• Fri frakt över 249 kr
  • •
  • Snabba leveranser
  • •
  • Billiga böcker
Kundservice

Du är på sajten för privatpersoner.

Företag, bibliotek eller offentlig verksamhet?

Du handlar på classic.bokus.com, där alla dina funktioner finns intakta.
Till classic.bokus.com
Bokus logotyp. Gå till startsidan.
  • Erbjudanden
  • Nyheter
  • Student
  • Topplistor
  • Barn & ungdom
  • Bokus Play
  • E-böcker
  • Pocketböcker
  • Spel & pussel

10% studentrabatt med kod TERM26

Sidfot

Mina sidor

    Hjälp

    • Kundservice
    • Vanliga frågor och svar
    • Frakt och leverans
    • Retur vid ångerrätt
    • Reklamera vara
    • Betalning
    • Köpvillkor
    • Allmänna villkor
    • Information om webbplatsens tillgänglighet

    Om Bokus

    • Om oss
    • Pressrum
    • För studenter
    • För företag
    • För bibliotek och offentlig verksamhet
    • För leverantörer
    • Hållbarhet

    Populärt

    • Aktuella erbjudanden
    • Presentkort
    • Studentlitteratur
    • Nya böcker
    • Topplistor
    • Signerade böcker
    • Engelska böcker

    Inspiration

    • Boktips
    • BookTok
    • Populära bokserier
    • Barnbokskaraktärer
    • Populära författare

    Mina sidor

      Hjälp

      • Kundservice
      • Vanliga frågor och svar
      • Frakt och leverans
      • Retur vid ångerrätt
      • Reklamera vara
      • Betalning
      • Köpvillkor
      • Allmänna villkor
      • Information om webbplatsens tillgänglighet

      Om Bokus

      • Om oss
      • Pressrum
      • För studenter
      • För företag
      • För bibliotek och offentlig verksamhet
      • För leverantörer
      • Hållbarhet

      Populärt

      • Aktuella erbjudanden
      • Presentkort
      • Studentlitteratur
      • Nya böcker
      • Topplistor
      • Signerade böcker
      • Engelska böcker

      Inspiration

      • Boktips
      • BookTok
      • Populära bokserier
      • Barnbokskaraktärer
      • Populära författare
      Logotyp för Bokus
      Följ oss på Facebook (extern länk)Följ oss på Instagram (extern länk)Följ oss på YouTube (extern länk)Följ oss på TikTok (extern länk)
      bokus @ CookiesAnpassa cookiesIntegritetspolicyKöpvillkor
      Till Citymail hemsida (extern länk)Till Budbee hemsida (extern länk)Till Postnord hemsida (extern länk)Till Schenker hemsida (extern länk)Till Early Bird hemsida (extern länk)Till Walleys hemsida (extern länk)
      1. Data och IT
      2. IT-säkerhet

      System Assurance

      Beyond Detecting Vulnerabilities

      AvNikolai Mansourov,Djenana Campara

      Häftad, Engelska, 2010

      Del i serien The MK/OMG Press

      700 kr

      Beställningsvara. Skickas inom 10-15 vardagar. Fri frakt över 249 kr.

      Beskrivning

      System Assurance teaches students how to use Object Management Group's (OMG) expertise and unique standards to obtain accurate knowledge about existing software and compose objective metrics for system assurance.

      OMG's Assurance Ecosystem provides a common framework for discovering, integrating, analyzing, and distributing facts about existing enterprise software. Its foundation is the standard protocol for exchanging system facts, defined as the OMG Knowledge Discovery Metamodel (KDM). In addition, the Semantics of Business Vocabularies and Business Rules (SBVR) defines a standard protocol for exchanging security policy rules and assurance patterns. Using these standards together, students will learn how to leverage the knowledge of the cybersecurity community and bring automation to protect systems.

      This book includes an overview of OMG Software Assurance Ecosystem protocols that integrate risk, architecture, and code analysis guided by the assurance argument. A case study illustrates the steps of the System Assurance Methodology using automated tools.

