so they assume that it is not something they should worry about when setting up their online business. If you’ve been operating a personal computer, then this is probably the reason why you’ve never been targeted. Hackers tend to attack networks and computers that are of value to them, so don’t be surprised if your “longstanding immunity” to attacks suddenly diminished after your online business begins to thrive. One attack in particular that you should be aware of is the infamous inference attack. In an inference attack, also known as a SQL injection, the perpetrator inserts an SQL code into a form to gain access to crucial information that is stored in on of your website’s databases. While this may sound like something that only happens to small business owners, it actually happens to large corporations as well. In fact, in recent years this kind of attack has resulted din millions of dollar in fraud. To protect yourself from an inference attack, heed the following tips.

Encrypt All of Your Site’s Data

If your website frequently exchanges sensitive date such as credit card numbers or bank information, then you’ll want to make sure all of your website’s data is encrypted with SSL or TSL. Keeping your data encrypted ensures that in the event of a security breach, the intruder will not be able to use the encrypted information to their advantage.

Use Secure Web Applications and Forms

Although there are many useful web applications available, many of these tools represent the biggest security risks for companies.  This is because hackers use these applications to gain access to the back-end of your website. Therefore, you should be very cautious about which web applications you use in the administration of your website. Make sure all applications and forms used are designed with secure code.  You should also make sure your website’s users do not have the capability of sending SQL queries, as this is how most hackers execute inference attacks. Avoiding malicious code input from hackers is the first line of defense in preventing an inference attack. You should also avoid using dynamic queries. Dynamic queries allow hackers to send and receive SQL information over the internet in plain text, therefore these queries present a substantial security risk. Many experts recommend avoiding the use of dynamic queries altogether.

Execute Updates Regularly

Keeping your operating system and website updated is an important part in maintaining the security of your online business. Many people don’t realize that maintaining the security of their website is a full time job that needs to be tended to daily. For this reason most security companies update their software as soon as a vulnerability is recognized.  To avoid an inference attack, or any other attack, you should keep you website and operating system updated, and make sure you are ware of any new developments.

Related Blog Posts

  • September 3, 2009 -- The Benefits of Web Application Scanning (3)
    Organizations in online industries such as e-commerce, banking and healthcare collect and provide access to data that can be classified as highly confidential. ...
  • August 25, 2009 -- How Secure is Your Hosting Solution? (0)
    It seems as if everyday, a handful of new companies emerge onto the web hosting scene.  These newcomers have many challenges on their hands.  Not only must they...
  • February 22, 2010 -- Web Hosting Encryption History – From WEP to WPA (0)
    The single most important feature a web hosting plan can have is a good encryption service. Without proper data encryption, all of the information sent to and f...
  • January 29, 2010 -- Domain Name Registration: Protecting Your Privacy (3)
    The internet is teeming with thousands of hackers that are constantly searching for any weaknesses that they can exploit. Aside from monetary motivation, these ...
  • January 12, 2010 -- Important Web Hosting Security Terms (0)
    The search for a good web hosting company can be very confusing, especially with the ever increasing selection. Each company promises they are the best, so who ...
  • January 6, 2010 -- Web Hosting Security: More Than Meets the Eye (2)
    As an online business owner, the security of your website should be at the top of your priority list. Web hosting security is a field that is constantly evolvin...
  • October 22, 2009 -- How To Secure Your Web Site (5)
    Securing your web site may be one of the most important things you can do to ensure your data is safe from hackers.  Any hole left open is an invitation to nefa...
  • October 21, 2009 -- osCommerce, Not For the Faint at Heart (0)
    A quick Google search online for e-commerce solutions will garner a huge number of software solutions available for free or commercial use.  Among the free solu...
  • October 13, 2009 -- Determining Which Host Will Work For Your Business (2)
    Determining the best hosting solution for your business can seem rather overwhelming when faced with the seemingly never-ending choices available on the web.  I...
  • September 18, 2009 -- Ensuring Security in the Cloud (1)
    Over the last several years, cloud computing has emerged from a promising concept to one of the most demanded IT hosting solutions.  With a devastating recessio...

2 Responses to “Inference Attacks: A Common Yet Serious Security Risk”

  1. Jon Says:

    Great points. It’s the “it won’t happen to me” syndrome or just plain ignorance, but how do you balance usability with the need for security?

  2. Fernley Says:

    Speaking of cracking, http://www.twitter.com got passwords stolen just 2 days ago. Seems that no site is safe.

Leave a Reply

Anti-Spam Protection by WP-SpamFree