• Fri frakt över 249 kr
  • •
  • Snabba leveranser
  • •
  • Billiga böcker
Kundservice

Du är på sajten för privatpersoner.

Företag, bibliotek eller offentlig verksamhet?

Du handlar på classic.bokus.com, där alla dina funktioner finns intakta.
Till classic.bokus.com
Bokus logotyp. Gå till startsidan.
  • Erbjudanden
  • Student
  • Topplistor
  • Barn & ungdom
  • Bokus Play
  • E-böcker
  • Ljudböcker
  • Pocketböcker
  • Spel & pussel

Upp till 25% på utvalda nyheter →

Sidfot

Mina sidor

    Hjälp

    • Kundservice
    • Vanliga frågor och svar
    • Frakt och leverans
    • Retur vid ångerrätt
    • Reklamera vara
    • Betalning
    • Köpvillkor
    • Allmänna villkor
    • Information om webbplatsens tillgänglighet

    Om Bokus

    • Om oss
    • Pressrum
    • För studenter
    • För företag
    • För bibliotek och offentlig verksamhet
    • För leverantörer
    • Hållbarhet

    Populärt

    • Aktuella erbjudanden
    • Presentkort
    • Studentlitteratur
    • Nya böcker
    • Topplistor
    • Signerade böcker
    • Engelska böcker

    Inspiration

    • Boktips
    • BookTok
    • Populära bokserier
    • Barnbokskaraktärer
    • Populära författare
    Logotyp för Bokus
    Följ oss på Facebook (extern länk)Följ oss på Instagram (extern länk)Följ oss på YouTube (extern länk)Följ oss på TikTok (extern länk)
    bokus @ CookiesAnpassa cookiesIntegritetspolicyKöpvillkor
    Till Citymail hemsida (extern länk)Till Budbee hemsida (extern länk)Till Postnord hemsida (extern länk)Till Schenker hemsida (extern länk)Till Early Bird hemsida (extern länk)Till Walleys hemsida (extern länk)
    1. Data och IT
    2. Nätverk och kommunikation

    Computer Security

    Art and Science

    AvMatt Bishop

    Inbunden, Engelska, 2018

    812 kr

    Beställningsvara. Skickas inom 7-10 vardagar. Fri frakt över 249 kr.

    Beskrivning

    The Comprehensive Guide to Computer Security, Extensively Revised with Newer Technologies, Methods, Ideas, and Examples

    In this updated guide, University of California at Davis Computer Security Laboratory co-director Matt Bishop offers clear, rigorous, and thorough coverage of modern computer security. Reflecting dramatic growth in the quantity, complexity, and consequences of security incidents, Computer Security, Second Edition, links core principles with technologies, methodologies, and ideas that have emerged since the first edition’s publication.

    Writing for advanced undergraduates, graduate students, and IT professionals, Bishop covers foundational issues, policies, cryptography, systems design, assurance, and much more. He thoroughly addresses malware, vulnerability analysis, auditing, intrusion detection, and best-practice responses to attacks. In addition to new examples throughout, Bishop presents entirely new chapters on availability policy models and attack analysis.

    • Understand computer security goals, problems, and challenges, and the deep links between theory and practice
    • Learn how computer scientists seek to prove whether systems are secure
    • Define security policies for confidentiality, integrity, availability, and more
    • Analyze policies to reflect core questions of trust, and use them to constrain operations and change
    • Implement cryptography as one component of a wider computer and network security strategy
    • Use system-oriented techniques to establish effective security mechanisms, defining who can act and what they can do
    • Set appropriate security goals for a system or product, and ascertain how well it meets them
    • Recognize program flaws and malicious logic, and detect attackers seeking to exploit them

    This is both a comprehensive text, explaining the most fundamental and pervasive aspects of the field, and a detailed reference. It will help you align security concepts with realistic policies, successfully implement your policies, and thoughtfully manage the trade-offs that inevitably arise.

    Register your book for convenient access to downloads, updates, and/or corrections as they become available. See inside book for details.

    Produktinformation

    • Utgivningsdatum:2018-10-19
    • Mått:195 x 234 x 50 mm
    • Vikt:160 g
    • Format:Inbunden
    • Språk:Engelska
    • Antal sidor:1 440
    • Upplaga:2
    • Förlag:Pearson Education
    • ISBN:9780321712332

    Utforska kategorier

    • Nätverk och kommunikation inom Data och IT
    • IT-säkerhet inom Data och IT

    Mer om författaren

    Matt Bishop is a professor in the Department of Computer Science at the University of California at Davis. His main research interest is the analysis of vulnerabilities in computer systems, including modeling them, building tools to detect vulnerabilities, and ameliorating or eliminating them. He works in the areas of network security, including the study of denial of service attacks and defenses, policy modeling, software assurance testing, resilience, and formal modeling of access control. He was co-chair of the Joint Task Force that developed the Cybersecurity Curricula 2017: Curriculum Guidelines for Post-Secondary Degree Programs in Cybersecurity, released in December 2017. He earned his Ph.D. in computer science from Purdue University in 1984.

    Innehållsförteckning

    • Preface xxixAcknowledgments xlvAbout the Author xlixPart I: Introduction 1Chapter 1: An Overview of Computer Security 31.1 The Basic Components 31.2 Threats 61.3 Policy and Mechanism 91.4 Assumptions and Trust 111.5 Assurance 121.6 Operational Issues 161.7 Human Issues 201.8 Tying It All Together 221.9 Summary 241.10 Research Issues 241.11 Further Reading 251.12 Exercises 25Part II: Foundations 29Chapter 2: Access Control Matrix 312.1 Protection State 312.2 Access Control Matrix Model 322.3 Protection State Transitions 372.4 Copying, Owning, and the Attenuation of Privilege 422.5 Summary 442.6 Research Issues 442.7 Further Reading 442.8 Exercises 45Chapter 3: Foundational Results 493.1 The General Question 493.2 Basic Results 513.3 The Take-Grant Protection Model 563.4 Closing the Gap: The Schematic Protection Model 683.5 Expressive Power and the Models 813.6 Comparing Security Properties of Models 943.7 Summary 1013.8 Research Issues 1023.9 Further Reading 1023.10 Exercises 103Part III: Policy 107Chapter 4: Security Policies 1094.1 The Nature of Security Policies 1094.2 Types of Security Policies 1134.3 The Role of Trust 1154.4 Types of Access Control 1174.5 Policy Languages 1184.6 Example: Academic Computer Security Policy 1264.7 Security and Precision 1314.8 Summary 1364.9 Research Issues 1364.10 Further Reading 1374.11 Exercises 138Chapter 5: Confidentiality Policies 1415.1 Goals of Confidentiality Policies 1415.2 The Bell-LaPadula Model 1425.3 Tranquility 1615.4 The Controversy over the Bell-LaPadula Model 1645.5 Summary 1695.6 Research Issues 1695.7 Further Reading 1705.8 Exercises 171Chapter 6: Integrity Policies 1736.1 Goals 1736.2 The Biba Model 1756.3 Lipner’s Integrity Matrix Model 1786.4 Clark-Wilson Integrity Model 1836.5 Trust Models 1896.6 Summary 1966.7 Research Issues 1966.8 Further Reading 1976.9 Exercises 198Chapter 7: Availability Policies 2017.1 Goals of Availability Policies 2017.2 Deadlock 2027.3 Denial of Service Models 2037.4 Example: Availability and Network Flooding 2157.5 Summary 2227.6 Research Issues 2227.7 Further Reading 2237.8 Exercises 224Chapter 8: Hybrid Policies 2278.1 Chinese Wall Model 2278.2 Clinical Information Systems Security Policy 2368.3 Originator Controlled Access Control 2398.4 Role-Based Access Control 2448.5 Break-the-Glass Policies 2498.6 Summary 2508.7 Research Issues 2508.8 Further Reading 2518.9 Exercises 252Chapter 9: Noninterference and Policy Composition 2559.1 The Problem 2559.2 Deterministic Noninterference 2599.3 Nondeducibility 2719.4 Generalized Noninterference 2749.5 Restrictiveness 2779.6 Side Channels and Deducibility 2809.7 Summary 2829.8 Research