The Craft of System Security (Paperback)
暫譯: 系統安全的技藝 (平裝本)

Sean Smith, John Marchesini

  • 出版商: Addison Wesley
  • 出版日期: 2007-08-01
  • 售價: $2,160
  • 貴賓價: 9.5$2,052
  • 語言: 英文
  • 頁數: 592
  • 裝訂: Paperback
  • ISBN: 0321434838
  • ISBN-13: 9780321434838
  • 相關分類: 資訊安全
  • 立即出貨 (庫存=1)

買這商品的人也買了...

相關主題

商品描述

"I believe The Craft of System Security is one of the best software security books on the market today. It has not only breadth, but depth, covering topics ranging from cryptography, networking, and operating systems--to the Web, computer-human interaction, and how to improve the security of software systems by improving hardware. Bottom line, this book should be required reading for all who plan to call themselves security practitioners, and an invaluable part of every university's computer science curriculum."
--Edward Bonver, CISSP, Senior Software QA Engineer, Product Security, Symantec Corporation

"Here's to a fun, exciting read: a unique book chock-full of practical examples of the uses and the misuses of computer security. I expect that it will motivate a good number of college students to want to learn more about the field, at the same time that it will satisfy the more experienced professional."
--L. Felipe Perrone, Department of Computer Science, Bucknell University

Whether you're a security practitioner, developer, manager, or administrator, this book will give you the deep understanding necessary to meet today's security challenges--and anticipate tomorrow's. Unlike most books, The Craft of System Security doesn't just review the modern security practitioner's toolkit: It explains why each tool exists, and discusses how to use it to solve real problems.

After quickly reviewing the history of computer security, the authors move on to discuss the modern landscape, showing how security challenges and responses have evolved, and offering a coherent framework for understanding today's systems and vulnerabilities. Next, they systematically introduce the basic building blocks for securing contemporary systems, apply those building blocks to today's applications, and consider important emerging trends such as hardware-based security.

After reading this book, you will be able to

  • Understand the classic Orange Book approach to security, and its limitations
  • Use operating system security tools and structures--with examples from Windows, Linux, BSD, and Solaris
  • Learn how networking, the Web, and wireless technologies affect security
  • Identify software security defects, from buffer overflows to development process flaws
  • Understand cryptographic primitives and their use in secure systems
  • Use best practice techniques for authenticating people and computer systems in diverse settings
  • Use validation, standards, and testing to enhance confidence in a system's security
  • Discover the security, privacy, and trust issues arising from desktop productivity tools
  • Understand digital rights management, watermarking, information hiding, and policy expression
  • Learn principles of human-computer interaction (HCI) design for improved security
  • Understand the potential of emerging work in hardware-based security and trusted computing

商品描述(中文翻譯)

《系統安全的技藝》是當今市場上最好的軟體安全書籍之一。我相信它不僅涵蓋廣泛,還具有深度,涉及的主題包括密碼學、網路、作業系統,甚至是網路、計算機與人類的互動,以及如何通過改善硬體來提高軟體系統的安全性。總之,這本書應該是所有計劃自稱為安全從業者的人必讀的書籍,也是每所大學計算機科學課程中不可或缺的一部分。
-- Edward Bonver, CISSP,產品安全高級軟體質量保證工程師,Symantec Corporation

祝這本書閱讀愉快且充滿刺激:這是一本獨特的書,充滿了計算機安全的實際使用和誤用的範例。我期待它能激勵許多大學生想要深入了解這個領域,同時也能滿足更有經驗的專業人士。
-- L. Felipe Perrone,巴克內爾大學計算機科學系

無論您是安全從業者、開發人員、經理還是管理員,這本書將為您提供應對當今安全挑戰所需的深刻理解,並預見明天的挑戰。與大多數書籍不同,《系統安全的技藝》不僅僅是回顧現代安全從業者的工具包:它解釋了每個工具存在的原因,並討論如何使用它來解決實際問題。

在快速回顧計算機安全的歷史後,作者接著討論現代的安全環境,展示安全挑戰和應對措施是如何演變的,並提供了一個理解當今系統和漏洞的連貫框架。接下來,他們系統地介紹了保護當代系統的基本構建塊,將這些構建塊應用於當今的應用程式,並考慮硬體安全等重要的新興趨勢。

閱讀完這本書後,您將能夠:
- 理解經典的橙皮書安全方法及其局限性
- 使用作業系統安全工具和結構,並提供來自 Windows、Linux、BSD 和 Solaris 的範例
- 學習網路、網頁和無線技術如何影響安全性
- 識別軟體安全缺陷,從緩衝區溢出到開發過程中的缺陷
- 理解密碼學原語及其在安全系統中的應用
- 在多樣的環境中使用最佳實踐技術來驗證人員和計算機系統
- 使用驗證、標準和測試來增強系統安全性的信心
- 發現桌面生產力工具所引發的安全、隱私和信任問題
- 理解數位版權管理、水印、資訊隱藏和政策表達
- 學習改善安全性的計算機與人類互動(HCI)設計原則
- 理解新興的硬體安全和可信計算工作的潛力