Core Security Patterns: Best Practices and Strategies for J2EE, Web Services, and Identity Management (Hardcover)
暫譯: 核心安全模式:J2EE、網路服務與身份管理的最佳實踐與策略 (精裝版)
Christopher Steel, Ramesh Nagappan, Ray Lai
- 出版商: Prentice Hall
- 出版日期: 2005-10-24
- 售價: $2,730
- 貴賓價: 9.5 折 $2,594
- 語言: 英文
- 頁數: 1088
- 裝訂: Hardcover
- ISBN: 0131463071
- ISBN-13: 9780131463073
-
相關分類:
資訊安全
已絕版
買這商品的人也買了...
-
$2,560$2,432 -
$2,600$2,470 -
$2,390$2,271 -
$320$250 -
$1,360$1,292 -
$400$340 -
$2,220$2,109 -
$880$695 -
$580$458 -
$650$507 -
$1,550$1,473 -
$490$294 -
$520$411 -
$780$616 -
$1,500$1,425 -
$1,740$1,653 -
$680$537 -
$780$616 -
$1,16497 Things Every Software Architect Should Know (Paperback)
-
$580$458 -
$580$458 -
$299Mule in Action (Paperback)
-
$1,881Head First Programming: A Learner's Guide to Programming Using the Python Language (Paperback)
-
$1,590$1,511 -
$1,330Beginning Python: Using Python 2.6 and Python 3.1 (Paperback)
商品描述
Description
Praise for Core Security Patterns
Java provides the application developer with essential security mechanisms and support in avoiding critical security bugs common in other languages. A language, however, can only go so far. The developer must understand the security requirements of the application and how to use the features Java provides in order to meet those requirements. Core Security Patterns addresses both aspects of security and will be a guide to developers everywhere in creating more secure applications.
--Whitfield Diffie, inventor of Public-Key Cryptography
A comprehensive book on Security Patterns, which are critical for secure programming.
--Li Gong, former Chief Java Security Architect, Sun Microsystems, and coauthor of Inside Java 2 Platform Security
As developers of existing applications, or future innovators that will drive the next generation of highly distributed applications, the patterns and best practices outlined in this book will be an important asset to your development efforts.
--Joe Uniejewski, Chief Technology Officer and Senior Vice President, RSA Security, Inc.
This book makes an important case for taking a proactive approach to security rather than relying on the reactive security approach common in the software industry.
--Judy Lin, Executive Vice President, VeriSign, Inc.
Core Security Patterns provides a comprehensive patterns-driven approach and methodology for effectively incorporating security into your applications. I recommend that every application developer keep a copy of this indispensable security reference by their side.
--Bill Hamilton, author of ADO.NET Cookbook, ADO.NET in a Nutshell, and NUnit Pocket Reference
As a trusted advisor, this book will serve as a Java developers security handbook, providing applied patterns and design strategies for securing Java applications.
--Shaheen Nasirudheen, CISSP,Senior Technology Officer, JPMorgan Chase
Like Core J2EE Patterns, this book delivers a proactive and patterns-driven approach for designing end-to-end security in your applications. Leveraging the authors strong security experience, they created a must-have book for any designer/developer looking to create secure applications.
--John Crupi, Distinguished Engineer, Sun Microsystems, coauthor of Core J2EE Patterns
Core Security Patterns is the hands-on practitioners guide to building robust end-to-end security into J2EE™ enterprise applications, Web services, identity management, service provisioning, and personal identification solutions. Written by three leading Java security architects, the patterns-driven approach fully reflects todays best practices for security in large-scale, industrial-strength applications.
The authors explain the fundamentals of Java application security from the ground up, then introduce a powerful, structured security methodology; a vendor-independent security framework; a detailed assessment checklist; and twenty-three proven security architectural patterns. They walk through several realistic scenarios, covering architecture and implementation and presenting detailed sample code. They demonstrate how to apply cryptographic techniques; obfuscate code; establish secure communication; secure J2ME™ applications; authenticate and authorize users; and fortify Web services, enabling single sign-on, effective identity management, and personal identification using Smart Cards and Biometrics.
