ModSecurity Handbook (Paperback)
暫譯: ModSecurity 手冊 (平裝本)

Ivan Ristic

  • 出版商: Feisty Duck
  • 出版日期: 2010-03-15
  • 售價: $1,991
  • 貴賓價: 9.8$1,951
  • 語言: 英文
  • 頁數: 384
  • 裝訂: Paperback
  • ISBN: 1907117024
  • ISBN-13: 9781907117022
  • 相關分類: Penetration-test
  • 無法訂購

相關主題

商品描述

PRODUCT DESCRIPTION ModSecurity Handbook is the definitive guide to ModSecurity, a popular open source web application firewall. Written by Ivan Ristic, who designed and wrote much of ModSecurity, this book will teach you everything you need to know to monitor the activity on your web sites and protect them from attack. Situated between your web sites and the world, web application firewalls provide an additional security layer, monitoring everything that comes in and everything that goes out. They enable you to perform many advanced activities, such as real-time application security monitoring, access control, virtual patching, HTTP traffic logging, continuous passive security assessment, and web application hardening. They can be very effective in preventing application security attacks, such as cross-site scripting, SQL injection, remote file inclusion, and others. Considering that most web sites today suffer from one problem or another, ModSecurity Handbook will help anyone who has a web site to run. The topics covered include: - Installation and configuration of ModSecurity - Logging of complete HTTP traffic - Rule writing, in detail - IP address, session, and user tracking - Session management hardening - Whitelisting, blacklisting, and IP reputation management - Advanced blocking strategies - Integration with other Apache modules - Working with rule sets - Virtual patching - Performance considerations - Content injection - XML inspection - Writing rules in Lua - Extending ModSecurity in C The book is suitable for all reader levels: it contains step-by-step installation and configuration instructions for those just starting out, as well as detailed explanations of the internals and discussion of advanced techniques for seasoned users. The official ModSecurity Reference Manual is included in the second part of the book. A digital version is available. For more information and to access the online companion, go to www.modsecurityhandbook.com ABOUT THE AUTHOR Ivan Ristic is a respected security expert and author, known especially for his contribution to the web application firewall field and the development of ModSecurity, the open source web application firewall. He is also the author of Apache Security, a comprehensive security guide for the Apache web server. A frequent speaker at computer security conferences, Ivan is an active participant in the application security community, a member of the Open Web Application Security Project, and an officer of the Web Application Security Consortium.

商品描述(中文翻譯)

產品描述
《ModSecurity 手冊》是關於 ModSecurity 的權威指南,ModSecurity 是一個流行的開源網路應用程式防火牆。這本書由 Ivan Ristic 撰寫,他設計並編寫了大部分的 ModSecurity,將教您所有需要知道的知識,以監控您的網站活動並保護它們免受攻擊。

網路應用程式防火牆位於您的網站與外界之間,提供額外的安全層,監控所有進入和離開的流量。它們使您能夠執行許多高級活動,例如即時應用程式安全監控、存取控制、虛擬修補、HTTP 流量日誌記錄、持續被動安全評估和網路應用程式加固。它們在防止應用程式安全攻擊方面非常有效,例如跨站腳本攻擊(cross-site scripting)、SQL 注入(SQL injection)、遠端檔案包含(remote file inclusion)等。

考慮到當今大多數網站都面臨某種問題,《ModSecurity 手冊》將幫助任何擁有網站的人。涵蓋的主題包括:
- ModSecurity 的安裝與配置
- 完整 HTTP 流量的日誌記錄
- 詳細的規則編寫
- IP 地址、會話和用戶追蹤
- 會話管理加固
- 白名單、黑名單和 IP 信譽管理
- 高級阻擋策略
- 與其他 Apache 模組的整合
- 使用規則集
- 虛擬修補
- 性能考量
- 內容注入
- XML 檢查
- 使用 Lua 編寫規則
- 在 C 中擴展 ModSecurity

本書適合所有讀者層級:對於剛入門的人,包含逐步的安裝和配置說明;對於經驗豐富的用戶,則提供詳細的內部解釋和高級技術的討論。官方的 ModSecurity 參考手冊包含在本書的第二部分。

數位版本可用。如需更多資訊及訪問線上伴隨資源,請前往 www.modsecurityhandbook.com

關於作者
Ivan Ristic 是一位受人尊敬的安全專家和作者,特別以其對網路應用程式防火牆領域和 ModSecurity 開源網路應用程式防火牆的貢獻而聞名。他也是《Apache Security》的作者,這是一本針對 Apache 網路伺服器的綜合安全指南。Ivan 經常在電腦安全會議上發表演講,並積極參與應用程式安全社群,是開放網路應用程式安全專案(Open Web Application Security Project)的成員,以及網路應用程式安全聯盟(Web Application Security Consortium)的官員。