Practical Security
暫譯: 實用安全性

Roman Zabicki

  • 出版商: Pragmatic Bookshelf
  • 出版日期: 2019-03-26
  • 售價: $1,080
  • 貴賓價: 9.5$1,026
  • 語言: 英文
  • 頁數: 134
  • 裝訂: Paperback
  • ISBN: 168050634X
  • ISBN-13: 9781680506341
  • 相關分類: 資訊安全
  • 立即出貨 (庫存 < 3)

買這商品的人也買了...

相關主題

商品描述

Most security professionals don't have the words "security" or "hacker" in their job title. Instead, as a developer or admin you often have to fit in security alongside your official responsibilities - building and maintaining computer systems. Implement the basics of good security now, and you'll have a solid foundation if you bring in a dedicated security staff later. Identify the weaknesses in your system, and defend against the attacks most likely to compromise your organization, without needing to become a trained security professional.

Computer security is a complex issue. But you don't have to be an expert in all the esoteric details to prevent many common attacks. Attackers are opportunistic and won't use a complex attack when a simple one will do. You can get a lot of benefit without too much complexity, by putting systems and processes in place that ensure you aren't making the obvious mistakes. Secure your systems better, with simple (though not always easy) practices.

Plan to patch often to improve your security posture. Identify the most common software vulnerabilities, so you can avoid them when writing software. Discover cryptography - how it works, how easy it is to get wrong, and how to get it right. Configure your Windows computers securely. Defend your organization against phishing attacks with training and technical defenses.

Make simple changes to harden your system against attackers.

What You Need:

You don't need any particular software to follow along with this book. Examples in the book describe security vulnerabilities and how to look for them. These examples will be more interesting if you have access to a code base you've worked on. Similarly, some examples describe network vulnerabilities and how to detect them. These will be more interesting with access to a network you support.

商品描述(中文翻譯)

大多數安全專業人士的職稱中並不包含「安全」或「駭客」這些字眼。相反地,作為開發人員或管理員,您經常需要將安全性納入您的正式職責中——建立和維護計算機系統。現在實施良好安全性的基本原則,將為您日後引入專門的安全人員打下堅實的基礎。識別系統中的弱點,並防範最有可能危害您組織的攻擊,而無需成為受過訓練的安全專業人士。

計算機安全是一個複雜的問題。但您不必精通所有深奧的細節,就能防止許多常見的攻擊。攻擊者是機會主義者,當簡單的攻擊足以達到目的時,他們不會使用複雜的攻擊。通過建立系統和流程,確保您不會犯明顯的錯誤,您可以在不增加太多複雜性的情況下獲得很多好處。以簡單(雖然不總是容易)的做法來更好地保護您的系統。

計劃經常進行修補,以改善您的安全姿態。識別最常見的軟體漏洞,以便在編寫軟體時避免它們。了解加密技術——它是如何運作的,出錯有多容易,以及如何正確使用它。安全配置您的 Windows 計算機。通過培訓和技術防禦來保護您的組織免受釣魚攻擊。

進行簡單的更改,以加強您的系統抵禦攻擊者的能力。

您需要的:

您不需要任何特定的軟體來跟隨本書的內容。本書中的範例描述了安全漏洞及其檢測方法。如果您能接觸到您曾經參與的代碼庫,這些範例會更有趣。同樣,一些範例描述了網路漏洞及其檢測方法。如果您能接觸到您所支持的網路,這些範例會更有趣。