Core Security Patterns covers all of the following, and more:
- What works and what doesnt: J2EE application-security best practices, and common pitfalls to avoid
- Implementing key Java platform security features in real-world applications
- Establishing Web Services security using XML Signature, XML Encryption, WS-Security, XKMS, and WS-I Basic security profile
- Designing identity management and service provisioning systems using SAML, Liberty, XACML, and SPML
- Designing secure personal identification solutions using Smart Cards and Biometrics
- Security design methodology, patterns, best practices, reality checks, defensive strategies, and evaluation checklists
- End-to-end security architecture case study: architecting, designing, and implementing an end-to-end security solution for large-scale applications
商品描述(中文翻譯)
**描述**
**對《核心安全模式》的讚譽**
Java 為應用程式開發者提供了基本的安全機制,並支持避免其他語言中常見的關鍵安全漏洞。然而,語言的能力是有限的。開發者必須理解應用程式的安全需求,以及如何使用 Java 提供的功能來滿足這些需求。《核心安全模式》針對安全的兩個方面進行了探討,將成為全球開發者創建更安全應用程式的指導。
--Whitfield Diffie,公鑰密碼學的發明者
這是一本全面的安全模式書籍,對於安全編程至關重要。
--Li Gong,前 Sun Microsystems 首席 Java 安全架構師,《Inside Java 2 Platform Security》的合著者
作為現有應用程式的開發者,或是未來推動下一代高度分散應用程式的創新者,本書中概述的模式和最佳實踐將成為您開發工作的重要資產。
--Joe Uniejewski,RSA Security, Inc. 首席技術官兼高級副總裁
本書強調採取主動的安全方法,而不是依賴於軟體行業中常見的被動安全方法。
--Judy Lin,VeriSign, Inc. 執行副總裁
《核心安全模式》提供了一種全面的模式驅動方法和方法論,有效地將安全性納入您的應用程式。我建議每位應用程式開發者都應隨身攜帶這本不可或缺的安全參考書。
--Bill Hamilton,《ADO.NET 食譜》、《ADO.NET 簡明指南》和《NUnit 口袋參考》的作者
作為值得信賴的顧問,本書將作為 Java 開發者的安全手冊,提供應用模式和設計策略以保護 Java 應用程式。
--Shaheen Nasirudheen,CISSP,JPMorgan Chase 高級技術官
與《核心 J2EE 模式》類似,本書提供了一種主動的模式驅動方法,用於設計應用程式的端到端安全性。利用作者強大的安全經驗,他們創造了一本對於任何希望創建安全應用程式的設計者/開發者來說必不可少的書籍。
--John Crupi,Sun Microsystems 傑出工程師,《核心 J2EE 模式》的合著者
《核心安全模式》是實踐者的指南,旨在為 J2EE™ 企業應用程式、網路服務、身份管理、服務供應和個人識別解決方案構建穩健的端到端安全性。本書由三位領先的 Java 安全架構師撰寫,模式驅動的方法充分反映了當今在大規模、工業級應用程式中安全的最佳實踐。
作者從基礎開始解釋 Java 應用程式安全的基本原則,然後介紹一種強大且結構化的安全方法論;一個供應商獨立的安全框架;一個詳細的評估檢查表;以及二十三種經過驗證的安全架構模式。他們通過幾個現實場景進行演示,涵蓋架構和實施,並提供詳細的範例代碼。他們展示了如何應用加密技術;混淆代碼;建立安全通信;保護 J2ME™ 應用程式;驗證和授權用戶;以及加固網路服務,實現單一登入、有效的身份管理和使用智能卡及生物識別技術的個人識別。
《核心安全模式》涵蓋以下所有內容,還有更多:
- 什麼有效,什麼無效:J2EE 應用程式安全最佳實踐,以及應避免的常見陷阱
- 在現實應用程式中實施關鍵的 Java 平台安全功能
- 使用 XML 簽名、XML 加密、WS-Security、XKMS 和 WS-I 基本安全配置建立網路服務安全
- 使用 SAML、Liberty、XACML 和 SPML 設計身份管理和服務供應系統
- 使用智能卡和生物識別技術設計安全的個人識別解決方案
- 安全設計方法論、模式、最佳實踐、現實檢查、防禦策略和評估檢查表
- 端到端安全架構案例研究:為大規模應用程式架構、設計和實施端到端安全解決方案