Enterprise Level Security: Securing Information Systems in an Uncertain World
暫譯: 企業級安全:在不確定的世界中保護資訊系統

Simpson, William R.

  • 出版商: Auerbach Publication
  • 出版日期: 2020-09-30
  • 售價: $2,070
  • 貴賓價: 9.5$1,967
  • 語言: 英文
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 0367658518
  • ISBN-13: 9780367658519
  • 相關分類: 資訊安全
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

Enterprise Level Security: Securing Information Systems in an Uncertain World provides a modern alternative to the fortress approach to security. The new approach is more distributed and has no need for passwords or accounts. Global attacks become much more difficult, and losses are localized, should they occur. The security approach is derived from a set of tenets that form the basic security model requirements. Many of the changes in authorization within the enterprise model happen automatically. Identities and claims for access occur during each step of the computing process.

 

Many of the techniques in this book have been piloted. These techniques have been proven to be resilient, secure, extensible, and scalable. The operational model of a distributed computer environment defense is currently being implemented on a broad scale for a particular enterprise.

The first section of the book comprises seven chapters that cover basics and philosophy, including discussions on identity, attributes, access and privilege, cryptography, the cloud, and the network. These chapters contain an evolved set of principles and philosophies that were not apparent at the beginning of the project.

The second section, consisting of chapters eight through twenty-two, contains technical information and details obtained by making painful mistakes and reworking processes until a workable formulation was derived. Topics covered in this section include claims-based authentication, credentials for access claims, claims creation, invoking an application, cascading authorization, federation, and content access control. This section also covers delegation, the enterprise attribute ecosystem, database access, building enterprise software, vulnerability analyses, the enterprise support desk, and network defense.

商品描述(中文翻譯)

企業級安全性:在不確定的世界中保護資訊系統 提供了一種現代的安全替代方案,取代了傳統的堡壘式安全方法。這種新方法更加分散,且不需要密碼或帳戶。全球性的攻擊變得更加困難,若發生損失也會是局部的。這種安全方法源自一組基本的安全模型需求原則。企業模型中的許多授權變更是自動發生的。身份和訪問聲明在計算過程的每一步中都會出現。

本書中的許多技術已經進行了試點。這些技術已被證明是具有韌性、安全性、可擴展性和可擴充性的。分散式計算環境防禦的操作模型目前正在某個特定企業中大規模實施。

本書的第一部分包含七章,涵蓋基礎知識和哲學,包括對身份、屬性、訪問和特權、密碼學、雲端和網絡的討論。這些章節包含了一組進化的原則和哲學,這些在項目開始時並不明顯。

第二部分由第八章到第二十二章組成,包含了通過痛苦的錯誤和重新加工過程所獲得的技術信息和細節,直到得出可行的公式。這部分涵蓋的主題包括基於聲明的身份驗證、訪問聲明的憑證、聲明創建、調用應用程序、級聯授權、聯邦和內容訪問控制。這部分還涵蓋了委派、企業屬性生態系統、數據庫訪問、構建企業軟體、漏洞分析、企業支援桌面和網絡防禦。

作者簡介

Dr. William R. Simpson earned his bachelor of science in aerospace engineering from Virginia Polytechnic Institute and State University, a master of science and a doctor of philosophy in aeronautical and astronautical engineering from Ohio State University, and a master of science in administration from George Washington University. He has held academic positions at George Mason University, Old Dominion University, the University of Maryland, and Ohio State University. He has held industry positions at the US Naval Air Test Center, the Center for Naval Analyses, the ARINC Research Corporation, and the Institute for Defense Analyses.

作者簡介(中文翻譯)

威廉·R·辛普森博士於維吉尼亞理工學院獲得航空工程學士學位,並在俄亥俄州立大學獲得航空與太空工程碩士及哲學博士學位,以及在喬治華盛頓大學獲得行政碩士學位。他曾在喬治梅森大學、老道明大學、馬里蘭大學和俄亥俄州立大學擔任學術職位。他也曾在美國海軍航空測試中心、海軍分析中心、ARINC研究公司和國防分析研究所擔任業界職位。