Book description
"I believe The Craft of System Security is one of the
best software security books on the market today. It has not only
breadth, but depth, covering topics ranging from cryptography,
networking, and operating systems--to the Web, computer-human
interaction, and how to improve the security of software systems by
improving hardware. Bottom line, this book should be required
reading for all who plan to call themselves security practitioners,
and an invaluable part of every university's computer science
curriculum."
--Edward Bonver, CISSP, Senior Software QA Engineer, Product
Security, Symantec Corporation
"Here's to a fun, exciting read: a unique book chock-full of
practical examples of the uses and the misuses of computer
security. I expect that it will motivate a good number of college
students to want to learn more about the field, at the same time
that it will satisfy the more experienced professional."
--L. Felipe Perrone, Department of Computer Science, Bucknell
University
Whether you're a security practitioner, developer, manager, or administrator, this book will give you the deep understanding necessary to meet today's security challenges--and anticipate tomorrow's. Unlike most books, The Craft of System Security doesn't just review the modern security practitioner's toolkit: It explains why each tool exists, and discusses how to use it to solve real problems.
After quickly reviewing the history of computer security, the authors move on to discuss the modern landscape, showing how security challenges and responses have evolved, and offering a coherent framework for understanding today's systems and vulnerabilities. Next, they systematically introduce the basic building blocks for securing contemporary systems, apply those building blocks to today's applications, and consider important emerging trends such as hardware-based security.
After reading this book, you will be able to
Understand the classic Orange Book approach to security, and its limitations
Use operating system security tools and structures--with examples from Windows, Linux, BSD, and Solaris
Learn how networking, the Web, and wireless technologies affect security
Identify software security defects, from buffer overflows to development process flaws
Understand cryptographic primitives and their use in secure systems
Use best practice techniques for authenticating people and computer systems in diverse settings
Use validation, standards, and testing to enhance confidence in a system's security
Discover the security, privacy, and trust issues arising from desktop productivity tools
Understand digital rights management, watermarking, information hiding, and policy expression
Learn principles of human-computer interaction (HCI) design for improved security
Understand the potential of emerging work in hardware-based security and trusted computing
Table of contents
- Title Page
- Copyright Page
- Dedication
- Contents
- List of Figures
- Preface
- Acknowledgments
- About the Authors
- Part I: History
- Part II: Security and the Modern Computing Landscape
- Part III: Building Blocks for Secure Systems
- Part IV: Applications
- Part V: Emerging Tools
- The Take-Home Lesson
- A. Exiled Theory
- Bibliography
- Index
- Footnotes
Product information
- Title: The Craft of System Security
- Author(s):
- Release date: November 2007
- Publisher(s): Addison-Wesley Professional
- ISBN: 9780321434838
You might also like
book
Trust in Computer Systems and the Cloud
Learn to analyze and measure risk by exploring the nature of trust and its application to …
book
Software Test Attacks to Break Mobile and Embedded Devices
This book presents an attack basis for testing mobile and embedded systems in "smart" devices. It …
book
Windows Software Compatibility and Hardware Troubleshooting
As companies keep their existing hardware and operating systems for more years than ever before, the …
book
Building Secure Firmware: Armoring the Foundation of the Platform
Use this book to build secure firmware. As operating systems and hypervisors have become successively more …