Cyber Defense for the Hybrid Enterprise in the Age of AI: Zero Trust and the Anatomy of Cyber Breaches
暫譯: AI 時代混合型企業的網路防禦:Zero Trust 與網路入侵剖析

Matos, Luis

  • 出版商: Cisco Press
  • 出版日期: 2026-09-27
  • 售價: $3,290
  • 貴賓價: 9.5 折 $3,125
  • 語言: 英文
  • 頁數: 960
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 0135472776
  • ISBN-13: 9780135472774
  • 相關分類: Penetration-test
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

Cyber Defense for the Hybrid Enterprise in the Age of AI explores how digital fraud, ransomware, malicious devices, and AI-driven cyber threats evolved into a modern cyber battlefield where attackers increasingly abuse automation, stealth, identity manipulation, and legitimate enterprise protocols to bypass traditional security defenses. Built from real-world enterprise incidents, Cisco security research, and operational experience across hybrid infrastructures, this book delivers a practical guide for understanding, detecting, and defending against modern cyberattacks using vendor-agnostic methodologies such as Zero Trust, NIST SP 800-207, NIST SP 800-30, CISA Zero Trust principles, Cyber Kill Chain, MITRE ATT&CK, and Cisco SAFE aligned with world-class security architectures.

Developed from a collaboration between Cisco and a global enterprise impacted by repeated digital fraud incidents, this book introduces the concept of the "digital battlefield" through different generations of real-world attacks observed in production environments. It also presents three attack models developed in Cisco labs: L.U.M.A. (Layer 2 Undetected Mobile Access), LTR-SMB (Little Red SMB Attack), and LTR-Inject (Little Red Wireless Inject Attack). These attack models demonstrate how adversaries can exploit Layer 2 communication, trusted enterprise protocols, wireless infrastructures, mobile networks, and identity spoofing techniques to evade traditional security controls and expand laterally across enterprise environments.

One of the most unique aspects of this book is that readers experience the battlefield from both perspectives: the attacker's side and the defender's side. Through adversary emulation exercises, penetration testing simulations, and real-world attack scenarios, readers gain a practical understanding of how modern attacks evolve across the complete attack lifecycle, including reconnaissance, lateral movement, persistence, ransomware propagation, malicious device infiltration, credential abuse, and data exfiltration. At the same time, this book demonstrates how defenders can detect and contain these threats using behavioral analytics, Zero Trust principles, and technologies such as Cisco ISE, TrustSec, MACsec, Secure Firewall, Secure Network Analytics, and Splunk integrated into adaptive security architectures.

Through practical deployment guidance, real-world case studies, lab simulations, and adversary emulation scenarios, security professionals will gain actionable strategies to implement continuous verification, behavioral analytics, automated threat containment, microsegmentation, macrosegmentation, and identity-aware security controls across enterprise and hybrid environments.

More than a theoretical cybersecurity book, Cyber Defense for the Hybrid Enterprise in the Age of AI serves as a field-tested operational playbook for architects, engineers, SOC analysts, penetration testers, and security leaders responsible for protecting modern infrastructures against the next generation cyber threats.

Key Features

  • Explains different generations of digital fraud, ransomware, and malicious device attacks
  • Introduces the L.U.M.A., LTR-SMB, and LTR-Inject attack models developed in Cisco labs
  • Applies vendor-agnostic methodologies including Zero Trust, NIST SP 800-207, NIST SP 800-30, CISA, Cyber Kill Chain, MITRE ATT&CK, and SAFE
  • Demonstrates both attacker and defender perspectives during real-world attack simulations
  • Covers ransomware, MITM attacks, malicious devices, wireless attacks, AI-driven threats, and east-west lateral movement
  • Includes penetration testing scenarios, adversary emulation exercises, and real-world enterprise case studies
  • Demonstrates practical implementation strategies for behavioral analytics, microsegmentation, and Zero Trust architectures
  • Presents actionable techniques to reduce operational, financial, and reputational risk
  • Shows how to integrate Cisco ISE, TrustSec, MACsec, Secure Firewall, Secure Network Analytics, Splunk, and other security technologies into modern enterprise environments

商品描述(中文翻譯)