Issues 2839.9 Further Reading 2839.10 Exercises 285Part IV: Implementation I: Cryptography 287Chapter 10: Basic Cryptography 28910.1 Cryptography 28910.2 Symmetric Cryptosystems 29110.3 Public Key Cryptography 30610.4 Cryptographic Checksums 31510.5 Digital Signatures 31810.6 Summary 32310.7 Research Issues 32410.8 Further Reading 32510.9 Exercises 326Chapter 11: Key Management 33111.1 Session and Interchange Keys 33211.2 Key Exchange 33211.3 Key Generation 34111.4 Cryptographic Key Infrastructures 34311.5 Storing and Revoking Keys 35311.6 Summary 35911.7 Research Issues 36011.8 Further Reading 36111.9 Exercises 362Chapter 12: Cipher Techniques 36712.1 Problems 36712.2 Stream and Block Ciphers 37012.3 Authenticated Encryption 37712.4 Networks and Cryptography 38112.5 Example Protocols 38412.6 Summary 41012.7 Research Issues 41112.8 Further Reading 41112.9 Exercises 413Chapter 13: Authentication 41513.1 Authentication Basics 41513.2 Passwords 41613.3 Password Selection 41813.4 Attacking Passwords 42613.5 Password Aging 43413.6 Challenge-Response 43813.7 Biometrics 44113.8 Location 44513.9 Multifactor Authentication 44613.10 Summary 44813.11 Research Issues 44913.12 Further Reading 45013.13 Exercises 451Part V: Implementation II: Systems 453Chapter 14: Design Principles 45514.1 Underlying Ideas 45514.2 Principles of Secure Design 45714.3 Summary 46614.4 Research Issues 46614.5 Further Reading 46714.6 Exercises 468Chapter 15: Representing Identity 47115.1 What Is Identity? 47115.2 Files and Objects 47215.3 Users 47315.4 Groups and Roles 47515.5 Naming and Certificates 47615.6 Identity on the Web 48415.7 Anonymity on the Web 49015.8 Summary 50115.9 Research Issues 50215.10 Further Reading 50315.11 Exercises 504Chapter 16: Access Control Mechanisms 50716.1 Access Control Lists 50716.2 Capabilities 51816.3 Locks and Keys 52616.4 Ring-Based Access Control 53116.5 Propagated Access Control Lists 53316.6 Summary 53516.7 Research Issues 53516.8 Further Reading 53616.9 Exercises 536Chapter 17: Information Flow 53917.1 Basics and Background 53917.2 Nonlattice Information Flow Policies 54217.3 Static Mechanisms 54817.4 Dynamic Mechanisms 56217.5 Integrity Mechanisms 56617.6 Example Information Flow Controls 56717.7 Summary 57417.8 Research Issues 57417.9 Further Reading 57517.10 Exercises 576Chapter 18: Confinement Problem 57918.1 The Confinement Problem 57918.2 Isolation 58218.3 Covert Channels 59418.4 Summary 61918.5 Research Issues 62018.6 Further Reading 62018.7 Exercises 622Part VI: Assurance 625Contributed by Elisabeth Sullivan and Michelle RuppelChapter 19: Introduction to Assurance 62719.1 Assurance and Trust 62719.2 Building Secure and Trusted Systems 63419.3 Summary 64519.4 Research Issues 64519.5 Further Reading 64619.6 Exercises 647Chapter 20: Building Systems with Assurance 64920.1 Assurance in Requirements Definition and Analysis 64920.2 Assurance during System and Software Design 66220.3 Assurance in Implementation and Integration 68520.4 Assurance during Operation and Maintenance 69520.5 Summary 69620.6 Research Issues 69620.7 Further Reading 69720.8 Exercises 698Chapter 21: Formal Methods 69921.1 Formal Verification Techniques 69921.2 Formal Specification 70221.3 Early Formal Verification Techniques 70521.4 Current Verification Systems 71321.5 Functional Programming Languages 72121.6 Formally Verified Products 72221.7 Summary 72321.8 Research Issues 72421.9 Further Reading 72521.10 Exercises 725Chapter 22: Evaluating Systems 72722.1 Goals of Formal Evaluation 72722.2 TCSEC: 1983-1999 73022.3 International Efforts and the ITSEC: 1991-2001 73722.4 Commercial International Security Requirements: 1991 74222.5 Other Commercial Efforts: Early 1990s 74422.6 The Federal Criteria: 1992 74422.7 FIPS 140: 1994-Present 74622.8 The Common Criteria: 1998-Present 74922.9 