InfoSecurity 2008 Threat Analysis
暫譯: 資訊安全 2008 威脅分析

Craig Schiller, Seth Fogie, Colby DeRodeff, Michael Gregg

  • 出版商: Syngress Media
  • 出版日期: 2007-11-01
  • 定價: $1,980
  • 售價: 5.0$990
  • 語言: 英文
  • 頁數: 480
  • 裝訂: Paperback
  • ISBN: 1597492248
  • ISBN-13: 9781597492249
  • 相關分類: 資訊安全
  • 立即出貨(限量) (庫存=4)

相關主題

商品描述

An all-star cast of authors analyze the top IT security threats for 2008 as selected by the editors and readers of Infosecurity Magazine. This book, compiled from the Syngress Security Library, is an essential reference for any IT professional managing enterprise security. It serves as an early warning system, allowing readers to assess vulnerabilities, design protection schemes and plan for disaster recovery should an attack occur. Topics include Botnets, Cross Site Scripting Attacks, Social Engineering, Physical and Logical Convergence, Payment Card Industry (PCI) Data Security Standards (DSS), Voice over IP (VoIP), and Asterisk Hacking.

Each threat is fully defined, likely vulnerabilities are identified, and detection and prevention strategies are considered. Wherever possible, real-world examples are used to illustrate the threats and tools for specific solutions.

* Provides IT Security Professionals with a first look at likely new threats to their enterprise
* Includes real-world examples of system intrusions and compromised data
* Provides techniques and strategies to detect, prevent, and recover
* Includes coverage of PCI, VoIP, XSS, Asterisk, Social Engineering, Botnets, and Convergence

商品描述(中文翻譯)

一群明星作家分析了2008年由《Infosecurity Magazine》的編輯和讀者選出的主要IT安全威脅。本書匯編自Syngress安全圖書館,是任何管理企業安全的IT專業人士必備的參考資料。它充當了一個早期警報系統,讓讀者能夠評估漏洞、設計保護方案並計劃災難恢復,以應對可能發生的攻擊。主題包括僵尸網絡(Botnets)、跨站腳本攻擊(Cross Site Scripting Attacks)、社會工程(Social Engineering)、物理與邏輯融合(Physical and Logical Convergence)、支付卡行業(Payment Card Industry, PCI)數據安全標準(Data Security Standards, DSS)、網路語音(Voice over IP, VoIP)和Asterisk駭客攻擊。

每個威脅都被充分定義,可能的漏洞被識別,並考慮了檢測和預防策略。在可能的情況下,使用實際案例來說明威脅和特定解決方案的工具。

* 為IT安全專業人士提供對其企業可能出現的新威脅的初步了解
* 包含系統入侵和數據洩露的實際案例
* 提供檢測、預防和恢復的技術和策略
* 包含對PCI、VoIP、XSS、Asterisk、社會工程、僵尸網絡和融合的覆蓋內容