<p><p>This book explores fundamental principles for securing IT systems and illustrates them with hands-on experiments that may be carried out by the reader using accompanying software. The experiments highlight key information security problems that arise in modern operating systems, networks, and
Applied Information Security: A Hands-on Approach
โ Scribed by David Basin, Patrick Schaller, Michael Schlรคpfer (auth.)
- Publisher
- Springer-Verlag Berlin Heidelberg
- Year
- 2011
- Tongue
- English
- Leaves
- 212
- Edition
- 1
- Category
- Library
No coin nor oath required. For personal study only.
โฆ Synopsis
This book explores fundamental principles for securing IT systems and illustrates them with hands-on experiments that may be carried out by the reader using accompanying software. The experiments highlight key information security problems that arise in modern operating systems, networks, and web applications. The authors explain how to identify and exploit such problems and they show different countermeasures and their implementation. The reader thus gains a detailed understanding of how vulnerabilities arise and practical experience tackling them.
After presenting the basics of security principles, virtual environments, and network services, the authors explain the core security principles of authentication and access control, logging and log analysis, web application security, certificates and public-key cryptography, and risk management. The book concludes with appendices on the design of related courses, report templates, and the basics of Linux as needed for the assignments.
The authors have successfully taught IT security to students and professionals using the content of this book and the laboratory setting it describes. The book can be used in undergraduate or graduate laboratory courses, complementing more theoretically oriented courses, and it can also be used for self-study by IT professionals who want hands-on experience in applied information security. The authors' supporting software is freely available online and the text is supported throughout with exercises.
โฆ Table of Contents
Front Matter....Pages I-XIV
Security Principles....Pages 1-16
The Virtual Environment....Pages 17-26
Network Services....Pages 27-45
Authentication and Access Control....Pages 47-67
Logging and Log Analysis....Pages 69-80
Web Application Security....Pages 81-101
Certificates and Public Key Cryptography....Pages 103-116
Risk Management....Pages 117-145
Back Matter....Pages 147-202
โฆ Subjects
Systems and Data Security; Data Structures, Cryptology and Information Theory; Management of Computing and Information Systems; Innovation/Technology Management; Business Information Systems
๐ SIMILAR VOLUMES
<span><b>Teaching computer and network security principles via hands-on activities</b><br>Unique among computer security texts, the Second Edition of the Computer & Internet Security: A Hands-on Approach builds on the authorโs long tradition of teaching this complex subject through a hands-on ap
Hardware Security: A Hands-On Learning Approach provides a broad, comprehensive and practical overview of hardware security that encompasses all levels of the electronic hardware infrastructure. It covers basic concepts like advanced attack techniques and countermeasures that are illustrated through
Teaching computer and network security principles via hands-on activities Unique among computer security texts, the Second Edition of the Computer & Internet Security: A Hands-on Approach builds on the authorโs long tradition of teaching this complex subject through a hands-on approach. For each se
HANDS-ON INFORMATION SECURITY LAB MANUAL, Fourth Edition, helps you hone essential information security skills by applying your knowledge to detailed, realistic exercises using Microsoftยฎ Windowsยฎ 2000, Windows XP, Windows 7, and Linux. This wide-ranging, non-certification-based lab manual includes
<p><span>This book demonstrates how information security requires a deep understanding of an organization's assets, threats and processes, combined with the technology that can best protect organizational security. It provides step-by-step guidance on how to analyze business processes from a securit