Enterprise Level Security 1 & 2
暫譯: 企業級安全 1 & 2

Foltz, Kevin, Simpson, William R.

  • 出版商: CRC
  • 出版日期: 2020-09-11
  • 售價: $4,760
  • 貴賓價: 9.5$4,522
  • 語言: 英文
  • 頁數: 500
  • 裝訂: Hardcover - also called cloth, retail trade, or trade
  • ISBN: 036753407X
  • ISBN-13: 9780367534073
  • 相關分類: 資訊安全
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

Enterprise Level Security: Securing Information Systems in an Uncertain World provides a modern alternative to the fortress approach to security. The new approach is more distributed and has no need for passwords or accounts. Global attacks become much more difficult, and losses are localized, should they occur. The security approach is derived from a set of tenets that form the basic security model requirements. Many of the changes in authorization within the enterprise model happen automatically. Identities and claims for access occur during each step of the computing process.

 

Many of the techniques in this book have been piloted. These techniques have been proven to be resilient, secure, extensible, and scalable. The operational model of a distributed computer environment defense is currently being implemented on a broad scale for a particular enterprise.

 

The first section of the book comprises seven chapters that cover basics and philosophy, including discussions on identity, attributes, access and privilege, cryptography, the cloud, and the network. These chapters contain an evolved set of principles and philosophies that were not apparent at the beginning of the project.

 

The second section, consisting of chapters eight through twenty-two, contains technical information and details obtained by making painful mistakes and reworking processes until a workable formulation was derived. Topics covered in this section include claims-based authentication, credentials for access claims, claims creation, invoking an application, cascading authorization, federation, and content access control. This section also covers delegation, the enterprise attribute ecosystem, database access, building enterprise software, vulnerability analyses, the enterprise support desk, and network defense.

Enterprise Level Security 2: Advanced Topics in an Uncertain World follows on from the authors’ first book on Enterprise Level Security (ELS), which covered the basic concepts of ELS and the discoveries made during the first eight years of its development. This book follows on from this to give a discussion of advanced topics and solutions, derived from 16 years of research, pilots, and operational trials in putting an enterprise system together. The chapters cover specific advanced topics derived from painful mistakes and numerous revisions of processes. This book covers many of the topics omitted from the first book including multi-factor authentication, cloud key management, enterprise change management, entity veracity, homomorphic computing, device management, mobile ad hoc, big data, mediation, and several other topics. The ELS model of enterprise security is endorsed by the Secretary of the Air Force for Air Force computing systems and is a candidate for DoD systems under the Joint Information Environment Program. The book is intended for enterprise IT architecture developers, application developers, and IT security professionals. This is a unique approach to end-to-end security and fills a niche in the market. Dr. Kevin E. Foltz, Institute for Defense Analyses, has over a decade of experience working to improve security in information systems. He has presented and published research on different aspects of enterprise security, security modeling, and high assurance systems. He also has degrees in Mathematics, Computer Science, Electrical Engineering, and Strategic Security Studies. Dr. William R. Simpson, Institute for Defense Analyses, has over two decades of experience working to improve systems security. He has degrees in Aeronautical Engineering and Business Administration, as well as undergoing military and government training. He spent many years as an expert in aeronautics before delving into the field of electronic and system testing, and he has spent the last 20 years on IT-related themes (mostly security, including processes, damage assessments of cyber intrusions, IT security standards, IT security evaluation, and IT architecture).

