Cantitate/Preț
Produs

Computer Security and the Internet: Information Security and Cryptography

Autor Paul C. van Oorschot
en Limba Engleză Hardback – 14 oct 2021

Abordarea tehnică din Computer Security and the Internet diferă de cea din Introduction to Computer Security de Michael T. Goodrich prin echilibrul fin între rigoare și accesibilitate — este mai puțin orientată spre un public generalist și mai mult spre specialiștii care au nevoie de specificații tehnice concrete fără a se pierde în formalism matematic pur. Subliniem faptul că Paul C. van Oorschot reușește să distileze concepte complexe în aproximativ 440 de pagini, oferind o bază solidă pentru dezvoltatori și manageri tehnici. Notăm cu interes continuitatea în opera autorului; dacă în Handbook of Applied Cryptography accentul cădea pe mecanismele matematice ale securității, acest volum extinde perspectiva asupra întregului ecosistem digital. Cartea este organizată progresiv, începând cu un set de 20 de principii de design care sunt reaplicate constant pe parcursul celor 13 capitole. Structura ne poartă de la blocurile fundamentale ale criptografiei și protocoalele de autentificare, către securitatea sistemelor de operare și a software-ului, culminând cu analize aplicate pe tehnologii moderne precum Bitcoin și Ethereum. Credem că valoarea practică a lucrării rezidă în capacitatea de a conecta erorile recurente de design din ultimii 50 de ani cu soluțiile actuale de apărare. Deși este un text de nivel universitar, autorul evită capcana abstractizării excesive, oferind în schimb detalii tehnice selective despre exploit-uri, securitatea browserelor și rețele wireless LAN (802.11). Includerea referințelor către standardele NIST și IETF transformă acest volum într-un instrument de lucru esențial pentru alinierea la bunele practici industriale actuale.

Citește tot Restrânge

Din seria Information Security and Cryptography

Preț: 43268 lei

Preț vechi: 54085 lei
-20%

Puncte Express: 649

Carte disponibilă

Livrare economică 01-15 mai
Livrare express 16-22 aprilie pentru 5830 lei


Specificații

ISBN-13: 9783030834104
ISBN-10: 3030834107
Pagini: 476
Ilustrații: XXIX, 446 p. 137 illus., 133 illus. in color.
Dimensiuni: 183 x 260 x 31 mm
Greutate: 1.09 kg
Ediția:2nd edition 2021
Editura: Springer
Colecția Information Security and Cryptography
Seria Information Security and Cryptography

Locul publicării:Cham, Switzerland

De ce să citești această carte

Recomandăm această carte profesioniștilor IT și studenților care doresc să înțeleagă arhitectura securității informatice dincolo de simplele definiții. Cititorul câștigă o viziune sistemică bazată pe 20 de principii practice, învățând să identifice vulnerabilitățile în software și rețele. Este un ghid tehnic riguros care acoperă atât fundamentele clasice, cât și securitatea activelor digitale moderne precum blockchain-ul, fără a necesita un background matematic avansat.


Despre autor

Paul C. van Oorschot este un cercetător și autor de renume în domeniul securității informației, fiind cunoscut în special pentru contribuția sa la Handbook of Applied Cryptography, o lucrare de referință în domeniu. Expertiza sa acoperă arii vaste, de la protocoale de autentificare la gestionarea certificatelor cu cheie publică. În prezent, activitatea sa se concentrează pe aplicarea riguroasă a principiilor de securitate în designul sistemelor moderne, reușind să facă puntea între cercetarea academică și implementarea practică în industrie și administrație guvernamentală.


Descriere scurtă

This book provides a concise yet comprehensive overview of computer and Internet security, suitable for a one-term introductory course for junior/senior undergrad or first-year graduate students. It is also suitable for self-study by anyone seeking a solid footing in security – including software developers and computing professionals, technical managers and government staff. An overriding focus is on brevity, without sacrificing breadth of core topics or technical detail within them. The aim is to enable a broad understanding in roughly 350 pages. Further prioritization is supported by designating as optional selected content within this. Fundamental academic concepts are reinforced by specifics and examples, and related to applied problems and real-world incidents.
The first chapter provides a gentle overview and 20 design principles for security. The ten chapters that follow provide a framework for understanding computer and Internet security. They regularly refer back to the principles, with supporting examples. These principles are the conceptual counterparts of security-related error patterns that have been recurring in software and system designs for over 50 years.
The book is “elementary” in that it assumes no background in security, but unlike “soft” high-level texts it does not avoid low-level details, instead it selectively dives into fine points for exemplary topics to concretely illustrate concepts and principles. The book is rigorous in the sense of being technically sound, but avoids both mathematical proofs and lengthy source-code examples that typically make books inaccessible to general audiences. Knowledge of elementary operating system and networking concepts is helpful, but review sections summarize the essential background. For graduate students, inline exercises and supplemental references provided in per-chapter endnotes provide a bridge to further topics and a springboard to the research literature; for those in industry and government, pointers are provided to helpful surveys and relevant standards, e.g., documents from the Internet Engineering Task Force (IETF), and the U.S. National Institute of Standards and Technology.


