Bulletproof SSL and TLS: Understanding and Deploying SSL/TLS and PKI to Secure Servers and Web Applications (Paperback)
暫譯: 防彈 SSL 與 TLS:理解與部署 SSL/TLS 及 PKI 以保護伺服器和網頁應用程式 (平裝本)

Ivan Ristic

買這商品的人也買了...

相關主題

商品描述

Bulletproof SSL and TLS is a complete guide to using SSL and TLS encryption to deploy secure servers and web applications. Written by Ivan Ristic, the author of the popular SSL Labs web site, this book will teach you everything you need to know to protect your systems from eavesdropping and impersonation attacks.

In this book, you'll find just the right mix of theory, protocol detail, vulnerability and weakness information, and deployment advice to get your job done:

  • Comprehensive coverage of the ever-changing field of SSL/TLS and Internet PKI, with updates to the digital version
  • For IT security professionals, help to understand the risks
  • For system administrators, help to deploy systems securely
  • For developers, help to design and implement secure web applications
  • Practical and concise, with added depth when details are relevant
  • Introduction to cryptography and the latest TLS protocol version
  • Discussion of weaknesses at every level, covering implementation issues, HTTP and browser problems, and protocol vulnerabilities
  • Coverage of the latest attacks, such as BEAST, CRIME, BREACH, Lucky 13, RC4 biases, Triple Handshake Attack, and Heartbleed
  • Thorough deployment advice, including advanced technologies, such as Strict Transport Security, Content Security Policy, and pinning
  • Guide to using OpenSSL to generate keys and certificates and to create and run a private certification authority
  • Guide to using OpenSSL to test servers for vulnerabilities
  • Practical advice for secure server configuration using Apache httpd, IIS, Java, Nginx, Microsoft Windows, and Tomcat

This book is available in paperback and a variety of digital formats without DRM. Digital version of Bulletproof SSL and TLS can be obtained directly from the author, at feistyduck.com.

商品描述(中文翻譯)

《防彈 SSL 和 TLS》是一本完整的指南,教你如何使用 SSL 和 TLS 加密來部署安全的伺服器和網路應用程式。這本書的作者是 Ivan Ristic,他也是知名的 SSL Labs 網站的創建者,將教你保護系統免受竊聽和冒充攻擊所需的所有知識。

在這本書中,你將找到理論、協議細節、漏洞和弱點資訊以及部署建議的完美組合,以幫助你完成工作:

- 全面涵蓋不斷變化的 SSL/TLS 和網際網路 PKI 領域,數位版本會持續更新
- 為 IT 安全專業人員提供理解風險的幫助
- 為系統管理員提供安全部署系統的幫助
- 為開發人員提供設計和實現安全網路應用程式的幫助
- 實用且簡潔,當細節相關時會提供更深入的內容
- 介紹密碼學和最新的 TLS 協議版本
- 討論各層級的弱點,涵蓋實作問題、HTTP 和瀏覽器問題以及協議漏洞
- 涵蓋最新的攻擊,例如 BEAST、CRIME、BREACH、Lucky 13、RC4 偏差、Triple Handshake Attack 和 Heartbleed
- 徹底的部署建議,包括進階技術,如嚴格傳輸安全 (Strict Transport Security)、內容安全政策 (Content Security Policy) 和釘選 (pinning)
- 指導使用 OpenSSL 生成金鑰和證書,以及創建和運行私有認證機構
- 指導使用 OpenSSL 測試伺服器的漏洞
- 提供使用 Apache httpd、IIS、Java、Nginx、Microsoft Windows 和 Tomcat 進行安全伺服器配置的實用建議

這本書有平裝本和多種無 DRM 的數位格式可供選擇。**《防彈 SSL 和 TLS》的數位版本可以直接從作者那裡獲得,網址為 feistyduck.com。**