      This book is recommended for technologists from a broad range of software companies and related industries; security analysts, computer systems analysts, computer software engineers-systems software, computer software engineers- applications, computer and information systems managers, network systems and data communication analysts.



      • Provides end-to-end methodology for systematic, repeatable, and affordable System Assurance.
      • Includes an overview of OMG Software Assurance Ecosystem protocols that integrate risk, architecture and code analysis guided by the assurance argument.
      • Case Study illustrating the steps of the System Assurance Methodology using automated tools.

      Produktinformation

      • Utgivningsdatum:2010-12-29
      • Mått:191 x 235 x 17 mm
      • Vikt:610 g
      • Format:Häftad
      • Språk:Engelska
      • Serie:The MK/OMG Press
      • Antal sidor:368
      • Förlag:Elsevier Science
      • ISBN:9780123814142

      Utforska kategorier

      • IT-säkerhet inom Data och IT

      Mer om författaren

      Nikolai Mansourov is recognized worldwide for his work in the areas of automatic code generation and using formal specifications in both forward and reverse engineering. Prior to joining KDM Analytics, Dr. Mansourov was the Chief Scientist and Chief Architect at Klocwork Inc, where he significantly helped build the company’s credibility. Dr. Mansourov also was a department head at the Institute for System Programming, Russian Academy of Sciences, where he was responsible for numerous groundbreaking research projects in advanced software development for industry leaders Nortel Networks and Telelogic. Dr. Mansourov has published over 50 research papers and is a frequent speaker as well as member of program committees at various international research forums. He is a founding member of the World-Wide Institute of Software Architects WWISA. His impact on the industry continues through his participation on several standards bodies, including the ITU-T and Object Management Group. Dr. Mansourov is one of the first OMG-certified UML Advanced Professionals and a member of the UML2 standardization team. Dr. Mansourov is the Editor of the OMG Knowledge Discovery Metamodel (KDM) specification and the Chair of the OMG Revision Task Force for KDM. Djenana Campara has 20+ years of experience and leadership in the software engineering field. Ms. Campara is a member of the Board of Directors of the Object Management Group (OMG). Djenana Campara chairs the OMG Architecture-Driven Modernization Task Force and Software Assurance Special Interests Group, and serves as a board member on the Canadian Consortium of Software Engineering Research (CSER). Previously, Djenana was CTO of Klocwork and chairwoman of Klocwork’s Board of Directors. Djenana founded the company in 2001 as a successful Nortel Networks spin off. She has served as Klocwork's chief executive officer, securing the company's first round of funding as well as closing its first customers.She has been awarded four US patents for her groundbreaking static analysis techniques implemented in Klocwork’s products. She has published a number of papers on software transformations, has been quoted in publications, including The Economist and Secure Computing, and has participated in Fortune Magazine's "Brainstorm 2003," an international conference of the world's most creative leaders.

      Recensioner i media

      "The Object Management Group (OMG) Software Assurance Ecosystem described in this book is a significant step towards collaborative cyber security automation; it offers a standards-based solution for building security and resilience in computer systems." --Joe Jarzombek, Director for Software Assurance, Global Cyber Security Management, National Cyber Security Division, Department of Homeland Security"System Assurance is a very complex and difficult subject. This book successfully demonstrates and describes in detail how to combine different existing tools together in order to systematically develop System Assurance documentation and justification in a practical manner for a specific domain. The book provides very useful practical guidance that can be used by technical and management practitioners for the specific domain described, and by example for others for different domains." --John P. Hopkinson, Security Strategist, Kwictech

