System Assurance: Beyond Detecting Vulnerabilities (Paperback)

Nikolai Mansourov, Djenana Campara

  • 出版商: Morgan Kaufmann
  • 出版日期: 2010-12-06
  • 定價: $2,260
  • 售價: 8.5$1,921
  • 語言: 英文
  • 頁數: 368
  • 裝訂: Paperback
  • ISBN: 0123814146
  • ISBN-13: 9780123814142
  • 立即出貨 (庫存 < 3)

買這商品的人也買了...

商品描述

In this day of frequent acquisitions and perpetual application integrations, systems are often an amalgamation of multiple programming languages and runtime platforms using new and legacy content. Systems of such mixed origins are increasingly vulnerable to defects and subversion.

System Assurance: Beyond Detecting Vulnerabilities addresses these critical issues. As a practical resource for security analysts and engineers tasked with system assurance, the book teaches you how to use the Object Management Group's (OMG) expertise and unique standards to obtain accurate knowledge about your existing software and compose objective metrics for system assurance. OMG's Assurance Ecosystem provides a common framework for discovering, integrating, analyzing, and distributing facts about your existing enterprise software. Its foundation is the standard protocol for exchanging system facts, defined as the OMG Knowledge Discovery Metamodel (KDM). In addition, the Semantics of Business Vocabularies and Business Rules (SBVR) defines a standard protocol for exchanging security policy rules and assurance patterns. Using these standards together, you will learn how to leverage the knowledge of the cybersecurity community and bring automation to protect your system.




  • Provides end-to-end methodology for systematic, repeatable, and affordable System Assurance.

  • Includes an overview of OMG Software Assurance Ecosystem protocols that integrate risk, architecture and code analysis guided by the assurance argument.

  • Case Study illustrating the steps of the System Assurance Methodology using automated tools.

商品描述(中文翻譯)

在這個頻繁收購和持續應用整合的時代,系統通常是由多種程式語言和運行平台的新舊內容混合而成。這樣混合來源的系統越來越容易出現缺陷和被破壞。

《系統保證:超越漏洞檢測》解決了這些關鍵問題。作為安全分析師和工程師的實用資源,本書教導您如何利用物件管理組織(OMG)的專業知識和獨特標準,獲取有關現有軟體的準確知識,並為系統保證建立客觀指標。OMG的保證生態系統提供了一個共同框架,用於發現、整合、分析和分發有關現有企業軟體的事實。其基礎是用於交換系統事實的標準協議,即OMG知識發現元模型(KDM)。此外,《業務詞彙和業務規則的語義學》(SBVR)定義了一個用於交換安全策略規則和保證模式的標準協議。通過結合這些標準,您將學習如何利用網絡安全社區的知識,並實現系統保護的自動化。

本書的特點包括:
- 提供了一個全面的、可重複和負擔得起的系統保證方法論。
- 概述了OMG軟體保證生態系統協議,該協議將風險、架構和代碼分析與保證論證相結合。
- 通過使用自動化工具展示了系統保證方法論的步驟的案例研究。