The Effects of Cyber Supply Chain Attacks and Mitigation Strategies
暫譯: 網路供應鏈攻擊的影響與緩解策略
Das, Ravi
- 出版商: CRC
- 出版日期: 2025-06-29
- 售價: $2,230
- 貴賓價: 9.5 折 $2,119
- 語言: 英文
- 頁數: 122
- 裝訂: Hardcover - also called cloth, retail trade, or trade
- ISBN: 1032955317
- ISBN-13: 9781032955315
海外代購書籍(需單獨結帳)
相關主題
商品描述
The world about a week ago witnessed what is probably the largest Cyber Supply Chain Attack ever known to humankind. The magnitude of this attack only merely underscores the sheer level of interconnectivity that exists today. Because of this, the chances of this happening many more times is very high. For instance, all it takes is just one weakness, vulnerability, or a backdoor for the Cyberattacker to exploit, and from there, deploy the malicious payload which will then be sent to thousands of victims worldwide.
This book will focus not only upon the two previous Supply Chain Attacks have recently happened, but it will also focus upon the Critical Infrastructure here in the United States. This includes the food supply chain, the water supply system the national power grid, and even the nuclear power facilities. Many of these establishments have been built with technology that was developed in the late 1960s and the early 1970s. Many of the vendors that built these technologies are now, for the most part, no longer in existence. Many of these are ICS and SCADA systems, and as a result, they also have many vulnerabilities from which a Cyberattacker can penetrate into a launch malicious payload, which will result in yet another form of a Cyber Supply Chain Attack.
Therefore, this book will focus upon the following:
*A Review Of the Critical Infrastructure of the United States
*A Review Of the Solar Winds Supply Chain Attack
*A Review As To How A Malicious Payload Can Created And Inserted, using SQL Injection Attacks as the primary example.
*A Critical Examination As To How Supply Chain Attacks Can Be Mitigated.
商品描述(中文翻譯)
這個世界大約一週前目睹了人類歷史上可能最大的網路供應鏈攻擊。這次攻擊的規模僅僅突顯了當今存在的高度互聯性。因此,這種事件再次發生的機率非常高。例如,只需要一個弱點、漏洞或後門,網路攻擊者就能利用這些進行攻擊,然後部署惡意載荷,這些載荷將被發送到全球數千名受害者手中。
本書將不僅專注於最近發生的兩起供應鏈攻擊,還將關注美國的關鍵基礎設施。這包括食品供應鏈、水供應系統、國家電網,甚至核電設施。許多這些設施是使用1960年代末和1970年代初開發的技術建造的。許多建造這些技術的供應商現在大多已經不存在。這些系統多為ICS和SCADA系統,因此它們也存在許多漏洞,網路攻擊者可以利用這些漏洞進入並發動惡意載荷,這將導致另一種形式的網路供應鏈攻擊。
因此,本書將專注於以下內容:
* 美國關鍵基礎設施的回顧
* SolarWinds供應鏈攻擊的回顧
* 如何創建和插入惡意載荷的回顧,以SQL注入攻擊作為主要範例
* 對供應鏈攻擊的緩解措施進行關鍵性檢討
作者簡介
I am currently a Cyber Technical Engineering Writer for a large IT Services Provider. I also do Cybersecurity Consulting through my private practice, ML Tech, Inc. I also hold the Certified In Cybersecurity Certification from the ISC(2).
I have published 18 books through CRC Press. I have recently signed a contract for a 19th book manuscript.
作者簡介(中文翻譯)
我目前是一家大型IT服務提供商的網路技術工程作家。我也透過我的私人公司ML Tech, Inc.提供網路安全諮詢。我持有ISC(2)頒發的網路安全認證(Certified In Cybersecurity Certification)。
我已經通過CRC Press出版了18本書,最近簽署了一本第19本書稿的合約。