Big4Guy

Welcome to Big4Guy.com. Big4Guy is an online resource where I will share with you the latest news, insights, knowledge and some experiences as a Big 4 consultant. We will discuss some of the important issues which organisations are facing today in the areas of information security, security and controls in SAP R/3, Oracle Applications, J.D.Edwards, Peoplesoft and various other ERP's. You will also find information on latest complaince regulations like Sarbanes Oxley, Basel II and so on. Big4guy will also attempt to provide valuable resources for individuals interested in examinations the CISA, CISM, CISSP, PMP and various other security certifications considered essential for entry in any Big 4 accounting, auditing and consulting firms. You are invited to post your comments and viewpoints to posts here. I sincerely hope this online journal will be useful to everyone from a budding student to a professional in the accounting, auditing, management and consultancy professions.

Post details: International Standards Organization Open systems Interconnection ISO OSI Layer 5 Sessions Layer

01/22/06

Permalink 09:21:56 pm, Categories: Information Security, 152 words   English (US)

International Standards Organization Open systems Interconnection ISO OSI Layer 5 Sessions Layer

Session layer is the fifth layer in the ISO OSI layer hierarchy. Session layer establishes, manages and terminates connections between various applications. The session acts as a coordinator between applications helping them to communicate. In short, the session layer controls dialogues and conversations between applications at each end.

The session layers however suffers from many vulnerabilites. One of the most major limitations is weak authentication mechanisms. Since sessions layer hooks up two applications, session credentials such as user id, password have to be exchanges. Lack of encryption can make this vulnerable to interception. Also, if session idenfications. Some of the other vulnerabilities of the session layer include failed authentication attempts, spoofing and hijacking.

Encrypted password exchange, specific account expiration, strong session identification and limiting failed login attempts via timing mechanism are some controls which ensure better security in the session layer.

More on ISO OSI Layers >>

Layer 6 Presentation Layer , Layer 7 Application Layer

Comments:

No Comments for this post yet...

Official Websites

Search

Google

Web Big4Guy.com

September 2008
Mon Tue Wed Thu Fri Sat Sun
<<  <   >  >>
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30          

Misc

Syndicate this blog XML

What is RSS?