Showing posts with label cryptography. Show all posts
Showing posts with label cryptography. Show all posts

4/27/2012

SSL and TLS: Designing and Building Secure Systems Review

SSL and TLS: Designing and Building Secure Systems
Average Reviews:

(More customer reviews)
As one of the three co-designers of SSL v3, I highly recommend this book -- it's the best book I've seen on SSL/TLS. Eric knows the protocol inside and out and does an excellent job of explaining both the practice and theory of SSL and TLS. The book also includes includes lots of practical information that isn't in the spec about how things are actually done and does a great job explaining the underlying cryptography and security.

Click Here to see more reviews about: SSL and TLS: Designing and Building Secure Systems

Secure Sockets Layer (SSL) is used in virtually every commercial web browser and server. In this book, one of the world's leading network security experts explains how SSL works -- and gives implementers step-by-step guidance and proven design patterns for building secure systems with SSL. Eric Rescorla also provides the first in-depth introduction to Transport Layer Security (TLS), the highly anticipated, maximum-security successor to SSL. Rescorla starts by introducing SSL's fundamentals: how it works, and the threats it is intended to address. One step at a time, he addresses each key SSL concept and technique, including cryptography, SSL performance optimization, designing and coding, and how to work around SSL's limitations. Rescorla demonstrates TLS at work in SMTP-based Internet security applications. The book includes detailed examples of SSL/TLS implementations, with in-depth insight into the key design choices that informed them. For all network and security designers, enterprise developers, system implementers, and suppliers of Internet security products and services.

Buy NowGet 29% OFF

Click here for more information about SSL and TLS: Designing and Building Secure Systems

Read More...

2/23/2012

Cryptography : Theory and Practice Review

Cryptography : Theory and Practice
Average Reviews:

(More customer reviews)
As other people have pointed out, this is not a mathematics book, and it is not an algorithm (recipies) book. It could be a great book for people that are interested in learning these tools to actually use them, either in a research or product development context (something besides homework). Unfortunately, the number of typos, in key mathematical expressions AND PORTIONS OF THE EXPLANATIONS is staggering. Go to the author's web page and you will find that some chapters, like 4 for example, average more than one typo per page (and some of these 'typos' are full sentences, or math expressions that do not look like anything that is actually printed on the page). If you do not have that errata sheet handy, you will waste a lot of time trying to understand the text, or trying to solve the exercises. If you are trying to learn from this book, without attending a class and without the errata, you will simply give up. It is a real shame because it has all the makings of a great book.

Click Here to see more reviews about: Cryptography : Theory and Practice



Buy Now

Click here for more information about Cryptography : Theory and Practice

Read More...

2/11/2012

CISSP Certification All-in-One Exam Guide, Fourth Edition (Cissp All-In-One Exam Guide) Review

CISSP Certification All-in-One Exam Guide, Fourth Edition (Cissp All-In-One Exam Guide)
Average Reviews:

(More customer reviews)
Not sure why this book is so highly rated. Having taken (and passed) the CISSP several years ago, I need to retake this exam and bought three books for review and study purposes. I have a previous version of the Harris book and it is ~900 pages. This new version is 1100+ pages, but seems to be filled more with fluff and some of the actually useful knowledge has been removed! One example which stands out is the removal of the effectiveness and acceptance charts for biometrics methods. This is an important concept and it is entirely ignored in this version. Other things have been changed to no real benefit. The CIA triad (as is the de-facto acronym, even in her previous book) has been renamed to the ICA triad. There is no reason for this.
Finally, the entire book is written in a dumbed-down, cutesy fashion in an attempt (I believe) to make the book more approachable. All it has done, IMO, has increased the number of pages, possibly forcing out relevant materials.
I will pass this test, but it won't be because of this book. Buy the ISC book and the Krutz book (and/or a previous version of the Harris book) - you will not be disappointed.
UPDATE: ok, took the test in Sept and passed. I won't turn this into a test review as this is about the book, but when you buy a certification book, your primary requirement is that the book will be timely and relevant to the test material. The 4th Edition Harris book does just that. ISC has made significant changes to both the content and nature of the test (in large part to keep its test current on security trends and to satisfy a larger target audience) and Shon has captured those changes very well. So, having said all that, it is my revised opinion that this book is more than adequate for passing the test (although it is still filled with fluff.) If I could change the review, I would probably give it 4 stars at this point. The ISC book and the Krutz book are both excellent references to actually apply the knowledge in a meaningful way, however if you just want to pass the test, the Harris book will serve you well.

