Skip the navigation
Opinion

Opinion: Web server security: Is IIS or Apache more secure

By Roger A. Grimes
September 7, 2007 12:00 PM ET

InfoWorld - Continuing the theme from my previous column on the relative security of Internet Information Services (IIS) vs. Apache, I've come across more studies to support my initial conclusion.

If you remember, I was questioning the findings of a Google report that stated that IIS Web servers were twice as likely as Apache servers to be hosting malware. I wasn't refuting the data, but I was questioning the conclusion, given the fact that the report's authors calculated their statistics using server IP addresses only.

Since a single Web server can, and often does, host multiple Web sites, the published results would be skewed by any server hosting multiple Web sites. And since Apache Web servers are often used to host hundreds to thousands of active sites (and IIS is less likely to host sites on the same scale), I felt the study underreported the prevalence of malicious Apache Web sites.

I was skeptical of the data because of my own experiences. I run both IIS and Apache Web servers in my honeynet. The Apache Web server gets attacked significantly more than the IIS server does. Also, most reported hacks are against Apache Web servers. Finally, I can't think of a single massive attack against IIS servers since the Code Red worm of July 2001. Yet Apache servers are being taken over by the thousands nearly every night. Something didn't add up.

Of course, being a full-time Microsoft employee, I wondered if my relationship was clouding my "objectivity." Because I make a living in the Windows world, was I not seeing the true malicious Web site activity accurately?

Over the last month, I've decided to track every reported Web site exploitation or malicious Web server host. With more than 3,000 data points, the number of reported malicious or compromised Apache Web sites is running 17 to 1. But it's not just my own data; take any random sampling from Zone-H's hacked Web site monitor statistics and you'll see a huge skew toward Apache servers versus IIS. Normal statistics show that somewhere around 80% to 90% of all malicious Web sites originate from an Apache server.

Zone-H's data has some other interesting points, such as how many single IP addresses (a single Web server, in most cases) are linked to the reported Web servers. It's not unusual to see a single exploit affecting a single IP address to result in hundreds to thousands of malicious Web sites. And yes, the vast majority of these data points are Apache.

Paul Laudanski of CastleCops fame collected supporting statistics from his own Phishing Incident Reporting and Termination Squad database for me. He said, "For PIRT reports above 500,000 (without checking their phish status): IIS = 1,302 reports, Apache = 20,104 reports. For all PIRT reports without confirming status: IIS = 16,744, Apache = 181,724. There are, of course, other Web servers I haven't checked for." That works out to be about 6% to 8% for IIS and 92% to 94% for Apache.

The overwhelming slant toward Apache cannot be explained by sheer numbers alone. Netcraft reports that in August 2007, Apache accounted for 48% of public-facing Web sites while IIS rose to 34%. So does that mean IIS is more secure than Apache?

The real answer, of course, is that both IIS and Apache, if installed as directed by the developers, are relatively secure. Most malicious Web site infections are the result of administrative mistakes and buggy applications -- not the underlying Web server software.

Open Web Application Security Project, one of the most respected organizations trying to increase Web server security, continues to report nearly the same top 10 Web site security flaws that have plagued Web sites since the beginning of the Web.

So I want to end my one-way debate of IIS vs. Apache by saying that both are fine, relatively secure platforms. Installing a secure Web server is easy; hosting secure applications on top of that secure base is the true challenge.

Roger A. Grimes is contributing editor of the InfoWorld Test Center. He also writes the Security Adviser blog and the Security Adviser column.

Reprinted with permission from InfoWorld. Story copyright 2010 InfoWorld Media Group, Inc. All rights reserved.
Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

App Development White Papers
The Keys to Distributed & Agile Application Development
How leading firms are winning with strategies for efficient application development, without relying on co-location.
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
Streamline Compliance and Increase ROI
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
All App Development White Papers
App Development Webcasts
Reduced TCO for Communications Applications with New Oracle SPARC Servers
In this webcast learn how Oracle's new SPARC T4 servers and SPARC Supercluster deliver the security, performance, and scalability required for 4G network...
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
All App Development Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs