Network Security Bible (2nd Ed.)
Book information
Description
Network security is constantly evolving, and this comprehensive guide has been thoroughly updated to cover the newest developments. If you are responsible for network security, this is the reference you need at your side. Covering new techniques, technology, and methods for approaching security, it also examines new trends and best practices being used by many organizations. The revised Network Security Bible complements the Cisco Academy course instruction in networking security. Covers all core areas of network security and how they interrelate. Fully revised to address new techniques, technology, and methods for securing an enterprise worldwide. Examines new trends and best practices in use by organizations to secure their enterprises. Features additional chapters on areas related to data protection/correlation and forensics. Includes cutting-edge topics such as integrated cybersecurity and sections on Security Landscape, with chapters on validating security, data protection, forensics, and attacks and threats. If you need to get up to date or stay current on network security, Network Security Bible, 2nd Edition covers everything you need to know. Network Security Bible Second Edition......Page 1 About the Technical Editor......Page 9 Credits......Page 11 Acknowledgments......Page 13 Contents at a Glance......Page 15 Contents......Page 17 The Goal of This Book......Page 37 How to Use This Book......Page 38 How This Book Is Organized......Page 40 Where To Go From Here......Page 46 Part I: Network Security Landscape......Page 47 Cyber Security......Page 49 Summary......Page 53 General Trends......Page 55 The Changing Face of Cyber Security......Page 62 Summary......Page 63 An Enterprise Security Methodology......Page 65 Key Questions to Manage Risk......Page 73 Summary......Page 78 Part II: Security Principles and Practices......Page 79 Key Principles of Network Security......Page 81 Formal Processes......Page 83 Risk Management......Page 106 Calculating and Managing Risk......Page 116 Summary......Page 117 Security Policies......Page 119 Security Awareness......Page 123 Managing the Technical Effort......Page 125 Configuration Management......Page 133 Business Continuity and Disaster Recovery Planning......Page 136 Physical Security......Page 144 Legal and Liability Issues......Page 151 Summary......Page 153 Control Models......Page 155 Types of Access Control Implementations......Page 158 Identification and Authentication......Page 161 Databases......Page 167 Remote Access......Page 169 Summary......Page 171 Malicious Code......Page 173 Review of Common Attacks......Page 175 External Attack Methodologies Overview......Page 182 Internal Threat Overview......Page 186 Summary......Page 188 Part III: Operating Systems and Applications......Page 189 Chapter 8: Windows Security......Page 191 Windows Security at the Heart of the Defense......Page 193 Out-of-the-Box Operating System Hardening......Page 197 Installing Applications......Page 217 Putting the Workstation on the Network......Page 221 Operating Windows Safely......Page 223 Upgrades and Patches......Page 237 Maintain and Test the Security......Page 240 Attacks Against the Windows Workstation......Page 244 Summary......Page 251 The Focus of UNIX/Linux Security......Page 253 Physical Security......Page 258 Controlling the Configuration......Page 263 Operating UNIX Safely......Page 270 Hardening UNIX......Page 291 Summary......Page 299 Web Browser and Client Risk......Page 301 How a Web Browser Works......Page 305 Web Browser Attacks......Page 314 Operating Safely......Page 317 Web Browser Configurations......Page 322 Summary......Page 332 What Is HTTP?......Page 333 How Does HTTP Work?......Page 335 Server Content......Page 347 Client Content......Page 349 State......Page 355 Attacking Web Servers......Page 361 Web Services......Page 363 Summary......Page 367 The E-mail Risk......Page 369 The E-mail Protocols......Page 386 E-mail Authentication......Page 391 Operating Safely When Using E-mail......Page 394 Summary......Page 401 Chapter 13: Domain Name System......Page 403 DNS Basics......Page 404 Purpose of DNS......Page 410 Setting Up DNS......Page 421 Security Issues with DNS......Page 423 DNS Attacks......Page 430 Designing DNS......Page 432 Detailed DNS Architecture......Page 434 DNS SEC......Page 435 Summary......Page 439 General Server Risks......Page 441 Security by Design......Page 442 Operating Servers Safely......Page 459 Server Applications......Page 463 Multi-Level Security and Digital Rights Management......Page 467 Summary......Page 473 Part IV: Network Security Fundamentals......Page 475 Protocols......Page 477 The Open Systems Interconnect Model......Page 478 The OSI Layers......Page 479 The TCP/IP Model......Page 485 TCP/IP Model Layers......Page 487 Internet Protocol......Page 488 VoIP......Page 496 Summary......Page 503 Electromagnetic Spectrum......Page 505 The Cellular Phone Network......Page 508 Placing a Cellular Telephone Call......Page 510 Wireless Transmission Systems......Page 515 Pervasive Wireless Data Network Technologies......Page 519 IEEE Wireless LAN Specifications......Page 524 IEEE 802.11......Page 526 IEEE 802.11 Wireless Security......Page 531 Bluetooth......Page 549 Wireless Application Protocol......Page 550 Future of Wireless......Page 552 Summary......Page 554 Chapter 17: Network Architecture Fundamentals......Page 555 Network Segments......Page 556 Network Address Translation......Page 557 Basic Architecture Issues......Page 559 Subnetting, Switching, and VLANs......Page 562 Address Resolution Protocol and Media Access Control......Page 563 Dynamic Host Configuration Protocol and Addressing Control......Page 564 Zero Configuration Networks......Page 565 System Design and Architecture Against Insider Threats......Page 571 Common Attacks......Page 574 Summary......Page 575 Firewalls......Page 577 Firewall Rules......Page 583 The Use of Personal Firewalls......Page 588 Summary......Page 594 Intrusion Detection Systems......Page 595 Emerging Technologies in Intrusion Detection Systems......Page 602 Summary......Page 613 Part V: Communication......Page 615 Chapter 20: Secret Communication......Page 617 What is Cryptography?......Page 618 General Terms......Page 622 Principles of Cryptography......Page 623 Historic Cryptography......Page 627 The Four Cryptographic Primitives......Page 633 Putting These Primitives Together to Achieve CIA......Page 648 The Difference Between Algorithm and Implementation......Page 649 Proprietary Versus Open Source Algorithms......Page 652 Attacks on Hash Functions......Page 653 Quantum Cryptography......Page 663 Summary......Page 674 Where Hidden Data Hides......Page 677 Where Is It Going?......Page 679 Overview of Steganography......Page 680 History of Steganography......Page 685 Core Areas of Network Security and Their Relation to Steganography......Page 687 Principles of Steganography......Page 689 Steganography Compared to Cryptography......Page 690 Types of Steganography......Page 692 Products That Implement Steganography......Page 700 Steganography Versus Digital Watermarking......Page 719 Types of Digital Watermarking......Page 721 Digital Watermarking and Stego......Page 722 Summary......Page 725 Chapter 22: Applications of Secure/Covert Communication......Page 727 E-mail......Page 728 Authentication Servers......Page 731 Working Model......Page 732 Public Key Infrastructure......Page 734 Virtual Private Networks......Page 738 Secure Sockets Layer/Transport Layer Security......Page 745 SSL Handshake......Page 746 Summary......Page 750 Part VI: The Security Threat and Response......Page 751 Intrusion Detection Mechanisms......Page 753 Honeypots......Page 758 Incident Handling......Page 762 Summary......Page 773 Chapter 24: Digital Forensics......Page 775 Traditional Computer Forensics......Page 776 Proactive Forensics......Page 792 Future Research Areas......Page 794 Summary......Page 796 Information Assurance Approaches and Methodologies......Page 797 Certification and Accreditation......Page 802 DIACAP......Page 806 Federal Information Processing Standard 102......Page 809 OMB Circular A-130......Page 810 The National Institute of Standards and Technology Assessment Guidelines......Page 811 Penetration Testing......Page 816 Auditing and Monitoring......Page 818 Summary......Page 820 Part VII: Integrated Cyber Security......Page 821 Overview......Page 823 Current State of Penetration Testing......Page 826 Formal Penetration Testing Methodology......Page 829 Steps to Exploiting a System......Page 833 Summary......Page 841 Chapter 27: Data Protection......Page 843 Endpoint Security......Page 845 Insider Threats and Data Protection......Page 851 Summary......Page 852 Critical Problems Facing Organizations......Page 855 General Tips for Protecting a Site......Page 861 Security Best Practices......Page 865 Summary......Page 880 Approaching the Problem......Page 881 Mission Resilience......Page 883 Limiting Failure Points......Page 890 Summary......Page 893 Index......Page 895
Similar books
CompTIA Linux+ Study Guide: Exam XK0-005, 5th Edition
2022 · EPUB
The Complete Internet Security Manual (New July 2021 Update)
2021 · DJVU
Cyber Crisis: Protecting Your Business from Real Threats in the Virtual World
Online Danger: How to Protect Yourself and Your Loved Ones From the Evil Side of the Internet
2018 · EPUB
Cyber Crisis: Protecting Your Business from Real Threats in the Virtual World
2021 · EPUB
SEC501.6: Data Loss Prevention
2016 · PDF
SEC501.4: First Responder
2016 · PDF
Hackers Beware: The Ultimate Guide to Network Security
2001 · DJVU