Network Security Assessment: Know Your Network, 2/e

Chris McNab

  • 出版商: O'Reilly
  • 出版日期: 2007-11-11
  • 定價: $1,650
  • 售價: 1.8$299
  • 語言: 英文
  • 頁數: 508
  • 裝訂: Paperback
  • ISBN: 0596510306
  • ISBN-13: 9780596510305
  • 相關分類: 資訊安全
  • 立即出貨(限量) (庫存=7)

買這商品的人也買了...

商品描述

Description

How secure is your network? The best way to find out is to attack it. Network Security Assessment provides you with the tricks and tools professional security consultants use to identify and assess risks in Internet-based networks-the same penetration testing model they use to secure government, military, and commercial networks. With this book, you can adopt, refine, and reuse this testing model to design and deploy networks that are hardened and immune from attack.

Network Security Assessment demonstrates how a determined attacker scours Internet-based networks in search of vulnerable components, from the network to the application level. This new edition is up-to-date on the latest hacking techniques, but rather than focus on individual issues, it looks at the bigger picture by grouping and analyzing threats at a high-level. By grouping threats in this way, you learn to create defensive strategies against entire attack categories, providing protection now and into the future.

Network Security Assessment helps you assess:
  • Web services, including Microsoft IIS, Apache, Tomcat, and subsystems such as OpenSSL, Microsoft FrontPage, and Outlook Web Access (OWA)

  • Web application technologies, including ASP, JSP, PHP, middleware, and backend databases such as MySQL, Oracle, and Microsoft SQL Server

  • Microsoft Windows networking components, including RPC, NetBIOS, and CIFS services

  • SMTP, POP3, and IMAP email services

  • IP services that provide secure inbound network access, including IPsec, Microsoft PPTP, and SSL VPNs

  • Unix RPC services on Linux, Solaris, IRIX, and other platforms

  • Various types of application-level vulnerabilities that hacker tools and scripts exploit

Assessment is the first step any organization should take to start managing information risks correctly. With techniques to identify and assess risks in line with CESG CHECK and NSA IAM government standards, Network Security Assessment gives you a precise method to do just that.

商品描述(中文翻譯)

描述

網絡安全評估

您的網絡有多安全?找出答案的最佳方法就是對其進行攻擊。《網絡安全評估》為您提供了專業安全顧問用於識別和評估基於互聯網的網絡風險的技巧和工具,這是他們用於保護政府、軍事和商業網絡的滲透測試模型。通過這本書,您可以採用、完善和重複使用這個測試模型,設計和部署網絡,使其免受攻擊。

《網絡安全評估》演示了一個決心的攻擊者如何搜索基於互聯網的網絡,尋找易受攻擊的組件,從網絡到應用層。這本新版書籍對最新的黑客技術保持了最新,但不是專注於個別問題,而是從更大的角度來分組和分析威脅。通過這種方式分組威脅,您學會了創建對抗整個攻擊類別的防禦策略,提供現在和未來的保護。

《網絡安全評估》幫助您評估:
- Web服務,包括Microsoft IIS、Apache、Tomcat和子系統,如OpenSSL、Microsoft FrontPage和Outlook Web Access(OWA)
- Web應用技術,包括ASP、JSP、PHP、中間件和後端數據庫,如MySQL、Oracle和Microsoft SQL Server
- Microsoft Windows網絡組件,包括RPC、NetBIOS和CIFS服務
- SMTP、POP3和IMAP電子郵件服務
- 提供安全入站網絡訪問的IP服務,包括IPsec、Microsoft PPTP和SSL VPN
- Linux、Solaris、IRIX和其他平台上的Unix RPC服務
- 黑客工具和腳本利用的各種應用層漏洞

評估是任何組織應該採取的第一步,以正確開始管理信息風險。《網絡安全評估》根據CESG CHECK和NSA IAM政府標準的技術,為您提供了一種準確的方法來做到這一點。