Security considerations for Web-based mail
Computerworld - What do field salespeople, home teleworkers, medical personnel and anyone working remotely from a central site have in common? A need for up-to-the-minute information. One of the most successful models for using the Internet for business is the information-dissemination model.
One of the most common methods for this today is e-mail. E-mail can be sent and received in many ways: pagers, cell phones and the like. However, one e-mail communication option that holds promise for increased and more timely information flow is Web-based e-mail systems.
Many businesses don't deploy Web mail for fear of exposing corporate e-mail systems to external threats. With recent government legislation, e-mail confidentiality has become a growing concern. So, what approaches and options for deploying secure Web mail are there? Understanding how a Web-mail system works can help in deciding if such systems can be securely deployed at your company.
Security goals
Most Web-mail systems are designed using a multitiered architecture. Usually, a Web server works as a reverse proxy to a back-end e-mail server that actually services the users' mail requests. Most Web-mail systems use separate databases to store the mail and user-authentication information. The main security issues for Web mail are identity management, privacy, data integrity and availability.
- Identity management is the life cycle of creating, validating and revoking user-authentication information. Web-mail user authentication can be done using authentication protocols native to the mail-server operating system or third-party authentication methods such as Remote Authentication Dial-In User Service, Lightweight Directory Access Protocol or SecureID.
- Privacy has to do with keeping information from unauthorized exposure. The primary method for ensuring privacy is the use of cryptography. Pretty Good Privacy (PGP) and Secure/Multipurpose Internet Mail Extension (S/MIME), both widely implemented in the form of browser plug-ins and/or integration application programming interfaces, are well understood. PGP and S/MIME encrypt the message itself. Secure Sockets Layer (SSL) and IPsec encrypt communication at the protocol level. SSL is most common to Web mail.
- Data integrity is relevant to protection from unauthorized modification of e-mail. Data integrity can be preserved by cryptographic techniques such as hashing and signing of messages. PGP and S/MIME provide the facility for digitally signing messages so that tampering with the data will result in mismatched message-hash results.
- Availability involves ensuring that the Web-mail system remains as accessible as possible. The use of redundant servers, load balancing and fail-over, and server clustering are all common ways to increase the probability that the Web-mail system will be available at the right time. An added plus to redundancy is continuous availability even during maintenance windows.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts