• Fri frakt över 249 kr
  • •
  • Snabba leveranser
  • •
  • Billiga böcker
Kundservice

Du är på sajten för privatpersoner.

Företag, bibliotek eller offentlig verksamhet?

Du handlar på classic.bokus.com, där alla dina funktioner finns intakta.
Till classic.bokus.com
Bokus logotyp. Gå till startsidan.
  • Erbjudanden
  • Student
  • Topplistor
  • Barn & ungdom
  • Bokus Play
  • E-böcker
  • Ljudböcker
  • Pocketböcker
  • Spel & pussel

Upp till 25% på utvalda nyheter →

Sidfot

Mina sidor

    Hjälp

    • Kundservice
    • Vanliga frågor och svar
    • Frakt och leverans
    • Retur vid ångerrätt
    • Reklamera vara
    • Betalning
    • Köpvillkor
    • Allmänna villkor
    • Information om webbplatsens tillgänglighet

    Om Bokus

    • Om oss
    • Pressrum
    • För studenter
    • För företag
    • För bibliotek och offentlig verksamhet
    • För leverantörer
    • Hållbarhet

    Populärt

    • Aktuella erbjudanden
    • Presentkort
    • Studentlitteratur
    • Nya böcker
    • Topplistor
    • Signerade böcker
    • Engelska böcker

    Inspiration

    • Boktips
    • BookTok
    • Populära bokserier
    • Barnbokskaraktärer
    • Populära författare
    Logotyp för Bokus
    Följ oss på Facebook (extern länk)Följ oss på Instagram (extern länk)Följ oss på YouTube (extern länk)Följ oss på TikTok (extern länk)
    bokus @ CookiesAnpassa cookiesIntegritetspolicyKöpvillkor
    Till Citymail hemsida (extern länk)Till Budbee hemsida (extern länk)Till Postnord hemsida (extern länk)Till Schenker hemsida (extern länk)Till Early Bird hemsida (extern länk)Till Walleys hemsida (extern länk)
    1. Naturvetenskap och teknik
    2. Teknik och industri
    3. Elektronik och kommunikationer

    Blockchain Application Security

    How to Design Secure and Attack Resilient Blockchain Applications

    AvMarco Morana,Harpreet Singh

    Inbunden, Engelska, 2025

    1 307 kr

    Beställningsvara. Skickas inom 5-8 vardagar. Fri frakt över 249 kr.

    Beskrivning

    Learn to secure, design, implement, and test tomorrow's blockchain applications.Blockchain Application Security guides readers through the architecture and components of blockchain, including protocols such as Bitcoin and beyond, by offering a technical yet accessible introduction. This resource is ideal for application architects, software developers, security auditors, and vulnerability testers working on enterprise blockchain solutions. It bridges the gap between theory and implementation, providing actionable guidance on protecting decentralized systems while capitalizing on their innovative benefits.Blockchain Application Security covers the essentials, from the fundamentals of distributed ledgers, consensus algorithms, digital wallets, smart contracts, privacy controls, and DIDs, to designing secure dApp architectures with component-level threat analysis and resilient APIs, token transactions, digital exchanges, and identity models. It features a complete lifecycle example for securing a DeFi lending and borrowing platform, along with practical walkthroughs for smart contract development, AWS-integrated blockchain systems, frontend/API integration, and code auditing."An accessible, comprehensive blockchain overview that emphasizes its value across industrial and government sectors with a holistic security focus."—David W. Kravitz, Technical Advisor, Spring Labs"A cutting-edge method for securing blockchain applications, pushing the boundaries of current practice."—David Cervigni, Senior Security Research Engineer at R3"Bridging theory and practice with realistic examples, this guide empowers architects and developers to build attack-resistant applications."—Steven Wierckx, Product Security Team Lead & Threatmodel Trainer at Toreon"A valuable resource for blockchain specialists, featuring hands-on examples of deploying dApps on AWS and securing infrastructure."—Ihor Sasovets, Lead Security Engineer, Penetration Tester at TechMagic"A practical roadmap for navigating blockchain security that we recommend to clients and incorporate into our training.—Vijay Dhanasekaran, Founder & Chief Blockchain Officer, Consultant at Blocknetics"An indispensable resource for dApp developers, guiding readers from fundamentals to advanced implementation with in-depth vulnerability analysis."—Mohd Mehdi, Head of DevOps, DevSecOps and Infrastructure at InfStones

    Produktinformation

    • Utgivningsdatum:2025-10-23
    • Mått:156 x 230 x 41 mm
    • Vikt:1 134 g
    • Format:Inbunden
    • Språk:Engelska
    • Antal sidor:640
    • Förlag:John Wiley & Sons Inc
    • ISBN:9781119551034

    Utforska kategorier

    • Elektronik och kommunikationer inom Naturvetenskap och teknik
    • Nätverk och kommunikation inom Data och IT
    • Databaser inom Data och IT

    Mer om författaren

    Marco Morana is the Field CISO at Avocado Systems Inc., where he leads the deployment of runtime threat modeling and product security solutions for enterprise clients where he leads the deployment of runtime threat modeling and product security solutions for enterprise clients. Previously, he held senior security leadership roles at JPMorgan Chase and Citibank, where he directed global architecture programs and led S-SDLC adoption across cloud and application platforms. At Citibank, Marco conducted architecture risk assessments for blockchain pilots including the first digital asset trade with Nasdaq via Chain.com and authored the bank's first security standards for blockchain. He is the coauthor of the PASTA threat modeling methodology and OWASP project leader focused on secure-by-design for blockchain and AI systems.Harpreet Singh is a seasoned engineering leader with 19 years of experience driving innovation in AI/LLM, cybersecurity, and large-scale distributed systems. He is known for a strategic approach to architecture, a focus on customer trust and safety, and a collaborative leadership style. He has successfully launched new products, integrated emerging technologies, and optimized security practices across global organizations.Francesco Piccoli is the cofounder and CEO of Almanax, a cybersecurity firm specializing in AI-powered solutions. He was previously the Head of Product at AnChain.AI, where he built security and compliance tools for the US SEC, IRS, and Salesforce. His team was part of $100M+ crypto hacks investigations. Prior to AnChain.AI, he led research initiatives in anomaly detection and autonomous driving. Francesco holds a Master of Engineering from UC Berkeley and lives in New York.

    Innehållsförteckning

    • Foreword xiiiPreface xivAcknowledgments xviiiIntroduction xx1 The Blockchain Technology Primer 11.1 Introduction 11.2 Brief History of the Blockchain and Its Evolution 21.3 DLT and the Blockchain 21.4 Blockchain Networks 71.4.1 Nodes 111.4.2 Scalability Components 131.4.3 Interoperability Components 171.4.4 Platforms 191.4.5 dApps 221.4.6 Practical Examples 231.5 The Blockchain Data Structure 261.5.1 Hash Functions 281.5.2 Digital Signatures 311.5.3 Block Structure 361.5.4 Merkle Trees 401.5.5 Fundamental Blockchain Elements 421.5.6 Inherent Security Risks of Blockchain Technology 461.6 Consensus Algorithms 551.6.1 Different Types of Consensus Algorithms 551.6.2 Deterministic Versus Nondeterministic Consensus Algorithms 611.7 Cryptocurrencies 641.7.1 Cryptocurrencies Use Cases 681.7.2 Use of Cryptocurrencies and Security Risks 691.8 Digital Wallets 711.8.1 Introduction 711.8.2 Security Features of Digital Wallets 761.9 Digital Transactions 791.9.1 Transaction Automation with Smart Contracts 851.9.2 Token Transactions 881.10 Privacy Controls 901.10.1 Anonymity Versus Pseudonymity of Blockchain Transactions 931.10.2 Techniques for Enhancing Transaction Privacy 941.11 Identity Controls 971.11.1 Identity Verification Methods 981.11.2 Privacy-Preserving Identities 1011.11.3 Identity and Access Management 1031.11.4 Decentralized Identities (DIDs) 1051.12 Legal and Regulatory Considerations 1061.13 Conclusions 1161.14 Future Directions and Trends in Blockchain Technology 1172 Designing Secure Decentralized Applications 1212.1 Introduction 1212.2 Decentralized Applications 1272.2.1 dApp Architectures 1322.2.2 Comparison of dApps with Traditional Centralized Applications 1392.2.3 Analysis of Use Cases for Blockchain and dApps 1412.3 Security Requirements 1452.3.1 Elicitation of Security Requirements 1452.3.2 Example of dApps Security Requirements 1492.4 Securing dApps 1522.4.1 Principles of Secure Blockchain Platform Design 1532.4.1.1 Overview of Security Architecture Principles 1542.4.1.2 Security Architecture Principles for dApps Design 1542.4.2 Securing dApps by Design 1622.4.2.1 Identifying dApps Security Design Flaws and Vulnerabilities 1632.4.2.2 Securing dApps Components by Design and Implementation 1712.4.3 Blockchain APIs 1852.4.3.1 Securing Blockchain APIs 1862.4.3.2 Blockchain API Vulnerabilities 1902.4.3.3 Security Review of Blockchain API 1932.4.4 Securing dApps Confidential Data and Transactions 1952.4.4.1 Security Requirements for the Protection of Confidential Data 1992.4.4.2 Vulnerabilities Exposing Confidential and Transactions Data 2022.4.4.3 Security Reviews to Identify Design Flaws and Vulnerabilities 2042.4.5 Consensus Algorithms 2062.4.5.1 Identifying Consensus Algorithm Vulnerabilities 2072.4.5.2 Secure Consensus Algorithm Best Practices 2112.4.6 Protecting Secrets 2132.4.6.1 Practical Examples of Security by Design Protection of Secrets and Keys in dApps 2142.4.6.2 Identification of Potential Vulnerabilities Related to Secret and Key Management with dApps 2172.4.7 Securing Token-Based Transactions 2182.4.7.1 Explanation of Token-Based Transactions 2192.4.7.2 Secure Token Standards 2212.4.7.3 Security Considerations for Securing dApps with Token-Based Use Cases 2242.4.8 Securing Cryptocurrency DEX Transactions 2272.4.8.1 Securing dApp Integration with Digital Exchanges 2282.4.8.2 Mitigating the Risks of DEX Use Cases 2332.4.9 Securing Digital Identities (DIDs) 2342.4.9.1 Explanation of Digital Identities 2422.4.9.2 Security Considerations for Digital Identities 2452.4.10 Securing Smart Contracts 2482.4.10.1 Overview of Smart Contracts and Security Considerations 2482.4.10.2 Common Smart Contract Vulnerabilities and Associated Risks 2512.4.10.3 Best Practices for Smart Contracts Security 2552.5 Conclusions for This Chapter 2662.5.1 Future Trends in Blockchain Technology and Security 2673 Mitigating Blockchain Vulnerabilities 2693.1 Introduction 2693.1.1 Focused dApp Application Security 2703.1.2 dApp Vulnerabilities Risks 2723.1.3 