Securing Storage: A Practical Guide to SAN and NAS Security (Hardcover)
暫譯: 儲存安全:SAN 與 NAS 安全實務指南 (精裝版)

Himanshu Dwivedi

  • 出版商: Addison Wesley
  • 出版日期: 2005-11-21
  • 售價: $1,800
  • 貴賓價: 9.5$1,710
  • 語言: 英文
  • 頁數: 560
  • 裝訂: Hardcover
  • ISBN: 0321349954
  • ISBN-13: 9780321349958
  • 相關分類: 資訊安全
  • 立即出貨(限量) (庫存=1)

買這商品的人也買了...

商品描述

Description

Systematically address your #1 enterprise security gap: storage

 

Securing Storage is an indispensable resource for every storage and security professional, and for anyone responsible for IT infrastructure, from architects and network designers to administrators.

 

You’ve invested heavily in securing your applications, operating systems, and network infrastructure. But you may have left one crucial set of systems unprotected: your SAN, NAS, and iSCSI storage systems. Securing Storage reveals why these systems aren’t nearly as secure as you think they are, and presents proven best practices for hardening them against more than 25 different attacks.

 

Securing storage is crucial to protecting intellectual property and trade secrets and complying with regulations ranging from Sarbanes-Oxley and HIPAA to Gramm-Leach-Bliley and SEC Rule 17a4. This book offers a complete blueprint for protecting all your storage systems–and all the data stored on them.

 

Most enterprises have failed to adequately address one crucial component of IT security: storage. The storage industry has largely failed to deliver secure solutions, and many IT professionals simply assume that security can be handled elsewhere. The result is a gaping security hole: it’s now far easier for internal attackers to compromise storage devices than to attack applications or operating systems. Now, for the first time, one of the world’s top storage security experts systematically reveals the weaknesses in SAN and NAS security–and offers robust, practical solutions.

 

Drawing on years of leading-edge research, renowned storage architect and security researcher Himanshu Dwivedi explains why SAN and NAS systems have become an open target for unauthorized access and data compromise–and why “security by obscurity” strategies will fail to protect storage, just as they’ve failed elsewhere. Dwivedi offers expert, step-by-step guidance for evaluating your own storage environment, designing security into it, implementing storage security best practices, and optimizing the security settings on any shared storage device. He also presents a full chapter of real-world case studies.

Coverage includes

 

•    Recognizing vulnerabilities that arise from inadequate perimeter security

•    Understanding where attacks on storage devices typically originate

•    Testing storage network security and audit compliance

•    Protecting against SAN attacks: WWN spoofing, name server pollution, session hijacking, zoning hopping, e-port and f-port

      replication, LUN  mask subversion, and more

•    Protecting NAS systems against attacks on Windows CIFS and Unix/Linux NFS protocols

•    Defending against iSCSI attacks, from iQN spoofing to CHAP message reflection and offline password brute forcing

•    Securing individual Fibre Channel and iSCSI SANs, NAS devices, and more

Table of Contents

Preface.    

Acknowledgments.

About the Author.

 1. Introduction to Storage Security.

I. SAN SECURITY.

 2. SANs: Fibre Channel Security.

 3. SANs: LUN Masking and HBA.

 4. SANs: Zone and Switch Security.

II. NAS SECURITY.

 5. NAS Security.

 6. NAS: CIFS Security.

 7. NAS: NFS Security.

III. ISCSI SECURITY.

 8. SANs: iSCSI Security.

IV. STORAGE DEFENSES.

 9.Securing Fibre Channel SANs.

10. Securing NAS.

11. Securing iSCSI.

V. SAN/NAS Policies, Trends, and Case Studies.

12. Compliance, Regulations, and Storage.

13. Auditing and Securing Storage Devices.

14. Storage Security Case Studies.

Index.

商品描述(中文翻譯)

**描述**

系統性地解決您企業安全的首要漏洞:儲存

《Securing Storage》是每位儲存和安全專業人士,以及所有負責 IT 基礎設施的人(從架構師和網路設計師到管理員)不可或缺的資源。

您已經在保護應用程式、作業系統和網路基礎設施上投入了大量資金。但您可能忽略了一組關鍵系統的保護:您的 SAN、NAS 和 iSCSI 儲存系統。《Securing Storage》揭示了為什麼這些系統的安全性遠不如您想像的那樣,並提出了針對 25 種不同攻擊的加固最佳實踐。

保護儲存對於保護知識產權和商業機密,以及遵守從 Sarbanes-Oxley 和 HIPAA 到 Gramm-Leach-Bliley 和 SEC Rule 17a4 的各種法規至關重要。本書提供了一個完整的藍圖,用於保護您所有的儲存系統及其上儲存的所有數據。

大多數企業未能充分解決 IT 安全的一個關鍵組成部分:儲存。儲存行業在提供安全解決方案方面大多失敗,許多 IT 專業人士僅僅假設安全可以在其他地方處理。結果是一個明顯的安全漏洞:內部攻擊者現在比攻擊應用程式或作業系統更容易攻擊儲存設備。現在,世界頂尖的儲存安全專家之一首次系統性地揭示了 SAN 和 NAS 安全的弱點,並提供了強大且實用的解決方案。

根據多年前沿研究,著名的儲存架構師和安全研究員 Himanshu Dwivedi 解釋了為什麼 SAN 和 NAS 系統已成為未經授權訪問和數據妥協的公開目標,以及為什麼「模糊安全」策略將無法保護儲存,就像它們在其他地方失敗一樣。Dwivedi 提供了專業的逐步指導,幫助您評估自己的儲存環境,設計安全性,實施儲存安全最佳實踐,並優化任何共享儲存設備的安全設置。他還提供了一整章的實際案例研究。

涵蓋內容包括:

• 辨識由於邊界安全不足而產生的漏洞
• 了解儲存設備攻擊通常來自何處
• 測試儲存網路安全性和審計合規性
• 防範 SAN 攻擊:WWN 偽造、名稱伺服器污染、會話劫持、區域跳躍、e-port 和 f-port 複製、LUN 掩碼顛覆等
• 保護 NAS 系統免受 Windows CIFS 和 Unix/Linux NFS 協議的攻擊
• 防禦 iSCSI 攻擊,從 iQN 偽造到 CHAP 訊息反射和離線密碼暴力破解
• 保護單個 Fibre Channel 和 iSCSI SAN、NAS 設備等

**目錄**

前言
致謝
關於作者
1. 儲存安全簡介
**I. SAN 安全**
2. SAN:Fibre Channel 安全
3. SAN:LUN 掩碼和 HBA
4. SAN:區域和交換機安全
**II. NAS 安全**
5. NAS 安全
6. NAS:CIFS 安全
7. NAS:NFS 安全
**III. iSCSI 安全**
8. SAN:iSCSI 安全
**IV. 儲存防禦**
9. 保護 Fibre Channel SAN
10. 保護 NAS
11. 保護 iSCSI
**V. SAN/NAS 政策、趨勢和案例研究**
12. 合規性、法規和儲存
13. 審計和保護儲存設備
14. 儲存安全案例研究
索引

最後瀏覽商品 (20)