Linux Hardening in Hostile Networks: Server Security from TLS to Tor (Paperback)
暫譯: 在敵對網路中的 Linux 強化:從 TLS 到 Tor 的伺服器安全性 (平裝本)
Kyle Rankin
- 出版商: Addison Wesley
- 出版日期: 2017-07-26
- 定價: $1,400
- 售價: 9.0 折 $1,260
- 語言: 英文
- 頁數: 272
- 裝訂: Paperback
- ISBN: 0134173260
- ISBN-13: 9780134173269
-
相關分類:
Linux、資訊安全
-
相關翻譯:
惡意網絡環境下的 Linux 防禦之道 (Linux Hardening in Hostile Networks: Server Security from TLS to Tor) (簡中版)
立即出貨
買這商品的人也買了...
-
$680$537 -
$660$627 -
$700$665 -
$380$300 -
$350$277 -
$590$502 -
$780$616 -
$1,254Feedback Control of Dynamic Systems, 7/e (IE-Paperback)
-
$480$408 -
$3,190$3,031 -
$560$420 -
$490$441 -
$2,550$2,423 -
$580$458 -
$500$425 -
$590$502 -
$1,400$1,330 -
$4,990$4,990 -
$690$587 -
$590$443 -
$400$300 -
$580$458 -
$580$493 -
$400$316 -
$450$356
商品描述
Implement Industrial-Strength Security on Any Linux Server
In an age of mass surveillance, when advanced cyberwarfare weapons rapidly migrate into every hacker’s toolkit, you can’t rely on outdated security methods–especially if you’re responsible for Internet-facing services. In Linux® Hardening in Hostile Networks, Kyle Rankin helps you to implement modern safeguards that provide maximum impact with minimum effort and to strip away old techniques that are no longer worth your time.
Rankin provides clear, concise guidance on modern workstation, server, and network hardening, and explains how to harden specific services, such as web servers, email, DNS, and databases. Along the way, he demystifies technologies once viewed as too complex or mysterious but now essential to mainstream Linux security. He also includes a full chapter on effective incident response that both DevOps and SecOps can use to write their own incident response plan.
Each chapter begins with techniques any sysadmin can use quickly to protect against entry-level hackers and presents intermediate and advanced techniques to safeguard against sophisticated and knowledgeable attackers, perhaps even state actors. Throughout, you learn what each technique does, how it works, what it does and doesn’t protect against, and whether it would be useful in your environment.
- Apply core security techniques including 2FA and strong passwords
- Protect admin workstations via lock screens, disk encryption, BIOS passwords, and other methods
- Use the security-focused Tails distribution as a quick path to a hardened workstation
- Compartmentalize workstation tasks into VMs with varying levels of trust
- Harden servers with SSH, use apparmor and sudo to limit the damage attackers can do, and set up remote syslog servers to track their actions
- Establish secure VPNs with OpenVPN, and leverage SSH to tunnel traffic when VPNs can’t be used
- Configure a software load balancer to terminate SSL/TLS connections and initiate new ones downstream
- Set up standalone Tor services and hidden Tor services and relays
- Secure Apache and Nginx web servers, and take full advantage of HTTPS
- Perform advanced web server hardening with HTTPS forward secrecy and ModSecurity web application firewalls
- Strengthen email security with SMTP relay authentication, SMTPS, SPF records, DKIM, and DMARC
- Harden DNS servers, deter their use in DDoS attacks, and fully implement DNSSEC
- Systematically protect databases via network access control, TLS traffic encryption, and encrypted data storage
- Respond to a compromised server, collect evidence, and prevent future attacks
Register your product at informit.com/register for convenient access to downloads, updates, and corrections as they become available.
商品描述(中文翻譯)
在任何 Linux 伺服器上實施工業級安全性
在大規模監控的時代,當先進的網路戰爭武器迅速進入每個駭客的工具箱時,您不能依賴過時的安全方法,尤其是當您負責面向互聯網的服務時。在《Linux® 在敵對網路中的加固》一書中,Kyle Rankin 幫助您實施現代的安全措施,以最小的努力提供最大的影響,並剝除不再值得您花時間的舊技術。
Rankin 提供了清晰、簡明的指導,關於現代工作站、伺服器和網路的加固,並解釋如何加固特定服務,例如網頁伺服器、電子郵件、DNS 和資料庫。在此過程中,他揭開了曾被視為過於複雜或神秘的技術的面紗,而這些技術現在對主流的 Linux 安全至關重要。他還包括了一整章關於有效事件響應的內容,DevOps 和 SecOps 都可以利用這些內容來撰寫自己的事件響應計劃。
每一章都以任何系統管理員可以快速使用的技術開始,以防範入門級駭客,並呈現中級和高級技術,以保護免受複雜且知識淵博的攻擊者,甚至可能是國家行為者的攻擊。在整個過程中,您將學習每種技術的功能、運作方式、能夠保護什麼以及無法保護什麼,以及它是否在您的環境中有用。
- 應用核心安全技術,包括雙因素身份驗證 (2FA) 和強密碼
- 通過鎖定螢幕、磁碟加密、BIOS 密碼和其他方法保護管理工作站
- 使用以安全為重點的 Tails 發行版作為加固工作站的快速途徑
- 將工作站任務劃分為具有不同信任級別的虛擬機 (VM)
- 使用 SSH 加固伺服器,利用 AppArmor 和 sudo 限制攻擊者可能造成的損害,並設置遠端 syslog 伺服器以追蹤其行為
- 使用 OpenVPN 建立安全的 VPN,並在無法使用 VPN 時利用 SSH 隧道流量
- 配置軟體負載平衡器以終止 SSL/TLS 連接並在下游啟動新的連接
- 設置獨立的 Tor 服務和隱藏的 Tor 服務及中繼
- 保護 Apache 和 Nginx 網頁伺服器,充分利用 HTTPS
- 使用 HTTPS 前向保密和 ModSecurity 網頁應用防火牆進行高級網頁伺服器加固
- 通過 SMTP 中繼身份驗證、SMTPS、SPF 記錄、DKIM 和 DMARC 加強電子郵件安全性
- 加固 DNS 伺服器,阻止其在 DDoS 攻擊中的使用,並全面實施 DNSSEC
- 通過網路存取控制、TLS 流量加密和加密資料存儲系統性地保護資料庫
- 對受損伺服器做出反應,收集證據,並防止未來的攻擊
在 informit.com/register 註冊您的產品,以便方便地訪問下載、更新和修正,隨著它們的可用性而提供。