The Art of Deception: Controlling the Human Element of Security
暫譯: 欺騙的藝術:掌控安全中的人類因素

Kevin D. Mitnick, William L. Simon

  • 出版商: Wiley
  • 出版日期: 2002-10-11
  • 售價: $980
  • 貴賓價: 9.8$960
  • 語言: 英文
  • 頁數: 304
  • 裝訂: Hardcover
  • ISBN: 0471237124
  • ISBN-13: 9780471237129
  • 相關分類: 資訊安全
  • 下單後立即進貨 (約5~7天)

買這商品的人也買了...

相關主題

商品描述

The world's most infamous hacker offers an insider's view of the low-tech threats to high-tech security
Kevin Mitnick's exploits as a cyber-desperado and fugitive form one of the most exhaustive FBI manhunts in history and have spawned dozens of articles, books, films, and documentaries. Since his release from federal prison, in 1998, Mitnick has turned his life around and established himself as one of the most sought-after computer security experts worldwide. Now, in The Art of Deception, the world's most notorious hacker gives new meaning to the old adage, "It takes a thief to catch a thief."
Focusing on the human factors involved with information security, Mitnick explains why all the firewalls and encryption protocols in the world will never be enough to stop a savvy grifter intent on rifling a corporate database or an irate employee determined to crash a system. With the help of many fascinating true stories of successful attacks on business and government, he illustrates just how susceptible even the most locked-down information systems are to a slick con artist impersonating an IRS agent. Narrating from the points of view of both the attacker and the victims, he explains why each attack was so successful and how it could have been prevented in an engaging and highly readable style reminiscent of a true-crime novel. And, perhaps most importantly, Mitnick offers advice for preventing these types of social engineering hacks through security protocols, training programs, and manuals that address the human element of security.

Table of Contents

Foreword.

Preface.

Introduction.

Part 1: Behind the Scenes.

Chapter 1: Security's Weakest Link.

Part 2: The Art of the Attacker.

Chapter 2: When Innocuous Information Isn't.

Chapter 3: The Direct Attack: Just Asking for It.

Chapter 4: Building Trust.

Chapter 5: "Let Me Help You".

Chapter 6: "Can You Help Me?".

Chapter 7: Phony Sites and Dangerous Attachments.

Chapter 8: Using Sympathy, Guilt, and Intimidation.

Chapter 9: The Reverse Sting.

Part 3: Intruder Alert.

Chapter 10: Entering the Premises.

Chapter 11: Combining Technology and Social Engineering.

Chapter 12: Attacks on the Entry-Level Employee.

Chapter 13: Clever Cons.

Chapter 14: Industrial Espionage.

Part 4: Raising the Bar.

Chapter 15: Information Security Awareness and Training.

Chapter 16: Recommended Corporate Information Security Policies.

Security at a Glance.

Sources.

Acknowledgments.

Index.

商品描述(中文翻譯)

世界上最臭名昭著的駭客提供了對低科技威脅高科技安全的內幕觀察。Kevin Mitnick作為網路逃犯的經歷,形成了歷史上最徹底的FBI追捕之一,並催生了數十篇文章、書籍、電影和紀錄片。自1998年從聯邦監獄釋放以來,Mitnick已經改變了自己的生活,並確立了自己作為全球最受追捧的電腦安全專家之一的地位。現在,在《欺騙的藝術》中,這位世界上最臭名昭著的駭客賦予了古老諺語“要抓住小偷,必須有小偷”的新意。

Mitnick專注於信息安全中的人為因素,解釋了為什麼世界上所有的防火牆和加密協議都無法阻止一個精明的騙子意圖侵入企業數據庫或一名憤怒的員工決心癱瘓系統。通過許多引人入勝的真實故事,講述成功攻擊商業和政府的案例,他展示了即使是最嚴密的信息系統也會受到假冒國稅局(IRS)代理人的光滑騙子的影響。從攻擊者和受害者的角度敘述,他解釋了每次攻擊為什麼如此成功,以及如何能夠防止這些攻擊,以引人入勝且易讀的風格,讓人聯想到真實犯罪小說。而且,也許最重要的是,Mitnick提供了防止這類社會工程攻擊的建議,通過安全協議、培訓計劃和手冊來解決安全中的人為因素。

目錄
前言
序言
引言
第一部分:幕後
第一章:安全的最弱環節
第二部分:攻擊者的藝術
第二章:當無害的信息並非如此
第三章:直接攻擊:自找麻煩
第四章:建立信任
第五章:“讓我幫你”
第六章:“你能幫我嗎?”
第七章:假網站和危險附件
第八章:利用同情、內疚和威脅
第九章:反向誘捕
第三部分:入侵者警報
第十章:進入場所
第十一章:結合技術與社會工程
第十二章:針對入門級員工的攻擊
第十三章:巧妙的詐騙
第十四章:工業間諜活動
第四部分:提高標準
第十五章:信息安全意識與培訓
第十六章:建議的企業信息安全政策

安全概覽
來源
致謝
索引

最後瀏覽商品 (20)