Identity Security for Software Development: Cultivating a security culture through secure coding practices and preparing for AI-powered security and d
暫譯: 軟體開發中的身份安全:透過安全編碼實踐培養安全文化,並為 AI 驅動的安全與防護做好準備

Ma, Aiyan

  • 出版商: BPB Publications
  • 出版日期: 2025-12-03
  • 售價: $1,720
  • 貴賓價: 9.5$1,634
  • 語言: 英文
  • 頁數: 302
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 9365892538
  • ISBN-13: 9789365892536
  • 相關分類: 資訊安全
  • 海外代購書籍(需單獨結帳)

商品描述

As modern infrastructures become increasingly automated, non-human identities, such as service accounts, API tokens, and automation agents, are emerging as critical security assets. Securing these identities is essential to protecting cloud-native environments, automated workflows, and machine-to-machine interactions from breaches, data leaks, and abuse.

This book provides a comprehensive guide to securing NHIs through practical strategies and hands-on demonstrations. Readers will explore the evolution of NHI security, from early machine-to-machine protocols to modern Zero Trust frameworks. Key topics include designing secure service accounts, managing API tokens and certificates, implementing secrets management with tools like HashiCorp Vault, SPRIE, and applying robust security controls such as encryption, access control, monitoring, ZTA, testing, automation, and centralization. To reinforce these concepts, the book presents a hands-on proof of concept (PoC) that demonstrates secure NHI management in an MCP system. Readers will gain insights into automating identity provisioning, ensuring credential hygiene, and integrating security best practices.

By the end of this book, readers will be equipped with the knowledge and skills to build resilient, security-first environments that protect NHIs across dynamic infrastructures.

WHAT YOU WILL LEARN

● Understand the evolution of NHI and best practices for securing service accounts, API tokens, and certificates.

● Implement secure credential storage, rotation, and access control using HashiCorp Vault and Kubernetes Secrets.

● Practical strategies for enforcing Zero Trust Architecture, rate limiting, and allow/block lists to mitigate unauthorized access and abuse.

● Build a functional MCP system that integrates secure identity management, credential hygiene, and automated workflows.

● Explore future-ready strategies like AI-driven threat detection, quantum-resistant algorithms, and dynamic authentication models to secure evolving infrastructures.

WHO THIS BOOK IS FOR

This book targets intermediate to advanced practitioners, security professionals, engineering teams, and technical leadership who must have foundational knowledge of cloud-native, API-driven, and automated infrastructure concepts.

商品描述(中文翻譯)

隨著現代基礎設施越來越自動化,非人類身份(如服務帳戶、API 令牌和自動化代理)正成為關鍵的安全資產。保護這些身份對於防止雲原生環境、自動化工作流程和機器對機器互動遭受違規、數據洩漏和濫用至關重要。

本書提供了一個全面的指南,通過實用策略和實作示範來保護非人類身份(NHI)。讀者將探索 NHI 安全的演變,從早期的機器對機器協議到現代的零信任框架。主要主題包括設計安全的服務帳戶、管理 API 令牌和證書、使用 HashiCorp Vault 等工具實施秘密管理,以及應用強健的安全控制措施,如加密、訪問控制、監控、零信任架構(ZTA)、測試、自動化和集中化。為了加強這些概念,本書提供了一個實作概念驗證(PoC),展示在多雲平台(MCP)系統中安全的 NHI 管理。讀者將獲得自動化身份供應、確保憑證衛生和整合安全最佳實踐的見解。

在本書結束時,讀者將具備建立韌性、安全優先環境的知識和技能,以保護動態基礎設施中的非人類身份。

你將學到的內容:
● 了解 NHI 的演變及保護服務帳戶、API 令牌和證書的最佳實踐。
● 使用 HashiCorp Vault 和 Kubernetes Secrets 實施安全的憑證存儲、輪換和訪問控制。
● 實用策略以強制執行零信任架構、速率限制和允許/阻止清單,以減輕未經授權的訪問和濫用。
● 建立一個功能性多雲平台(MCP)系統,整合安全身份管理、憑證衛生和自動化工作流程。
● 探索未來準備的策略,如 AI 驅動的威脅檢測、抗量子算法和動態身份驗證模型,以保護不斷演變的基礎設施。

本書適合對象:
本書針對中級到高級的從業者、安全專業人士、工程團隊和技術領導者,他們必須具備雲原生、API 驅動和自動化基礎設施概念的基礎知識。