      Innehållsförteckning

      • Contents1. Why Hackers know more about our systems1.1 Operating in cyberspace involves risks1.2 Why Hackers are repeatadly successful1.2.1 What are the challenges in defending cybersystems?1.2.1.1 Difficulties in understanding and assessing risks1.2.1.2 Understanding Development Trends1.2.1.3 Comprehending Systems’ Complexity1.2.1.4 Understanding Assessment Practices and their Limitations1.2.1.5 Vulnerability Scanning Technologies and their Issues1.3 Where do We Go from Here1.3.1 Systematic and repeatable defense at affordable cost1.3.2 The OMG Software Assurance Ecosystem1.3.3 Linguistic Modeling to manage the common vocabulary1.4 Who should read this book2 Chapter: Confidence as a Product2.1 Are you confident that there is no black cat in the dark room?2.2 The Nature of Assurance2.2.1 Engineering, Risk and Assurance2.2.2 Assurance Case (AC)2.2.2.1 Contents of an Assurance Case2.2.2.2 Structure of the Assurance Argument2.3 Overview of the Assurance Process2.3.1 Producing Confidence2.3.1.1 Economics of Confidence3 Chapter: How to Build Confidence 3.1 Assurance in the System Lifecycle3.2 Activities of System Assurance Process3.2.1 Project Definition3.2.2 Project Preparation3.2.3 Assurance argument development3.2.4 Architecture Security Analysis3.2.4.1 Discover System Facts3.2.4.2 Threat identification3.2.4.3 Safeguard Identification3.2.4.4 Vulnerability detection3.2.4.5 Security Posture Analysis3.2.5 Evidence analysis3.2.6 Assurance Case Delivery4 Chapter: Knowledge of System as of Element in Cybersecurity argument 4.1 What is system4.2 Boundaries of the system4.3 Resolution of the system description4.4 Conceptual commitment for system descriptions4.5 System architecture4.6 Example of an architecture framework4.7 Elements of System4.8 System Knowledge Involves Multiple Viewpoints4.9 Concept of operations (CONOP)4.10 Network Configuration4.11 System life cycle and assurance4.11.1 System life cycle stages4.11.2 Enabling Systems4.11.3 Supply Chain4.11.4 System life cycle processes4.11.5 The implications to the common vocabulary and the integrated system model5 Chapter: Knowledge of Risk as an Element of Cybersecurity argument 5.1 Introduction5.2 Basic cybersecurity elements5.3 Common vocabulary for risk analysis5.3.1 Defining diScernable vocabulary for Assets5.3.2 Threats and hazards5.3.3 Defining dicernable vocabulary for Injury and Impact5.3.4 Defining dicernable vocabulary for threats5.3.5 Threat scenarios and attacks5.3.6 Defining dicernable vocabulary for vulnerabilities5.3.7 Defining dicernable vocabulary for safeguards5.3.8 Risk5.4 Systematic Threat Identification5.5 Assurance Strategies5.5.1 Injury Argument5.5.2 Entry point argument5.5.3 Threat argument5.5.4 Vulnerability argument5.5.5 Security requirement argument5.5.6 Assurance of the threat identification6 Chapter: Knowledge of Vulnerabilities as an Element of Cybersecurity Argument 6.1 Vulnerability as part of system knowledege6.1.1 What is Vulnerability6.1.2 Vulnerability as Unit of Knowledge: The History of Vulnerability6.1.3 Vulnerabilities and the Phases of the System Life Cycle6.1.4 Enumeration of Vulnerabilities as a Knowledge Product6.1.5 Vulnerability Databases6.1.5.1 US-CERT6.1.5.2 Open Source Vulnerability Database (OSVDB)6.1.6 Vulnerability Life Cycle6.2 NIST Security Content Automation Protocol (SCAP) Ecosystem6.2.1 Overview of SCAP Ecosystem6.2.2 Information Exchanges under SCAP7 