5/04/2012

Securing Storage: A Practical Guide to SAN and NAS Security Review

Securing Storage: A Practical Guide to SAN and NAS Security
Average Reviews:

(More customer reviews)
The theme of this book is that Storage Area Networks and Network Attached Storage have been hitherto neglected with respect to securing their contents against unauthorised use. Dwivedi remarks that most sysadmins focus on maintaining and securing a corporate firewall. Along with regularly patching users' machines plus web servers. A common attitude is that SAN and NAS devices are at the very heart of the corporate network, and often cannot be directly accessed from outside the firewall.
Dwivedi spends the bulk of his book debunking this idea. For one thing, he points out that a SAN or NAS box is a computer that has to run an operating system. Usually linux, unix or Microsoft. A vendor is very unlikely to write a custom operating system from scratch. Too expensive and takes too long to devise. So even if nothing else, you as a sysadmin should regularly patch those boxes if you can, when known bugs are found in their operating systems. These boxes should be no more exempt from patching than your other machines, even those behind the firewall.
Another cause of concern is the sheer mass of data on a SAN or NAS box. Nowadays, likely to be many gigabytes. These are high value targets for an attacker. Whereas a typical user's desktop would have much smaller data sets.
Plus, even with a firewall, there is always the possibility of an employee being an attacker. If she has a machine inside the firewall, then this already gives her a good start. Of course, you might reply that you "lock down" your users' machines, so that they cannot get root access, for example. But the attacker with a Microsoft machine could boot off a Knoppix CD, for example, and go into a linux that sits only in memory, and for which she has root. Suppose now you have a NAS box exporting a file system via NFS to the attacker's machine, which is normally running Microsoft Windows. The author shows how the attacker can from her Knoppix OS mount the NAS file system and by changing her local passwd file, assume any user id and group id that gives her read access (and maybe write access) to any file in the foreign file system.
These are the sort of attacks that you have to guard against. The book offers several chapters at its end describing possible countermeasures. The tone of the book is not alarmist. Rather, Dwivedi matter of factly walks through many attacks; the above being just one case. He shows how using open source code freely available on the net, that an attacker could gleam useful data from your machines.

Click Here to see more reviews about: Securing Storage: A Practical Guide to SAN and NAS Security

The security of data, as shown by several recent high-profile cases, is weak. It is but a question of time before courts begin requiring more thorough steps to be taken--users and courts want data security. This book not only helps IT meet those growing needs, but shows the vendors where they need to improve. Regulations have highlighted an overlying issue of data protection. Data, whether it is financial data, non-public private information, or medical data, needs to be protected from unauthorized external and internal entities at all times. Much valuable data (i.e. customer and patient data) spends most of its lifetime in a storage device--not on computers, servers, or networks. Local failures and outside intruders can change, destroy, or compromise stored data even if the main network is secure: storage requires its own security. This book is a must read for IT personnel responsible for data security and security consultants who perform compliance audits at companies that use storage devices.

Buy NowGet 27% OFF

Click here for more information about Securing Storage: A Practical Guide to SAN and NAS Security

Read More...

SOA Security Review

SOA Security
Average Reviews:

(More customer reviews)
Great book for starters.
However it misses the latest Standards in Security such as PKI, SAML, XACML, WS-Federation, WS-Trust and how it pertains to SOA based solution architecture. So much for a book titled "SOA Security". Also it totally ignores to explain how to ensure security at all integration tiers.
Not for security experts, more for people who are starters and do not have time to "Google" either.
Does not do detailed coverage only basic topics related to Web services security around SOAP and WSDL standards with Apache Axis sample APIs (which are out of box and can be googled easily) are discussed. It is a bit difficult to relate the examples to the meat on the book.
Also missing is the information on how to use the abused Apache API examples to compose/build a Secure SOA service base architecture or how to secure BPM workflows, SOA governance, Identity management using federation, entitlement issues with BPM portals,... the list goes on.
This book contains very repetitive content. The only good portion I found was the chapter on XML Web services. The authors should refer Information Security Management Handbook, Sixth Edition (Isc2 Press) and Core Security Patterns: Best Practices and Strategies for J2EE(TM), Web Services, and Identity Management (Sun Core Series) before the next version comes out.

