Multi-Domain Access Control and Trust (Synthesis Lectures on Information Security, Privacy, and Trust)
暫譯: 多域存取控制與信任(資訊安全、隱私與信任綜合講座)

James Joshi

  • 出版商: Morgan & Claypool
  • 出版日期: 2019-03-29
  • 售價: $1,600
  • 貴賓價: 9.5$1,520
  • 語言: 英文
  • 頁數: 112
  • 裝訂: Paperback
  • ISBN: 1627051473
  • ISBN-13: 9781627051477
  • 相關分類: 資訊安全
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

In recent years, we have been witness to rapid advances in high-performance computing and networking technologies that have given rise to tremendous growth of large-scale distributed IT environments. Security and privacy have become significant concerns in such environments. An essential aspect of current and emerging IT environments is the interconnectedness of different components in the form of heterogeneous systems, applications, or entire IT infrastructures. In some cases such environments span state (e.g., in an eGovernment environment ) and national boundaries (e.g., in the case of multinational enterprises and their partnership with other multinational enterprises). These environments often give rise to serious challenges with regards security and privacy requirements and enforcement. Such environments are essentially multidomain environments where multiple security and administrative domains coexist with their individual sets of security and privacy requirements as well as administrative control. This amalgam of heterogeneous IT domains with their unique protection requirements are becoming more of a common phenomenon than individual, isolated systems that were seen decades ago. Examples of these multidomain environments include Internet-based applications, digital government environments, integrated healthcare systems, IT infrastructure in multinational enterprises. Recently growing Cybersecurity incidents including compromise of various commercial systems, nation or state sponsored cyber-attacks (e.g., Chinese hackers infiltrating US institutions , growing attacks from Iran , Stuxnet, etc.), have allowed us to peek into the dangers of how globally connected Internet environments and the heterogeneity of protection measures of interconnected infrastructures may be exploited in the digital world. To ensure the success of current and emerging highly interconnected, distributed, multidomain environments, it is imperative that we have effective and efficient security mechanisms and frameworks that provide holistic solutions to security and privacy challenges in such complex environments. While many security issues need to be addressed in an integrated way, key towards building such secure environments is to develop appropriate models and mechanisms for establishing appropriated level of trust and managing cross domain accesses. While other security issues such as authentication, intrusion detection, and response, security accounting, etc. are as important, we focus on the central issues of access and trust management in this book.

商品描述(中文翻譯)

近年來,我們目睹了高效能計算和網路技術的快速進步,這些進步促成了大規模分散式 IT 環境的巨大增長。在這樣的環境中,安全性和隱私已成為重要的關注點。當前和新興的 IT 環境的一個基本特徵是不同組件之間的互聯性,這些組件以異構系統、應用程式或整個 IT 基礎設施的形式存在。在某些情況下,這些環境跨越了州(例如,在電子政府環境中)和國家邊界(例如,在跨國企業及其與其他跨國企業的合作中)。這些環境經常帶來與安全性和隱私要求及執行相關的嚴重挑戰。這些環境本質上是多域環境,其中多個安全和管理域共存,並擁有各自的安全和隱私要求以及管理控制。這種異構 IT 域的混合及其獨特的保護要求,正變得比幾十年前所見的個別孤立系統更為普遍。這些多域環境的例子包括基於網際網路的應用程式、數位政府環境、整合醫療系統、跨國企業的 IT 基礎設施。最近,隨著網路安全事件的增加,包括各種商業系統的妥協、國家或政府贊助的網路攻擊(例如,中國黑客滲透美國機構、來自伊朗的攻擊增長、Stuxnet 等),讓我們得以窺見全球互聯網環境的危險,以及互聯基礎設施的保護措施的異質性如何在數位世界中被利用。為了確保當前和新興的高度互聯、分散式、多域環境的成功,我們必須擁有有效且高效的安全機制和框架,提供針對這些複雜環境中安全和隱私挑戰的整體解決方案。雖然許多安全問題需要以整合的方式來解決,但建立這些安全環境的關鍵在於開發適當的模型和機制,以建立適當的信任水平並管理跨域訪問。雖然其他安全問題如身份驗證、入侵檢測和響應、安全會計等同樣重要,但本書將重點放在訪問和信任管理的核心問題上。