Cuprins

1. Security Concepts and Principles.- 2. Cryptographic Building Blocks.- 3. User Authentication—Passwords, Biometrics and Alternatives.- 4. Authentication Protocols and Key Establishment.-5. Operating System Security and Access Control.- 6. Software Security—Exploits and Privilege Escalation.- 7. Malicious Software.- 8. Public-Key Certificate Management and Use Cases.- 9. Web and Browser Security.- 10. Firewalls and Tunnels.- 11. Intrusion Detection and Network-Based Attacks.- 12. Wireless LAN Security: 802.11 and Wi-Fi.- 13. Bitcoin, Blockchains and Ethereum.- Epilogue.- Index. 

Recenzii

“I can vouch to the accuracy and clarity found in Van Oorschot's latest book, and can recommend it to those serious about getting introduced to security. The topic is very broad, as evidenced by the number of important security conferences and the hundreds of papers published every year, not to mention the billions made selling security products and services.” (Rik Farrow, usenix.org, April 8, 2022)

“The book is a technical tour de force and is a helpful reference. … the book has its primary audience in students in a one-term or two-term, third- or fourth-year undergraduate course in computer science, those in the corporate world looking for a highly technical reference will find the book to be quite valuable. … As a first-rate computer scientist and writer, van Oorschot has written a book that will make you a much smarter and better information security professional.” (Ben Rothke, rsaconference.com, April 7, 2022)

Notă biografică

Paul C. van Oorschot is a Professor of Computer Science at Carleton University (Ottawa), where he is Canada Research Chair in Authentication and Computer Security. He is an ACM Fellow, an IEEE Fellow, and a Fellow of the Royal Society of Canada. He was Program Chair of NSPW 2014-2015, USENIX Security 2008, NDSS 2001-2002, and co-author of the Handbook of Applied Cryptography (1996). He has served on the editorial boards of IEEE TDSC, IEEE TIFS, and ACM TISSEC/TOPS. His research interests include authentication and identity management, computer security, Internet security, security and usability, software security, and applied cryptography. His academic career was preceded by 14 years of industrial research and development in telecommunications and software security.

Textul de pe ultima copertă

Building on the core strengths of the inaugural book, this second edition of a uniquely accessible textbook provides a concise, yet comprehensive overview of computer and Internet security. It builds on the design principles to address security-related error patterns that have plagued software and system designs for more than 50 years.
Computer Security and the Internet is “elementary” in that it assumes no background in security, but unlike “soft” high-level texts it does not avoid low-level details. The book reinforces fundamental academic concepts with examples and also relates these concepts to practical challenges and real-world incidents. Its overriding focus is brevity, without sacrificing breadth of core topics or technical detail within them; it designates selected content as optional to help readers prioritize topics. While knowledge of elementary operating-system and networking concepts is helpful, review sections summarize the essential background.
Topics and features:
  • Delivers comprehensive, technically sound explanations without burdening readers with mathematical proofs or lengthy source-code examples
  • (NEW) adds chapter on wireless LAN security (Wi-Fi and 802.11)
  • (NEW) adds chapter on Bitcoin and Ethereum, blockchains and cryptocurrencies
  • Integrates inline exercises and supplemental per-chapter references and endnotes, bridging to further topics and serving as a springboard to research literature
  • Dives selectively into fine points for exemplary topics to concretely illustrate concepts and principles
  • Provides pointers to key surveys and relevant standards, including from the Internet Engineering Task Force and the U.S. National Institute of Standards and Technology


Ideal for a one- or two-term introductory course for junior/senior undergraduate or first-year graduate students, this textbook/reference is also suitable for self-study by anyone seeking a solid footing in security, including software developers and computing professionals, technical managers, and government staff.
Paul C. van Oorschot is a Professor of Computer Science at Carleton University (Ottawa), Canada Research Chair in Authentication and Computer Security, ACM Fellow, and IEEE Fellow. His earlier industrial career was in telecommunications and software security.