Click Here to see more reviews about: SOA Security


SOA is one of the latest technologies enterprises are using to tame their software costs - in development, deployment, and management. SOA makes integration easy, helping enterprises not only better utilize their existing investments in applications and infrastructure, but also open up new business opportunities. However, one of the big stumbling blocks in executing SOA is security. This book addresses Security in SOA with detailed examples illustrating the theory, industry standards and best practices.

It is true that security is important in any system. SOA brings in additional security concerns as well rising out of the very openness that makes it attractive. If we apply security principles blindly, we shut ourselves of the benefits of SOA. Therefore, we need to understand which security models and techniques are right for SOA. This book provides such an understanding.

Usually, security is seen as an esoteric topic that is better left to experts. While it is true that security requires expert attention, everybody, including software developers, designers, architects, IT administrators and managers need to do tasks that require very good understanding of security topics. Fortunately, traditional security techniques have been around long enough for people to understand and apply them in practice. This, however, is not the case with SOA Security.

Anyone seeking to implement SOA Security is today forced to dig through a maze of inter-dependent specifications and API docs that assume a lot of prior experience on the part of readers. Getting started on a project is hence proving to be a huge challenge to practitioners. This book seeks to change that. It provides bottom-up understanding of security techniques appropriate for use in SOA without assuming any prior familiarity with security topics on the part of the reader.

Unlike most other books about SOA that merely describe the standards, this book helps you get started immediately by walking you through sample code that illustrates how real life problems can be solved using the techniques and best practices described in standards. Whereas standards discuss all possible variations of each security technique, this book focusses on the 20% of variations that are used 80% of the time. This keeps the material covered in the book simple as well as self-sufficient for all readers except the most advanced.


Buy NowGet 36% OFF

Click here for more information about SOA Security

Read More...

5/03/2012

Sacred Trust: The Ten Rules of Life, Death, and Medicine Review

Sacred Trust: The Ten Rules of Life, Death, and Medicine
Average Reviews:

(More customer reviews)
This is a marvelous work. All physicians should read it, and lots of patients should, too. The anecdotes will stay with you long after you put it down, and if you're not a physician, you'll expect more of your doctors after you read Dr. Hollenbeck's lovely little book. It's full of medical wisdom, but practical wisdom, too, in the form of Dr. Hollenbeck's mother's Irish sayings. Just a complete pleasure to read! I enjoyed every page.

Click Here to see more reviews about: Sacred Trust: The Ten Rules of Life, Death, and Medicine



Buy Now

Click here for more information about Sacred Trust: The Ten Rules of Life, Death, and Medicine

Read More...

5/02/2012

The Official Student Doctor Network MCAT Pearls: A high-yield review of the pre-medical sciences Review

The Official Student Doctor Network MCAT Pearls: A high-yield review of the pre-medical sciences
Average Reviews:

(More customer reviews)
This note book is good. I recommend it to anyone who is sitting for MCAT. I had made my own notes before buying this book. I am supprised to learn that this book has touched all important MCAT topics sincerely. I commend the the author for coming up with these notes. On the other hand, I do suggest that this (material in the book)is just the base on which one has to build for MCAT. As author's friend said, practice....... the questions. Works for me.

Click Here to see more reviews about: The Official Student Doctor Network MCAT Pearls: A high-yield review of the pre-medical sciences