商品描述(中文翻譯)

《企業級安全:在不確定的世界中保護資訊系統》提供了一種現代的安全替代方案,取代了傳統的堡壘式安全方法。這種新方法更加分散,無需密碼或帳戶。全球攻擊變得更加困難,若發生損失也會局部化。這種安全方法源自一組基本安全模型要求的信條。企業模型中的許多授權變更是自動發生的。身份和訪問聲明在計算過程的每一步中都會出現。

本書中的許多技術已經過試點,這些技術已被證明具有韌性、安全性、可擴展性和可擴展性。分散式計算環境防禦的操作模型目前正在某個企業中大規模實施。

本書的第一部分由七章組成,涵蓋基礎知識和哲學,包括對身份、屬性、訪問和特權、密碼學、雲端和網絡的討論。這些章節包含了一組進化的原則和哲學,這些在項目開始時並不明顯。

第二部分由第八章到第二十二章組成,包含了通過痛苦的錯誤和重構過程所獲得的技術信息和細節,直到得出可行的公式。本部分涵蓋的主題包括基於聲明的身份驗證、訪問聲明的憑證、聲明創建、調用應用程序、級聯授權、聯邦和內容訪問控制。本部分還涵蓋了委派、企業屬性生態系統、數據庫訪問、企業軟件構建、漏洞分析、企業支持桌面和網絡防禦。

《企業級安全 2:在不確定的世界中的進階主題》是作者第一本《企業級安全》(ELS)的延續,該書涵蓋了ELS的基本概念以及在最初八年開發過程中所做的發現。本書在此基礎上討論了進階主題和解決方案,這些都是基於16年的研究、試點和運營試驗所衍生的。各章節涵蓋了源自痛苦錯誤和多次修訂過程的具體進階主題。本書涵蓋了許多在第一本書中省略的主題,包括多因素身份驗證、雲端金鑰管理、企業變更管理、實體真實性、同態計算、設備管理、移動自組織、大數據、中介以及其他幾個主題。ELS企業安全模型得到了空軍部長對空軍計算系統的支持,並且是國防部系統在聯合信息環境計劃下的候選者。本書旨在針對企業IT架構開發者、應用程序開發者和IT安全專業人士。這是一種獨特的端到端安全方法,填補了市場上的一個利基。凱文·E·福爾茨博士,國防分析研究所,擁有超過十年的經驗,致力於改善資訊系統的安全性。他在企業安全、安全建模和高保障系統的不同方面發表過研究並進行過報告。他還擁有數學、計算機科學、電氣工程和戰略安全研究的學位。威廉·R·辛普森博士,國防分析研究所,擁有超過二十年的經驗,致力於改善系統安全。他擁有航空工程和工商管理的學位,並接受過軍事和政府的培訓。他在航空學領域擔任專家多年,然後轉向電子和系統測試領域,並在過去20年中專注於IT相關主題(主要是安全,包括過程、網絡入侵的損害評估、IT安全標準、IT安全評估和IT架構)。

作者簡介

Dr. Kevin E. Foltz, Institute for Defense Analyses, has over a decade of experience working to improve security in information systems. He has presented and published research on different aspects of enterprise security, security modeling, and high assurance systems. He also has degrees in Mathematics, Computer Science, Electrical Engineering, and Strategic Security Studies.

Dr. William R. Simpson, Institute for Defense Analyses, has over two decades of experience working to improve systems security. He has degrees in Aeronautical Engineering and Business Administration, as well as undergoing military and government training. He spent many years as an expert in aeronautics before delving into the field of electronic and system testing, and he has spent the last 20 years on IT-related themes (mostly security, including processes, damage assessments of cyber intrusions, IT security standards, IT security evaluation, and IT architecture).

作者簡介(中文翻譯)

凱文·E·福茲博士,國防分析研究所,擁有超過十年的資訊系統安全改善經驗。他在企業安全、安全建模和高保障系統等不同方面發表過研究並進行過報告。他擁有數學、計算機科學、電機工程和戰略安全研究的學位。

威廉·R·辛普森博士,國防分析研究所,擁有超過二十年的系統安全改善經驗。他擁有航空工程和工商管理的學位,並接受過軍事和政府的訓練。他在航空學領域擔任專家多年,之後轉向電子和系統測試領域,並在過去的20年中專注於與資訊科技相關的主題(主要是安全,包括流程、網路入侵的損害評估、資訊科技安全標準、資訊科技安全評估和資訊科技架構)。