Insider Threat: Protecting the Enterprise from Sabotage, Spying, and Theft
暫譯: 內部威脅:保護企業免受破壞、間諜行為和盜竊
Eric Cole, Sandra Ring
- 出版商: Syngress Media
- 出版日期: 2006-03-01
- 售價: $1,490
- 貴賓價: 9.5 折 $1,416
- 語言: 英文
- 頁數: 350
- 裝訂: Paperback
- ISBN: 1597490482
- ISBN-13: 9781597490481
已過版
相關主題
商品描述
Description:
As network defense perimeters get stronger and stronger; IT, security, law enforcement, and intelligence professionals are realizing that the greatest threats to their networks are increasingly coming from within their own organizations. These insiders, comprised of current and former employees or contractors, can use their inside knowledge of a target network to carry out acts of sabotage, espionage, and theft of data. This book will teach IT professional and law enforcement officials about the dangers posed by insiders to their IT infrastructure and how to mitigate these risks by designing and implementing secure IT systems as well as security and human resource policies. The book will begin by identifying the types of insiders who are most likely to pose a threat. Next, the reader will learn about the variety of tools and attacks used by insiders to commit their crimes including: encryption, steganography, and social engineering. The book will then specifically address the dangers faced by corporations and government agencies. Finally, the reader will learn how to design effective security systems to prevent insider attacks and how to investigate insider security breeches that do occur. Throughout the book, the authors will use their backgrounds in the CIA to analyze several, high-profile cases involving insider threats.
商品描述(中文翻譯)
描述:
隨著網路防禦邊界越來越強大,資訊科技(IT)、安全、執法和情報專業人員逐漸意識到,對其網路的最大威脅越來越來自於他們自己組織內部。這些內部人員,包括現任和前任員工或承包商,能夠利用他們對目標網路的內部知識來進行破壞、間諜活動和數據盜竊。本書將教導IT專業人員和執法官員有關內部人員對其IT基礎設施所構成的危險,以及如何通過設計和實施安全的IT系統以及安全和人力資源政策來減輕這些風險。本書將首先識別最有可能構成威脅的內部人員類型。接下來,讀者將了解內部人員用來犯罪的各種工具和攻擊,包括:加密、隱寫術和社會工程。然後,本書將具體討論企業和政府機構面臨的危險。最後,讀者將學習如何設計有效的安全系統以防止內部攻擊,以及如何調查已發生的內部安全漏洞。在整本書中,作者將利用他們在CIA的背景來分析幾個涉及內部威脅的高調案例。