Security Incidents: Lessons Learned for Future Resilience 2733.1.3.1 Smart Contract Exploits: Confronting a Critical Threat 2743.1.3.2 Digital Wallet Design Flaws: Mitigating Emerging Threats 2783.1.3.3 Proactive Security Recommendations from Blockchain Breaches 2803.2 Enhancing Blockchain Security: Mitigating Vulnerabilities and Design Flaws 2863.2.1 Introduction to Threat Modeling 2883.2.2 PASTA Threat Modeling 2923.2.2.1 Definition of Business Objectives 2933.2.2.2 Definition of the Technical Scope 2953.2.2.3 Application Decomposition and Analysis 2973.2.2.4 Threat Analysis 2993.2.2.5 Vulnerability Analysis 3013.2.2.6 Attack Modeling (AM) 3043.2.2.7 Risk Assessment and Mitigation 3073.2.3 Threat Modeling Example: DeFi Lending and Borrowing dApp 3113.2.3.1 Stage 0 – Setting the Stages for PASTA Threat Modeling 3173.2.3.2 Stage I – Definition of Business Objectives 3183.2.3.3 Stage II – Definition of Technical Scope 3373.2.3.4 Stage III – Application Decomposition and Analysis 3453.2.3.5 Stage IV – Threat Analysis 3623.2.3.6 Stage V – Vulnerability Analysis 3813.2.3.7 Stage VI – Attack Modeling 3993.2.3.8 Stage VII – Risk Analysis and Management 4183.2.4 Security-Driven Tools and Techniques for dApps 4433.3 Auditing Blockchain Applications for Compliance 4523.4 Conclusions 4584 Securing Blockchain Applications: Practical Examples 4614.1 Introduction 4614.2 dApp Creation Example 4624.2.1 Architecture 4624.2.2 Project Components 4624.2.2.1 Token.sol (ERC-20 Token Contract) 4624.2.2.2 Smart Contract Deployment 4634.2.3 AWS Integration 4644.2.3.1 API Gateway Setup 4644.2.3.2 Create a New API in Amazon API Gateway 4644.2.3.3 Link the API to AWS Lambda Function 4644.2.3.4 Define API Methods 4654.2.3.5 Additional Configuration 4664.2.4 Create a Frontend 4664.2.4.1 Create React App 4674.2.4.2 Create Frontend Code 4674.2.5 Security Review 4684.2.5.1 Smart Contract Vulnerabilities 4684.2.5.2 AWS Lambda Security 4684.2.5.3 API Gateway Misconfigurations 4694.2.5.4 Data Storage Risks 4694.2.5.5 Blockchain Event Handling 4704.2.5.6 Cross-Origin Resource Sharing (CORS) 4704.2.5.7 Frontend Integration Risks 4704.2.6 Conclusion 4704.3 Code Auditing Examples 4714.3.1 Introduction 4714.3.2 Rationale for Secure Coding Practices 4714.3.3 Auditing Smart Contract Code 4724.3.3.1 Common Smart Contract Vulnerabilities: Reentrancy 4734.3.3.2 Integer Overflows and Underflows 4744.3.3.3 DoS of Smart Contracts 4744.3.3.4 Access Control Failures 4754.3.3.5 Logic Flaws and Business Logic Errors 4764.3.4 Audit Processes and Tools for Smart Contracts 4764.3.4.1 Manual Code Review 4764.3.4.2 Automated Static Analysis Tools 4774.3.4.3 Unit and Integration Testing 4774.3.4.4 Formal Verification 4784.3.5 Best Practices in Smart Contract Audits 4784.3.5.1 Security by Design 4784.3.5.2 Remediation and Secure Redeployment 4794.3.6 Auditing Blockchain Node Software 4794.3.6.1 Types of Blockchain Nodes 4794.3.6.2 Typical Vulnerabilities in Node Implementations 4804.3.6.3 Approaches to Node Software Auditing 4834.3.7 Auditing Wallet Software 4844.3.7.1 Types of Wallets 4854.3.7.2 Wallet-Specific Vulnerabilities 4864.3.7.3 Wallet Security Audits and Testing 4884.3.8 Auditing dApps 4894.3.8.1 dApp Architecture Components 4894.3.8.2 Common dApp Vulnerabilities 4904.3.8.3 dApp Auditing and Testing 4914.3.9 Consolidating Findings and Reporting 4924.3.9.1 Security Reporting Framework 4934.3.9.2 Coordination with Development Teams (see the note) 4944.3.9.3 Disclosure Best Practices 4944.3.10 Conclusion 495Appendix A: Threat Modeling Matrix 497Appendix B: Mapping of Threat Scenarios to Targeted Weaknesses and Asset Impacted 531Appendix C: Mapping of Threat Scenarios to Exploitable Attack Paths 541Appendix D: Threat Scenarios Attack Simulation Tests 543Appendix E: Threat Scenario Weakness and Vulnerabilities Risk Ratings 547Appendix F: Risks Mitigation Plan 553Appendix G: Threats Risk Register 557Appendix H: Attack Simulation Testing Report 559Appendix I: Risk Analysis Report 563References 571About the Authors 591Index 593