Bulletproof TLS and PKI, Second Edition: Understanding and Deploying SSL/TLS and PKI to Secure Servers and Web Applications (Paperback)
暫譯: 防彈 TLS 與 PKI,第二版:理解與部署 SSL/TLS 及 PKI 以保護伺服器和網頁應用程式 (平裝本)
Ristic, Ivan
買這商品的人也買了...
-
$3,360$3,192 -
$1,200$1,176 -
$800$632 -
$800$632 -
$594$564 -
$980$774 -
$780$546 -
$534$507 -
$414$393 -
$419$398
相關主題
商品描述
Bulletproof TLS and PKI is a complete guide to using TLS encryption and PKI to deploy secure servers and web applications. Written by Ivan Ristic, author of the popular SSL Labs web site, this book will teach you everything you need to know to protect your systems from eavesdropping and impersonation attacks.
In this book, you'll find just the right mix of theory, protocol detail, vulnerability and weakness information, and deployment advice to get your job done:
- Comprehensive coverage of the ever-changing field of SSL/TLS and Internet PKI, with updates to the digital version
- For IT professionals, help to understand security risks
- For system administrators, help to deploy systems securely
- For developers, help to secure web applications
- Practical and concise, with added depth as needed
- Introduction to cryptography and the Internet threat model
- Coverage of TLS 1.3 as well as earlier protocol versions
- Discussion of weaknesses at every level, covering implementation issues, HTTP and browser problems, and protocol vulnerabilities
- Coverage of the latest attacks, such as BEAST, CRIME, BREACH, Lucky 13, RC4 biases, Triple Handshake Attack, and Heartbleed
- Thorough deployment advice, including advanced technologies, such as Strict Transport Security, Content Security Policy, and pinning
- Guide to using OpenSSL to generate keys and certificates and to create and run a private certification authority
- Guide to using OpenSSL to test servers for vulnerabilities
This book is also available in a variety of digital formats directly from the publisher. Visit us at www.feistyduck.com.
商品描述(中文翻譯)
《防彈 TLS 和 PKI》是一本完整的指南,教您如何使用 TLS 加密和 PKI 部署安全的伺服器和網路應用程式。這本書的作者是 Ivan Ristic,他也是知名的 SSL Labs 網站的創建者,將教您保護系統免受竊聽和冒充攻擊所需的所有知識。
在這本書中,您將找到理論、協議細節、漏洞和弱點資訊以及部署建議的完美組合,以幫助您完成工作:
- 全面涵蓋不斷變化的 SSL/TLS 和網際網路 PKI 領域,數位版本會持續更新
- 為 IT 專業人員提供理解安全風險的幫助
- 為系統管理員提供安全部署系統的幫助
- 為開發人員提供保護網路應用程式的幫助
- 實用且簡潔,必要時提供更深入的內容
- 介紹密碼學和網際網路威脅模型
- 涵蓋 TLS 1.3 及早期協議版本
- 討論各層級的弱點,包括實作問題、HTTP 和瀏覽器問題以及協議漏洞
- 涵蓋最新攻擊,例如 BEAST、CRIME、BREACH、Lucky 13、RC4 偏差、Triple Handshake Attack 和 Heartbleed
- 提供徹底的部署建議,包括先進技術,如嚴格傳輸安全 (Strict Transport Security)、內容安全政策 (Content Security Policy) 和釘選 (pinning)
- 指導使用 OpenSSL 生成金鑰和證書,以及創建和運行私有認證機構
- 指導使用 OpenSSL 測試伺服器的漏洞
這本書也以多種數位格式直接從出版商處提供。請訪問我們的網站 www.feistyduck.com。