《Cyber Defense for the Hybrid Enterprise in the Age of AI》探討數位詐欺、勒索軟體、惡意裝置與 AI 驅動的網路威脅,如何演變成現代網路戰場;在這個戰場中,攻擊者越來越常濫用自動化、隱匿技術、身分操弄,以及企業所信任的合法通訊協定,藉此繞過傳統安全防禦機制。本書以真實企業事件、Cisco 安全性研究,以及混合式基礎架構的實務經驗為基礎,運用 Zero Trust、NIST SP 800-207、NIST SP 800-30、CISA Zero Trust 原則、Cyber Kill Chain、MITRE ATT&CK 與 Cisco SAFE 等與廠商無關的方法論,並結合世界級安全架構,提供理解、偵測與防禦現代網路攻擊的實用指南。

本書源自 Cisco 與一家多次遭受數位詐欺事件影響的全球企業之合作,透過在正式環境中觀察到的不同世代真實攻擊,介紹「數位戰場」的概念。本書也呈現 Cisco 實驗室所開發的三種攻擊模型:L.U.M.A.(Layer 2 Undetected Mobile Access,第 2 層未偵測行動存取)、LTR-SMB(Little Red SMB Attack,小紅 SMB 攻擊)與 LTR-Inject(Little Red Wireless Inject Attack,小紅無線注入攻擊)。這些攻擊模型展示攻擊者如何利用第 2 層通訊、受信任的企業通訊協定、無線基礎架構、行動網路與身分偽造技術,避開傳統安全控制,並在企業環境中進行橫向擴散。

本書最獨特的特色之一,是讓讀者同時從兩種角度體驗戰場:攻擊者的角度與防禦者的角度。透過對手模擬演練、滲透測試模擬與真實世界攻擊情境,讀者將實際了解現代攻擊如何貫穿完整的攻擊生命週期,包括偵察、橫向移動、持續存取、勒索軟體擴散、惡意裝置滲透、憑證濫用與資料外洩。同時,本書也示範防禦者如何運用行為分析、Zero Trust 原則,以及 Cisco ISE、TrustSec、MACsec、Secure Firewall、Secure Network Analytics 和 Splunk 等技術,將這些威脅偵測並加以遏止,進而整合至自適應安全架構中。

透過實際部署指引、真實案例研究、實驗室模擬與對手模擬情境,安全專業人員將獲得可立即採用的策略,以便在企業與混合式環境中實施持續驗證、行為分析、自動化威脅遏止、微分段、宏分段,以及身分感知型安全控制。

《Cyber Defense for the Hybrid Enterprise in the Age of AI》不只是一本理論性的網路安全書籍,更是一本經過實務驗證的營運作戰手冊,適合負責保護現代基礎架構、抵禦下一代網路威脅的架構師、工程師、SOC 分析師、滲透測試人員與安全主管。

主要特色

• 說明不同世代的數位詐欺、勒索軟體與惡意裝置攻擊
• 介紹 Cisco 實驗室所開發的 L.U.M.A.、LTR-SMB 與 LTR-Inject 攻擊模型
• 套用包括 Zero Trust、NIST SP 800-207、NIST SP 800-30、CISA、Cyber Kill Chain、MITRE ATT&CK 與 SAFE 在內的廠商無關方法論
• 在真實世界攻擊模擬中,展示攻擊者與防禦者雙方的觀點
• 涵蓋勒索軟體、MITM 攻擊、惡意裝置、無線攻擊、AI 驅動的威脅,以及東西向橫向移動
• 收錄滲透測試情境、對手模擬演練與真實企業案例研究
• 示範行為分析、微分段與 Zero Trust 架構的實際導入策略
• 提出可執行的技術,以降低營運、財務與聲譽風險
• 說明如何將 Cisco ISE、TrustSec、MACsec、Secure Firewall、Secure Network Analytics、Splunk 與其他安全技術整合至現代企業環境中

作者簡介

Luis Matos, CCIEx5, is a Principal Architect in Cisco's CX Advanced Services organization for the LATAM region, bringing more than 26 years of experience in cybersecurity and networking, including more than 23 years as a university professor at several national institutions. Throughout his career, he has specialized in designing and implementing complex solutions for Data Centers, Internet/MPLS backbones, and enterprise security architectures, with a strong focus on telecommunications providers, large financial institutions, airports, and critical infrastructures.

作者簡介(中文翻譯)

Luis Matos,CCIEx5,是 Cisco CX Advanced Services 組織在 LATAM 地區的首席架構師,擁有超過 26 年的資安與網路經驗,其中包括在多所國家級高等教育機構擔任大學教授超過 23 年的經歷。在職業生涯中,他專精於設計與實作複雜的解決方案,涵蓋資料中心、Internet/MPLS 骨幹網路,以及企業安全架構,並主要服務於電信業者、大型金融機構、機場與關鍵基礎設施。