SSE-CMM: 1997-Present 76522.10 Summary 76822.11 Research Issues 76922.12 Further Reading 76922.13 Exercises 770Part VII: Special Topics 773Chapter 23: Malware 77523.1 Introduction 77523.2 Trojan Horses 77623.3 Computer Viruses 78023.4 Computer Worms 79023.5 Bots and Botnets 79323.6 Other Malware 79623.7 Combinations 80323.8 Theory of Computer Viruses 80323.9 Defenses 80823.10 Summary 82023.11 Research Issues 82023.12 Further Reading 82123.13 Exercises 822Chapter 24: Vulnerability Analysis 82524.1 Introduction 82524.2 Penetration Studies 82724.3 Vulnerability Classification 84524.4 Frameworks 84924.5 Standards 86424.6 Gupta and Gligor’s Theory of Penetration Analysis 86824.7 Summary 87324.8 Research Issues 87424.9 Further Reading 87524.10 Exercises 876Chapter 25: Auditing 87925.1 Definition 87925.2 Anatomy of an Auditing System 88025.3 Designing an Auditing System 88425.4 A Posteriori Design 89325.5 Auditing Mechanisms 89725.6 Examples: Auditing File Systems 90025.7 Summary 91025.8 Research Issues 91125.9 Further Reading 91225.10 Exercises 913Chapter 26: Intrusion Detection 91726.1 Principles 91726.2 Basic Intrusion Detection 91826.3 Models 92026.4 Architecture 94226.5 Organization of Intrusion Detection Systems 94826.6 Summary 95426.7 Research Issues 95426.8 Further Reading 95526.9 Exercises 956Chapter 27: Attacks and Responses 95927.1 Attacks 95927.2 Representing Attacks 96027.3 Intrusion Response 97127.4 Digital Forensics 98727.5 Summary 99627.6 Research Issues 99727.7 Further Reading 99827.8 Exercises 999Part VIII: Practicum 1003Chapter 28: Network Security 100528.1 Introduction 100528.2 Policy Development 100628.3 Network Organization 101128.4 Availability 102628.5 Anticipating Attacks 102728.6 Summary 102828.7 Research Issues 102828.8 Further Reading 102928.9 Exercises 1030Chapter 29: System Security 103529.1 Introduction 103529.2 Policy 103629.3 Networks 104229.4 Users 104829.5 Authentication 105329.6 Processes 105529.7 Files 106129.8 Retrospective 106629.9 Summary 106829.10 Research Issues 106829.11 Further Reading 106929.12 Exercises 1070Chapter 30: User Security 107330.1 Policy 107330.2 Access 107430.3 Files and Devices 108030.4 Processes 108730.5 Electronic Communications 109230.6 Summary 109430.7 Research Issues 109530.8 Further Reading 109530.9 Exercises 1096Chapter 31: Program Security 109931.1 Problem 109931.2 Requirements and Policy 110031.3 Design 110431.4 Refinement and Implementation 111131.5 Common Security-Related Programming Problems 111731.6 Testing, Maintenance, and Operation 114131.7 Distribution 114631.8 Summary 114731.9 Research Issues 114731.10 Further Reading 114831.11 Exercises 1148Part IX: Appendices 1151Appendix A: Lattices 1153A.1 Basics 1153A.2 Lattices 1154A.3 Exercises 1155Appendix B: The Extended Euclidean Algorithm 1157B.1 The Euclidean Algorithm 1157B.2 The Extended Euclidean Algorithm 1158B.3 Solving ax mod n = 1 1160B.4 Solving ax mod n = b 1161B.5 Exercises 1161Appendix C: Entropy and Uncertainty 1163C.1 Conditional and Joint Probability 1163C.2 Entropy and Uncertainty 1165C.3 Joint and Conditional Entropy 1166C.4 Exercises 1169Appendix D: Virtual Machines 1171D.1 Virtual Machine Structure 1171D.2 Virtual Machine Monitor 1171D.3 Exercises 1176Appendix E: Symbolic Logic 1179E.1 Propositional Logic 1179E.2 Predicate Logic 1184E.3 Temporal Logic Systems 1186E.4 Exercises 1188Appendix F: The Encryption Standards 1191F.1 Data Encryption Standard 1191F.2 Advanced Encryption Standard 1196F.3 Exercises 1205Appendix G: Example Academic Security Policy 1207G.1 Acceptable Use Policy 1207G.2 University of California Electronic Communications Policy 1212G.3 User Advisories 1234G.4 Electronic Communications—Allowable Use 1241Appendix H: Programming Rules 1247H.1 Implementation Rules 1247H.2 Management Rules 1249References 1251Index 1341