Security Engineering: A Guide to Building Dependable Distributed Systems, Second Edition
by Ross J. Anderson
Part I. PART I
In this section of the book, I cover the basics of security engineering technology. The first chapter sets out to define the subject matter by giving an overview of the secure distributed systems found in four environments: a bank, an air force base, a hospital, and the home. The second chapter then plunges into the thick of things by tackling usability. The interface between the user and the machine is where the most intractable problems lurk. Phishing is the most rapidly growing online crime; pretexting is the main way in which privacy is compromised; and psychology is likely to be one of the most fruitful areas of security research in coming years. We need to know more about how people can be deceived, so we can design systems that make deception harder. There is also the problem that risk perceptions and realities have drifted ever further apart, specially since 9/11.
The following chapters dig progressively deeper into the technical meat. The third chapter is on security protocols, which specify how the players in a system — whether people, computers, or other electronic devices — communicate with each other. The fourth is on access control: even once a client (be it a phone, a PC, or whatever) has authenticated itself satisfactorily to a server, we still need mechanisms to control which data it can read or write on the server and which transactions it can execute. These mechanisms operate at different levels — operating system, database, application — but share ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access