Chapter: Vulnerability Patterns as a New Assurance Content 7.1 Beyond Current SCAP Ecosystem7.2 Vulnerability Patterns7.3 Software Fault Patterns7.3.1 Safeguard category of clusters and corresponding Software fault Patterns (SFPs)7.3.1.1 Authentication7.3.1.2 Access Control7.3.1.3 Privilege7.3.2 Direct Impact category of clusters and corresponding Software fault Patterns (SFPs)7.3.2.1 Information Leak7.3.2.2 Memory Management7.3.2.3 Memory Access7.3.2.4 Path Resolution7.3.2.5 Tainted Input8 Chapter: OMG Software Assurance Ecosystem 8.1 Introduction8.2 OMG Assurance Ecosystem: towards collaborative cybersecurity9 Chapter: Common Fact Model for Assurance Content9.1 Assurance Content9.2 The Objectives9.3 Design criteria for information exchange protocols9.4 Tradeoffs9.5 Information Exchange Protocols9.6 The Nuts and Bolts of Fact Models9.6.1 Objects9.6.2 Noun Concepts9.6.3 Facts about existence of objects9.6.4 Individual concepts9.6.5 Relations between concepts9.6.6 Verb concepts9.6.7 Characteristics9.6.8 Situational concepts9.6.9 Viewpoints and views9.6.10 Information exchanges and assurance9.6.11 Fact-oriented Integration9.6.12 Automatic derivation of facts9.7 The representation of facts9.7.1 Representing facts in XML9.7.2 Representing facts and schemes in Prolog9.8 The common schema9.9 System assurance facts10 Chapter: Linguistic Models10.1 Fact Models and Linguistic Models10.2 Background10.3 Overview of SBVR10.4 How to use SBVR10.4.1 Simple vocabulary10.4.2 Vocabulary Entries10.4.3 Statements10.4.4 Statements as formal definitions of new concepts10.4.4.1 Definition of a Noun Concept10.4.4.2 Definition of a Verb Concept10.4.4.3 The General Concept caption10.5 SBVR Vocabulary for describing Elementary Meanings10.6 SBVR Vocabulary for describing Representations10.7 SBVR Vocabulary for describing Extensions10.8 Reference schemes10.9 SBVR Semantic Formulations10.9.1 Defining new terms and facts types using SBVR11 Chapter: Standard Protocol for Exchanging System Facts 11.1 Background11.2 Organization of the KDM vocabulary11.2.1 Infrastructure Layer11.2.2 Program Elements Layer11.2.3 Resource Layer11.2.4 Abstractions Layer11.3 The process of discovering system facts11.4 Discovering the baseline system facts11.4.1 Inventory views11.4.1.1 Inventory Viewpoint vocabulary in SBVR11.4.2 Build Views11.4.3 Data views11.4.4 UI views11.4.5 Code views11.4.5.1 Code views: Elements of Structure11.4.5.2 Code views: Elements of Behavior11.4.5.3 Micro KDM11.4.6 Platform views11.4.7 Event views11.5 Performing architecture analysis11.5.1 Structure Views11.5.2 Conceptual Views11.5.2.1 Linguistic Viewpoint11.5.2.2 Behavior Viewpoint12 Chapter: Case Study 12.1 Introduction12.2 Background12.3 Concepts of operations12.3.1 Executive summary12.3.2 Purpose12.3.3 Locations12.3.4 Operational Authority12.3.5 System Architecture12.3.5.1 Clicks2Bricks Web server12.3.5.2 Database server12.3.5.3 SMTP server12.3.6 System Assumptions12.3.7 External dependencies12.3.8 Implementation Assumptions12.3.9 Interfaces with Other Systems12.3.10 Security assumptions12.3.11 External Security Notes12.3.12 Internal Security notes12.4 Business vocabulary and security policy for Clicks2Bricks in SBVR12.5 Building the integrated system model12.5.1 Building the baseline system model12.5.2 Enhancing the baseline model with the system architecture facts12.6 Mapping cybersecurity facts to system facts12.7 Assurance case
      Hoppa över listan