Click Here to see more reviews about: CISSP Certification All-in-One Exam Guide, Fourth Edition (Cissp All-In-One Exam Guide)


All-in-One is All You Need

Fully revised for the latest exam release, this authoritative volume offers thorough coverage of all the material on the Certified Information Systems Security Professional (CISSP) exam. Written by a renowned security expert and CISSP, this guide features complete details on all 10 exam domains developed by the International Information Systems Security Certification Consortium (ISC²). Inside, you'll find learning objectives at the beginning of each chapter, exam tips, practice questions, and in-depth explanations. CISSP All-in-One Exam Guide, Fourth Edition will not only help you pass the test, but also be your essential on-the-job reference.

Covers all 10 subject areas on the exam:

Access control
Application security
Business continuity and disaster recovery planning
Cryptography
Information security and risk management
Legal, regulations, compliance, and investigations
Operations security
Physical (environmental) security
Security architecture and design
Telecommunications and network security

The CD-ROM features:

Simulated exam with practice questions and answers
Video training from the author
Complete electronic book


Buy Now

Click here for more information about CISSP Certification All-in-One Exam Guide, Fourth Edition (Cissp All-In-One Exam Guide)

Read More...

2/10/2012

Information Security : Principles and Practice Review

Information Security : Principles and Practice
Average Reviews:

(More customer reviews)
This text is an excellent introduction to the popular, important subjects of computer and network security, and is the best such text that I have yet seen. Professor Stamp offers clarity of presentation and a fluid, conversational style. There is an nice balance between comprehensive coverage and detailed analysis. Overall, I really like the structural organization, selection of topics, breadth of coverage, and level of difficulty. No special prerequisites are required to comprehend the basic ideas. However, readers with technical backgrounds will find a lot of material to challenge them. There are an abundance of illustrative figures, nice examples within the body of the text, and a wealth of good problems at the end of each chapter. The author provides excellent references for further study. Appendices delve into details concerning mathematical underpinnings and networking details.
The book is divided into four main parts: cryptography, access control, protocols, and software. The cryptography section introduces fascinating historical vignettes, then explores details of modern block and stream ciphers. The author includes an excellent chapter on cryptanalysis. He provides specific examples, using mathematics and Boolean logic. The access control section explains issues of policy and implementation, regarding authentication and authorization. The protocols section discusses specific mechanisms for secure exchange of confidential information. The final section describes management of software flaws and related security issues.

Click Here to see more reviews about: Information Security : Principles and Practice

Your expert guide to information securityAs businesses and consumers become more dependent on complex multinational information systems, the need to understand and devise sound information security systems has never been greater. This title takes a practical approach to information security by focusing on real-world examples. While not sidestepping the theory, the emphasis is on developing the skills and knowledge that security and information technology students and professionals need to face their challenges. The book is organized around four major themes:* Cryptography: classic cryptosystems, symmetric key cryptography, public key cryptography, hash functions, random numbers, information hiding, and cryptanalysis* Access control: authentication and authorization, password-based security, ACLs and capabilities, multilevel and multilateral security, covert channels and inference control, BLP and Biba's models, firewalls, and intrusion detection systems* Protocols: simple authentication protocols, session keys, perfect forward secrecy, timestamps, SSL, IPSec, Kerberos, and GSM* Software: flaws and malware, buffer overflows, viruses and worms, software reverse engineering, digital rights management, secure software development, and operating systems securityAdditional features include numerous figures and tables to illustrate and clarify complex topics, as well as problems-ranging from basic to challenging-to help readers apply their newly developed skills. A solutions manual and a set of classroom-tested PowerPoint(r) slides will assist instructors in their course development. Students and professors in information technology, computer science, and engineering, and professionals working in the field will find this reference most useful to solve their information security issues.An Instructor's Manual presenting detailed solutions to all the problems in the book is available from the Wiley editorial department.An Instructor Support FTP site is also available.

Buy NowGet 25% OFF

Click here for more information about Information Security : Principles and Practice

Read More...

1/30/2012

E-Commerce Security: Weak Links, Best Defenses Review

E-Commerce Security: Weak Links, Best Defenses
Average Reviews:

(More customer reviews)
The title is ever so slightly misleading in that the topic is not electronic commerce as a whole, but the (admittedly most popular) Web segment of it. However, within this limit, the book does provide solid coverage and good advice for a whole range of issues.
Chapter one is a general introduction to the factors involved, looking at some recent "attacks" of various types, and then reviewing the client, transport, server, and operating system components to be examined in the remainder of the book. Client (generally browser) flaws are covered thoroughly in chapter two. The breadth of coverage even includes mention of topics such as the concern for privacy considerations with cookies. Active content is the major concern, with an excellent discussion of ActiveX (entitled "ActiveX [In]security"), a reasonably detailed review of the Java security model, and a look at JavaScript. Unfortunately, very little of this touches directly on e-commerce as such, except insofar as insecure client technology is going to make e-commerce a harder sell to the general public. While covering the transport of transaction information, in chapter three, Ghosh makes an interesting distinction between stored account systems (where you want to secure the transmission of identification data) and stored value systems (where the data, once transmitted, is useless to an eavesdropper). Many books concentrate on either channel security or electronic cash systems, so this comparison is instructive.
A server involves multiple programs, and may involve multiple machines. Server security can quickly become complex, and this is quite evident in chapter four. While a great deal of useful and thought-provoking information is presented, the complicated nature of the undertaking works against this chapter. Not all topics are dealt with thoroughly, or as well as the previous material was. Oddly, one issue not covered in depth is the firewall, which is handled very well in chapter five, with operating system problems. Ghosh sets up a classification scheme for OS attacks, illustrated by specific weaknesses in Windows NT and UNIX.
The book ends in chapter six with a call for certification of software, greater attention to security in all forms of software, and, interestingly, for greater use of component software. (From the jacket material, it appears that Ghosh is currently involved in the promotion of component software systems.)
Each chapter ends with a set of references. Unlike all too many books with bibliographies stuff with obscure citations from esoteric journals, the bulk of the material listed is available on the Internet. A separate section lists Web sites used in the text.
The various issues dealt with in the book are explained clearly, and generally present counsel on the best practices for secure online commerce. A compact but comprehensive guide to the current state of electronic transaction security.

Click Here to see more reviews about: E-Commerce Security: Weak Links, Best Defenses



Buy Now

Click here for more information about E-Commerce Security: Weak Links, Best Defenses

Read More...

12/22/2011

CISSP All-in-One Exam Guide, Fifth Edition Review

CISSP All-in-One Exam Guide, Fifth Edition
Average Reviews:

(More customer reviews)
There is no simple formula to prepare for the CISSP certification, and no single resource which can guarantee success on the certification exam since every applicant's background is unique. However, this book (fifth edition) was my only resource in preparing for the exam and I passed on my first attempt (April 24, 2010).
I spent 60+ hours in preparation for the exam... that's 60+ hours of DEDICATED individual study using this book and CD, not 60+ hours spent web surfing during lunch hours or commercial breaks. My recent background is in middle management, with 20 years experience in network architecture and data security, so I already had a firm technical foundation for the test areas dealing with protocols and encryption variations. I also have an MS in Computer Science. Nonetheless, the exam was so broad, with topics covering general principles and concepts, that I could have prepared twice as long and still left the exam with questions about the outcome.
My personal opinion is that formal classroom instruction, through one of the many organizations offering CISSP preparation courses, is a worthwhile companion to Shon Harris' book. A study group is also a good idea. You will not obtain CISSP certification if you take the exam without preparation. This book (fifth edition) was sufficient, but not 100% comprehensive, to prepare me for passing the CISSP test.
Note: Some reviewers do not appreciate Shon's frequent analogies and humor. Most of her analogies helped me internalize the complex topics, but that's my personal learning style. The efforts at humor were generally awful, but every once in a while she was subtle and brilliant enough to make me laugh out loud. Working through Shon's unique writing style was not a problem for me... I actually found it refreshing.

Click Here to see more reviews about: CISSP All-in-One Exam Guide, Fifth Edition

Get complete coverage of the latest release of the Certified Information Systems Security Professional (CISSP) exam inside this comprehensive, fully updated resource. Written by the leading expert in IT security certification and training, this authoritative guide covers all 10 CISSP exam domains developed by the International Information Systems Security Certification Consortium (ISC2). You'll find learning objectives at the beginning of each chapter, exam tips, practice exam questions, and in-depth explanations. Designed to help you pass the CISSP exam with ease, this definitive volume also serves as an essential on-the-job reference.
COVERS ALL 10 CISSP DOMAINS:
Information security and risk management
Access control
Security architecture and design
Physical and environmental security
Telecommunications and network security
Cryptography
Business continuity and disaster recovery planning
Legal regulations, compliance, and investigations
Application security
Operations security

THE CD-ROM FEATURES:
Hundreds of practice exam questions
Video training excerpt from the author
E-book

Shon Harris, CISSP, is a security consultant, a former member of the Information Warfare unit in the Air Force, and a contributing writer to Information Security Magazine and Windows 2000 Magazine. She is the author of the previous editions of this book.

Buy NowGet 49% OFF

Click here for more information about CISSP All-in-One Exam Guide, Fifth Edition

Read More...

12/15/2011

CompTIA Security+ All-in-One Exam Guide, Second Edition (Exam SY0-201) Review

CompTIA Security+ All-in-One Exam Guide, Second Edition (Exam SY0-201)
Average Reviews:

(More customer reviews)
According to CompTIA's website, while not a prerequisite, they recommend that an individual sitting the Security+ exam have "at least two years of on-the-job technical networking experience, with an emphasis on security." They further recommend having the Network+ certification. My review of this book is based on an assumption that the individual using this book either meets these recommendations or, through some other means, has equivalent knowledge and experience.
As the author of an eLearning program that helps prepare people for the Security+ exam, I have considered the Security+ 2008 objectives more than most. This book covers everything you need to know to pass the Security+ exam - assuming you have the fundamentals of networking down. As an example, on page 15 (very early in the book) the authors assume you know what a port is when they say, "A network administrator can, for instance, move a service from its default port to a different port..." There is no explanation as to what a "port" is and, according to CompTIA's recommendations, there need not be.
I've given this as a simple example, but the book is filled with assumptions. It's probably a good thing. The book is nearly 700 pages now; imagine how large it would be if all of the knowledge were provided in this single resource. If you don't meet the recommendations that CompTIA suggests, I would encourage you to get this book along with your choice of a Network+ study guide. Then, even if you don't wish to acquire the Network+ certification, you will have the knowledge you need for the assumed information in this book.
I particularly liked the organization of this book. Part I deals with the theory of security (principles, organizational requirements, legal issues, etc.) and provides a foundation for the rest of the book. Part II deals with confidentiality in quite a bit more depth than is required by the Security+ exam. The coverage is closer to that needed for the CISSP exam. The next two parts, Security in the Infrastructure and Security in Transmission address the security needs for network access, data access and data transfer. The final part, excluding the Appendices, is Part V; here, issues related to operational and administrative security are addressed.
Overall, the information is presented in a sequence that makes it both digestible and memorable. I have to say that, in my opinion, this is the best Security+ book to come along yet.

Click Here to see more reviews about: CompTIA Security+ All-in-One Exam Guide, Second Edition (Exam SY0-201)


A CompTIA Security+ Exam Guide and An On-the-Job Reference--All-in-One

Get complete coverage of all the material included on the CompTIA Security+ exam inside this fully up-to-date, comprehensive resource. Written by network security experts, this authoritative exam guide features learning objectives at the beginning of each chapter, exam tips, practice questions, and in-depth explanations. Designed to help you pass the CompTIA Security+ exam with ease, this definitive volume also serves as an essential on-the-job reference. Get full details on all exam topics, including how to:

Combat viruses, Trojan horses, spyware, logic bombs, and worms

Buy NowGet 46% OFF

Click here for more information about CompTIA Security+ All-in-One Exam Guide, Second Edition (Exam SY0-201)

Read More...

10/11/2011

Core Security Patterns: Best Practices and Strategies for J2EE™, Web Services, and Identity Management Review

Core Security Patterns: Best Practices and Strategies for J2EEâ„¢, Web Services, and Identity Management
Average Reviews:

(More customer reviews)
This is the best book I ever had for Java security. This book talks everything you need to know about java security architecture and how to implement them with patterns. In addition to patterns, the book also recommends security bestpractices considerations for J2EE production, how to do proactive and reactive security assessments using well-defined checklists, security design case-study for portal. Undoubtedly, this book is very easy to understand, good code examples and nicely organized to support the needs of a Java developer. It is highly recommended for anyone wants to get involved with security architecture in J2EE applications and web services. If you are a Java guy..then go for it.

Click Here to see more reviews about: Core Security Patterns: Best Practices and Strategies for J2EE™, Web Services, and Identity Management

Praise for Core Security Patterns
"Java provides the application developer with essential security mechanisms and support in avoiding critical security bugs common in other languages. A language, however, can only go so far. The developer must understand the security requirements of the application and how to use the features Java provides in order to meet those requirements. Core Security Patterns addresses both aspects of security and will be a guide to developers everywhere in creating more secure applications."

--Whitfield Diffie, inventor of Public-Key Cryptography

"A comprehensive book on Security Patterns, which are critical for secure programming."

--Li Gong, former Chief Java Security Architect, Sun Microsystems, and coauthor of Inside Java 2 Platform Security

"As developers of existing applications, or future innovators that will drive the next generation of highly distributed applications, the patterns and best practices outlined in this book will be an important asset to your development efforts."

--Joe Uniejewski, Chief Technology Officer and Senior Vice President, RSA Security, Inc.

"This book makes an important case for taking a proactive approach to security rather than relying on the reactive security approach common in the software industry."

--Judy Lin, Executive Vice President, VeriSign, Inc.

"Core Security Patterns provides a comprehensive patterns-driven approach and methodology for effectively incorporating security into your applications. I recommend that every application developer keep a copy of this indispensable security reference by their side."

--Bill Hamilton, author of ADO.NET Cookbook, ADO.NET in a Nutshell, and NUnit Pocket Reference

"As a trusted advisor, this book will serve as a Java developer™s security handbook, providing applied patterns and design strategies for securing Java applications."

--Shaheen Nasirudheen, CISSP,Senior Technology Officer, JPMorgan Chase

"Like Core J2EE Patterns, this book delivers a proactive and patterns-driven approach for designing end-to-end security in your applications. Leveraging the authors™ strong security experience, they created a must-have book for any designer/developer looking to create secure applications."

--John Crupi, Distinguished Engineer, Sun Microsystems, coauthor of Core J2EE Patterns

Core Security Patterns is the hands-on practitioner™s guide to building robust end-to-end security into J2EE' enterprise applications, Web services, identity management, service provisioning, and personal identification solutions. Written by three leading Java security architects, the patterns-driven approach fully reflects today™s best practices for security in large-scale, industrial-strength applications.

The authors explain the fundamentals of Java application security from the ground up, then introduce a powerful, structured security methodology; a vendor-independent security framework; a detailed assessment checklist; and twenty-three proven security architectural patterns. They walk through several realistic scenarios, covering architecture and implementation and presenting detailed sample code. They demonstrate how to apply cryptographic techniques; obfuscate code; establish secure communication; secure J2ME' applications; authenticate and authorize users; and fortify Web services, enabling single sign-on, effective identity management, and personal identification using Smart Cards and Biometrics.

Core Security Patterns covers all of the following, and more:

What works and what doesn™t: J2EE application-security best practices, and common pitfalls to avoid

Implementing key Java platform security features in real-world applications

Establishing Web Services security using XML Signature, XML Encryption, WS-Security, XKMS, and WS-I Basic security profile

Designing identity management and service provisioning systems using SAML, Liberty, XACML, and SPML

Designing secure personal identification solutions using Smart Cards and Biometrics

Security design methodology, patterns, best practices, reality checks, defensive strategies, and evaluation checklists

End-to-end security architecture case study: architecting, designing, and implementing an end-to-end security solution for large-scale applications


Buy NowGet 37% OFF

Click here for more information about Core Security Patterns: Best Practices and Strategies for J2EE™, Web Services, and Identity Management

Read More...

10/09/2011

Principles of Information Security Review

Principles of Information Security
Average Reviews:

(More customer reviews)
This book does provide a broad overview of the concepts of information security. Whatever good information this book does provide is, to some extent, offset by three problems: First, the book is filled with many, many typographical errors. While reading the book, I constantly found myself going back and trying to determine what the writer meant by many of the mangled sentences (or pieces of sentences) in the book. Second, there are a few errors in information. Finally, there are areas where important explanations or details about concepts are completely omitted. The writers needed to do some additional work and editing to make the book's portrayal of many of the concepts it covers clearer and more comprehensive.
There are plenty of free online resources (NIST's Computer Security Resource Center, for example) that would be better places to learn about information security than this text.

Click Here to see more reviews about: Principles of Information Security

The fourth edition of Principles of Information Security explores the field of information security and assurance with updated content including new innovations in technology and methodologies. Readers will revel in the comprehensive coverage that includes a historical overview of information security, discussions on risk management and security technology, current certification information, and more. The text builds on internationally recognized standards and bodies of knowledge to provide the knowledge and skills students need for their future roles as business decision-makers. Information security in the modern organization is a management issue which technology alone cannot answer; it is a problem that has important economic consequences for which management will be held accountable. Readers can feel confident that they are using a standards-based, content-driven resource to prepare for their work in the field.

Buy NowGet 21% OFF

Click here for more information about Principles of Information Security

Read More...

10/08/2011

Planning for PKI: Best Practices Guide for Deploying Public Key Infrastructure Review

Planning for PKI: Best Practices Guide for Deploying Public Key Infrastructure
Average Reviews:

(More customer reviews)
I have found that an unscientific--albeit effective--way to gauge the success of an idea or technology is to do a search on the subject at Amazon.com and see how many returns you get. For diet, there are well over 15,000 titles. For PKI (public key infrastructure), there are exactly four.
While there are nearly 4,000 times as many books about dieting as there are books about PKI, the similarities between the two subjects are interesting. Both dieting and PKI are often difficult to do right, but when they are done correctly, the positive effects are immense.
In a nutshell, a PKI is a set of technologies that enables users of inherently insecure networks and software applications (i.e., the Internet and browsers) to exchange data and perform transactions securely and privately. In a PKI, each user has a set of cryptographic keys comprised of a public-key and a private-key. A PKI also enables the use of a digital certificate that can be used to identify items such as individual end users, host systems, organizations, and directory services. PKI is based on public key cryptography, which is the most common method used to authenticate the sender of a message, or to encrypt that message.
A PKI establishes digital trust and maintains that level of assurance. In the real world, trust is built through a complex web of social, legal, national, international, and business interactions that may take years or decades to develop. Unfortunately, that same level of trust is much harder to implement in the electronic world.
With that in mind, Planning for PKI: Best Practices Guide for Deploying Public Key Infrastructure provides a thorough technical introduction to the workings of PKI. Those wanting a less technical and more managerial approach should read PKI: Implementing & Managing E-Security by Andrew Nash.
The reason that PKI is so important is that information security is often the most fundamental need for today's businesses and e-commerce sites. There is hardly a Fortune 500 company without some type of external public connection, and given that more than 95% of the hosts on the Internet are running TCP/IP version 4 (with no inherent security), these systems are built and running on an insecure infrastructure. Such a reality is a scary thought.
The book is well organized into six sections. The first three chapters cover the basics and rudiments of security, cryptography, and PKI. Fortunately, the authors accomplish this by page 43. One of my personal gripes against many information security books is that they spend way too much time rehashing security basics, while not getting to the subject title until halfway through the book.
Section Two includes seven chapters detailing the different PKI components, protocols, architectures, and uses of digital certificates. Many of those considering PKI do not always realize that the "I" in PKI is infrastructure. Without a well-thought out and tested architecture and methodology, a PKI is nearly sure to fail. Getting the initial PKI software rolled out is often not an easy endeavor. Getting those pieces to work effectively in a distributed infrastructure takes an immense amount of planning and work. Section Two details ways to ensure that a PKI is well built, so that it does not collapse like a poorly designed building.
Chapter 12, "Policies, Procedures and PKI," is one of the most important chapters in the book, in that a PKI comprises much more than simply its underlying software. The book astutely notes that the technical mechanisms of a PKI are insufficient on their own, as they must be used in combination with a set of procedures to implement a particular corporate security policy.
The need for policy can't be over-emphasized, as it is a critical element in the effective and successful operation of a PKI. A PKI can't be effective unless it is deployed in the context of working policies that govern the use, administration, and management of certificates. In a similar vein, noted security guru Marcus Ranum defines a firewall as "the implementation of your Internet security policy. If you haven't got a security policy, you haven't got a firewall. Instead, you've got a thing that's sort of doing something, but you don't know what it's trying to do because no one has told you what it should do". So, too, with a PKI; if there are no policies to determine its appropriate use, inertia states that it will not be used properly.
Rather than being an abstract and dry guide, Planning for PKI: Best Practices Guide for Deploying Public Key Infrastructure concludes with some real-world examples of PKI rollouts. By learning how the three large PKI projects were implemented, readers can benefit from the lessons learned, so that they will not make the same (often common) mistakes.
Rather than being an abstract academic text, the authors, Russ Housley and Tim Polk, write from years of practical experience. Housley is the Chief Scientist for Spyrus, and Polk is the technical lead for PKI at NIST.
This review of mine originally appeared at ..../articles/2001/0104/0104m/0104m.htm
At a little over 300 pages, Planning for PKI: Best Practices Guide for Deploying Public Key Infrastructure is a valuable reference to the workings of PKI.

Click Here to see more reviews about: Planning for PKI: Best Practices Guide for Deploying Public Key Infrastructure



Buy NowGet 20% OFF

Click here for more information about Planning for PKI: Best Practices Guide for Deploying Public Key Infrastructure

Read More...

8/13/2011

Cryptography and Network Security: Principles and Practice (3rd Edition) Review

Cryptography and Network Security: Principles and Practice (3rd Edition)
Average Reviews:

(More customer reviews)
This book is intended to serve both as a textbook for an academic course of study, and as a self-study and reference guide for practicing professionals. The material has been extended to emphasize encryption and its central position in network protection. The structure and flow have been reorganized with both classroom use and solo instruction in mind, and additional teaching material, such as additional problems, have been added.
Chapter one is an introduction to the topics to be covered. In a practical way it outlines the concerns involved in the phrase computer security, and the priorities occasioned by the networked nature of modern computing. There is also an outline of the chapters and sequence in the rest of the book. While the text does note that cryptographic techniques underlie most of current security technologies this is only done briefly. Examples in the major categories listed would help explain this primary position.
Part one deals with conventional, symmetric, encryption and the various methods of attacking it. Chapter two covers the historical substitution and transposition ciphers. Symmetric block ciphers are discussed in chapter three, illustrated by an explanation of DES (Data Encryption Standard). The additional conventional algorithms of triple DES, IDEA (International Data Encryption Algorithm), and RC5 are reviewed in chapter four. The use of conventional encryption for confidentiality is outlined in chapter five.
Part three looks at public-key encryption and hash functions. Chapter six introduces public-key encryption and its uses in confidentiality, authentication, and key management and exchange. Number theory is the basis of these modern algorithms, so some basic mathematical concepts are outlined in chapter seven. Digital signatures and message authentication is introduced in some detail in chapter eight. The algorithms themselves are explained in chapter nine, including MD5 (Message Digest algorithm), SHA (Secure Hash Algorithm), and others. Protocols using digital signatures are described in chapter ten.
Part three takes this background material and relates its use in security practice. Chapter eleven looks at authentication, concentrating on Kerberos and X.509. The examples of e-mail security systems given in chapter twelve are PGP (Pretty Good Privacy) and S/MIME (Secure/Multipurpose Internet Mail Extension). Security provisions for the Internet Protocol (IP) itself are reviewed in chapter thirteen. Web security, in chapter fourteen, again concentrates on protocol level matters, but also discusses the SET (Secure Electronic Transaction) standard at the application level.
Part four outlines general system security. To the general public the primary concern of security is to deal with intruders and malicious software, so it may seem odd to the uninitiated to find that both of these subjects are lumped together in chapter fifteen. Chapter sixteen finishes off the book with a description of firewalls and the concept of trusted systems that they rely on.
Each chapter ends with a set of recommended readings and problems. Many chapters also have appendices giving additional details of specific topics related to the subject just discussed.

Click Here to see more reviews about: Cryptography and Network Security: Principles and Practice (3rd Edition)

For one-semester, undergraduate/graduate level courses in Cryptography, Computer Security, and Network Security.Best-selling author and four-time winner of the TEXTY award for the best Computer Science and Engineering text, William Stallings provides a practical survey of both the principles and practice of cryptography and network security. This text, which won the 1999 TAA Award for the best computer science and engineering textbook of the year, has been completely updated to reflect the latest developments in the field. It has also been extensively reorganized to provide the optimal sequence for classroom instruction and self-study.

Buy Now

Click here for more information about Cryptography and Network Security: Principles and Practice (3rd Edition)

Read More...

8/10/2011

Network Security Bible Review

Network Security Bible
Average Reviews:

(More customer reviews)
This is a great book; it goes in great detail about security in all aspects of the computer industry. However it lacks one critical aspect, how do I do that? Like all network and computer professionals, I do not know everything, so when you tell me I should do something a certain way I'd hope that you will also tell me how to do it. With this book I found myself saying, maybe they will tell me what to do later, over and over, never happens. If you want to buy a book that's a reference manual, this is the one to get. If you are looking for a "how to" as well as a "what to look for" book, consider looking elsewhere.

Click Here to see more reviews about: Network Security Bible


The comprehensive A-to-Z guide on network security, fully revised and updated

Network security is constantly evolving, and this comprehensive guide has been thoroughly updated to cover the newest developments. If you are responsible for network security, this is the reference you need at your side.
Covering new techniques, technology, and methods for approaching security, it also examines new trends and best practices being used by many organizations. The revised Network Security Bible complements the Cisco Academy course instruction in networking security.
Covers all core areas of network security and how they interrelate
Fully revised to address new techniques, technology, and methods for securing an enterprise worldwide
Examines new trends and best practices in use by organizations to secure their enterprises
Features additional chapters on areas related to data protection/correlation and forensics
Includes cutting-edge topics such as integrated cybersecurity and sections on Security Landscape, with chapters on validating security, data protection, forensics, and attacks and threats

If you need to get up to date or stay current on network security, Network Security Bible, 2nd Edition covers everything you need to know.

Buy NowGet 39% OFF

Click here for more information about Network Security Bible

Read More...