Your expert guide to information security
As businesses and consumers become more dependent on complex
multinational information systems, the need to understand and
devise sound information security systems has never been greater.
This title takes a practical approach to information security by
focusing on real-world examples. While not sidestepping the theory,
the emphasis is on developing the skills and knowledge that
security and information technology students and professionals need
to face their challenges. The book is organized around four major
themes:
* Cryptography: classic cryptosystems, symmetric key cryptography,
public key cryptography, hash functions, random numbers,
information hiding, and cryptanalysis
* Access control: authentication and authorization, password-based
security, ACLs and capabilities, multilevel and multilateral
security, covert channels and inference control, BLP and Biba's
models, firewalls, and intrusion detection systems
* Protocols: simple authentication protocols, session keys, perfect
forward secrecy, timestamps, SSL, IPSec, Kerberos, and GSM
* Software: flaws and malware, buffer overflows, viruses and worms,
software reverse engineering, digital rights management, secure
software development, and operating systems security
Additional features include numerous figures and tables to
illustrate and clarify complex topics, as well as problems-ranging
from basic to challenging-to help readers apply their newly
developed skills. A solutions manual and a set of classroom-tested
PowerPoint(r) slides will assist instructors in their course
development. Students and professors in information technology,
computer science, and engineering, and professionals working in the
field will find this reference most useful to solve their
information security issues.
An Instructor's Manual presenting detailed solutions to all the
problems in the book is available from the Wiley editorial
department.
An Instructor Support FTP site is also available.
Autorentext
MARK STAMP, PHD, is Professor of Computer Science, San José State University, where he teaches undergraduate and graduate-level information security courses. In addition to his experience gained in private industry and academia, Dr. Stamp has seven years' experience working as a cryptanalyst at the U.S. National Security Agency.
Klappentext
Your expert guide to information security
As businesses and consumers become more dependent on complex multinational information systems, the need to understand and devise sound information security systems has never been greater. This title takes a practical approach to information security by focusing on real-world examples. While not sidestepping the theory, the emphasis is on developing the skills and knowledge that security and information technology students and professionals need to face their challenges. The book is organized around four major themes:
- Cryptography: classic cryptosystems, symmetric key cryptography, public key cryptography, hash functions, random numbers, information hiding, and cryptanalysis
- Access control: authentication and authorization, password-based security, ACLs and capabilities, multilevel and multilateral security, covert channels and inference control, BLP and Biba's models, firewalls, and intrusion detection systems
- Protocols: simple authentication protocols, session keys, perfect forward secrecy, timestamps, SSL, IPSec, Kerberos, and GSM
- Software: flaws and malware, buffer overflows, viruses and worms, software reverse engineering, digital rights management, secure software development, and operating systems security
Additional features include numerous figures and tables to illustrate and clarify complex topics, as well as problemsranging from basic to challengingto help readers apply their newly developed skills. A solutions manual and a set of classroom-tested PowerPoint® slides will assist instructors in their course development. Students and professors in information technology, computer science, and engineering, and professionals working in the field will find this reference most useful to solve their information security issues.
Zusammenfassung
Your expert guide to information security
As businesses and consumers become more dependent on complex multinational information systems, the need to understand and devise sound information security systems has never been greater. This title takes a practical approach to information security by focusing on real-world examples. While not sidestepping the theory, the emphasis is on developing the skills and knowledge that security and information technology students and professionals need to face their challenges. The book is organized around four major themes:
* Cryptography: classic cryptosystems, symmetric key cryptography, public key cryptography, hash functions, random numbers, information hiding, and cryptanalysis
* Access control: authentication and authorization, password-based security, ACLs and capabilities, multilevel and multilateral security, covert channels and inference control, BLP and Biba's models, firewalls, and intrusion detection systems
* Protocols: simple authentication protocols, session keys, perfect forward secrecy, timestamps, SSL, IPSec, Kerberos, and GSM
* Software: flaws and malware, buffer overflows, viruses and worms, software reverse engineering, digital rights management, secure software development, and operating systems security
Additional features include numerous figures and tables to illustrate and clarify complex topics, as well as problems-ranging from basic to challenging-to help readers apply their newly developed skills. A solutions manual and a set of classroom-tested PowerPoint(r) slides will assist instructors in their course development. Students and professors in information technology, computer science, and engineering, and professionals working in the field will find this reference most useful to solve their information security issues.
An Instructor's Manual presenting detailed solutions to all the problems in the book is available from the Wiley editorial department.
An Instructor Support FTP site is also available.
Inhalt
Preface.
About The Author.
Acknowledgments.
1. Introduction.
1.1 The Cast of Characters.
1.2 Alice's Online Bank.
1.2.1 Confidentiality, Integrity and.
1.2.2 Beyond CIA.
1.3 About This Book.
1.3.1 Cryptography.
1.3.2 Access Control.
1.3.3 Protocols.
1.3.4 Software.
1.4 The People Problem.
1.5 Theory and Practice.
1.6 Problems.
I. CRYPTO.
2. Crypto Basics.
2.1 Introduction.
2.2 How to Speak Crypto.
2.3 Classic Crypto.
2.3.1 Simple Substitution Cipher.
2.3.2 Cryptanalysis of a Simple Substitution.
2.3.3 Definition of Secure.
2.3.4 Double Transposition Cipher.
2.3.5 One-time Pad.
2.3.6 Project VENONA.
2.3.7 Codebook Cipher.
2.3.8 Ciphers of the Election of 1876.
2.4 Modern Crypto History.
2.5 A Taxonomy of Cryptography.
2.6 A Taxonomy of Cryptanalysis.
2.7 Summary.
2.8 Problems.
3. Symmetric Key Crypto.
3.1 Introduction.
3.2 Stream Ciphers.
3.2.1 A5/1.
3.2.2 RC4.
3.3 Block Ciphers.
3.3.1 Feistel Cipher.
3.3.2 DES.
3.3.3 Triple DES.
3.3.4 AES.
3.3.5 Three More Block Ciphers.
3.3.6 TEA.
3.3.7 Block Cipher Modes.
3.4 Integrity.
3.5 Summary.
3.6 Problems.