      Mer från samma författare

      Djenana Campara, Nikolai Mansourov - System Assurance, E-bok

      System Assurance

      Djenana Campara, Nikolai Mansourov

      E-bok
      2010

      618 kr

      Hoppa över listan

      Mer från samma serie

      Tim Weilkiens - Systems Engineering with SysML/UML, Häftad

      Systems Engineering with SysML/UML

      Tim Weilkiens

      Häftad, 2008

      583 kr

      Michael Guttman, John Parodi - Real-Life MDA, Häftad

      Real-Life MDA

      Michael Guttman, John Parodi

      Häftad, 2007

      521 kr

      Tim Weilkiens, Bernd Oestereich - UML 2 Certification Guide, Häftad

      UML 2 Certification Guide

      Tim Weilkiens, Bernd Oestereich

      Häftad, 2006

      597 kr

      David Loshin - Master Data Management, Häftad

      Master Data Management

      David Loshin

      Häftad, 2008

      585 kr

      Fred A. Cummins - Building the Agile Enterprise, Häftad

      Building the Agile Enterprise

      Fred A. Cummins

      Häftad, 2008

      546 kr

      Jack E. Olson - Database Archiving, Häftad

      Database Archiving

      Jack E. Olson

      Häftad, 2008

      646 kr

      James Bean - SOA and Web Services Interface Design, Häftad

      SOA and Web Services Interface Design

      James Bean

      Häftad, 2009

      546 kr

      William M. Ulrich, Philip Newcomb - Information Systems Transformation, Häftad

      Information Systems Transformation

      William M. Ulrich, Philip Newcomb

      Häftad, 2010

      662 kr

      Bran Selic, Sebastien Gerard - Modeling and Analysis of Real-Time and Embedded Systems with UML and MARTE, Häftad

      Modeling and Analysis of Real-Time and Embedded Systems with UML and MARTE

      Bran Selic, Sebastien Gerard

      Häftad, 2013

      572 kr

      Philippe Desfray, Gilbert Raymond - Modeling Enterprise Architecture with TOGAF, Häftad

      Modeling Enterprise Architecture with TOGAF

      Philippe Desfray, Gilbert Raymond

      Häftad, 2014

      482 kr

      Hoppa över listan

      Du kanske också är intresserad av

      Djenana Campara, Nikolai Mansourov - System Assurance, E-bok

      System Assurance

      Djenana Campara, Nikolai Mansourov

      E-bok
      2010

      618 kr

      Måns Petter Zelmerlöw - När allt faller, Inbunden
      • -12%

      När allt faller

      Måns Petter Zelmerlöw

      Inbunden, 2026

      229 kr259 kr

      Marco Brambilla, Piero Fraternali - Interaction Flow Modeling Language, Häftad

      Interaction Flow Modeling Language

      Marco Brambilla, Piero Fraternali

      Häftad, 2014

      540 kr

      Carola Häggkvist - SIGNERAD - Jag är Carola, Inbunden
      • Signerad!

      SIGNERAD - Jag är Carola

      Carola Häggkvist

      Inbunden, 2026

      269 kr

      Fred A. Cummins - Building the Agile Enterprise, Häftad

      Building the Agile Enterprise

      Fred A. Cummins

      Häftad, 2016

      572 kr

      Tim Weilkiens, Bernd Oestereich - UML 2 Certification Guide, Häftad

      UML 2 Certification Guide

      Tim Weilkiens, Bernd Oestereich

      Häftad, 2006

      597 kr

      Philippe Desfray, Gilbert Raymond - Modeling Enterprise Architecture with TOGAF, Häftad

      Modeling Enterprise Architecture with TOGAF

      Philippe Desfray, Gilbert Raymond

      Häftad, 2014

      482 kr

      Michael Guttman, John Parodi - Real-Life MDA, Häftad

      Real-Life MDA

      Michael Guttman, John Parodi

      Häftad, 2007

      521 kr

      William M. Ulrich, Philip Newcomb - Information Systems Transformation, Häftad

      Information Systems Transformation

      William M. Ulrich, Philip Newcomb

      Häftad, 2010

      662 kr

      James Bean - SOA and Web Services Interface Design, Häftad

      SOA and Web Services Interface Design

      James Bean

      Häftad, 2009

      546 kr