The Official Student Doctor Network MCAT Pearls is a grassroots effort to provide aspiring physicians with an affordable alternative to prepare for the MCAT. With the free, online version attracting over 150,000 visitors, the print version of MCAT Pearls will provide students with a portable version of the successful online content. Written using the AAMC MCAT curriculum as its main foundation, MCAT Pearls will function as the ultimate companion guide by following pre-medical students from the beginning of their studies and evolving into the ultimate, personalized resource and go-to study guide when preparing for the MCAT. The structure of the book was designed for busy pre-meds: with a question and answer format, high-yield review is possible alone or in groups. With ample margins for note-taking, MCAT Pearls will invariably evolve into your personalized resource. With a comprehensive table of contents, locating information is simple. With 300+ images and 100+ tables, information is crystallized into the pertinent concepts. Unique also to The Official Student Doctor Network MCAT Pearls is the emphasis on providing students with a flexible platform to pull together the voluminous amount of information represented on the MCAT: one which can be used early in their studies and grow into custom tailored study guide, or, one that can be used in last minute review sessions. After years of development, The Official Student Doctor Network MCAT Pearls has come a long way and will continue to strive to meet the educational needs of pre-meds.

Buy Now

Click here for more information about The Official Student Doctor Network MCAT Pearls: A high-yield review of the pre-medical sciences

Read More...

SNMP MIB Handbook Review

SNMP MIB Handbook
Average Reviews:

(More customer reviews)
Let me start simple: I'm neither a book author nor a professional "reviewer".
The only reason for this review -- and yes, this is my very first one -- is that I'm truly impressed with "SNMP MIB Handbook". Let me try to explain how did I happen to find it -- and why do I consider it "The Bible of MIB Design".
My recent task was (well, still is :)) to design an architecture for Enterprise Infrastructure Management, where the term "Infrastructure" is broad and a little bit vague (or should I say: "yet to be defined"? :)) -- but at the very least it includes hardware, software and essential business processes. SNMP, by no surprise, is one of several "ways to go" -- so I decided to refresh my SNMP knowledge.
After reading some introductory tutorials and not-so-introductory books, it occurred to me that something is missing, while 80% of information is "covered" again and again. Everybody talks about familiar subject: SNMP history, the fact that SNMP is based on UDP -- and how it is encapsulated; differences between SNMPv1, SNMPv2c and SNMPv3, the internal format of different types of SNMP messages, what is MIB, the concept of TRAP (notification), how to configure and use various commercial or freeware SNMP tools, etc.
What's missing then? Here is the short answer: nobody tells you how to DESIGN *your* MIB.
Let me make an analogy: there are plenty books on English Grammar; there are also quite a few on different reading "techniques". But how many books will teach you writing? Not writing in general, but writing *good prose* or *nice poems*? There you are!
Does it matter? Well, as usual, it depends. If your job is to *use* already existing MIBs -- that's one thing. But what if you have to *create* (i.e. design and implement) a MIB of your own -- the one that *others* will have to use? How would you do that? Where to start? What to cover - and what to omit? What are current design practices? What are the most typical mistakes?
Try to "google" on a topic of MIB design -- you'd be surprised with the results.
That being said, what's so special about this book?
It has answers to all of the questions above -- and goes far beyond.
Without further ado let me provide brief highlights about what I like most:
-- Not only it teaches you SMI (v1 and v2) syntax but also tells *how to read* MIBs, how to tell whether a particular MIB is good or not - and why;
-- While most other SNMP books fall short on advanced MIB objects (telling you about MIB tables at most), this one goes deep into the world of complex MIBs: you'll know about tables with multiple INDEX objects (and about different types of INDEX objects themselves), about row-create tables (and different scenarios of using them), about object identifier POINTERS, INDEX pointers, etc.
-- MIB Design Patterns: this part alone justifies the price! All-in-One vs. Product-specific MIBs; why SMI registration MIBs are important (and what to put inside); how to design TRAPs *properly* (different models for TRAP design, best practices, typical mistakes, consequences for end-users (e.g.: network engineers)); what objects are essential for Enterprise MIB design; how to *partition* you MIB properly (for example, how to model Product Options, how to account for future versions of the Product, how to model new/modified/deprecated functionality of the Product, the importance of state information -- and the difference between dynamic and static state info). And on top of that the book provides real-world *full* Enterprise-level MIB examples -- to read and learn from!
-- References (Appendix A) are really useful. Ever tried to figure out what RFCs define SNMPv3 (and what are *current* ones)? What SNMP Validation compilers are available? Where to look for various Enterprise MIBs?
-- Did I mention short quiz-type exercises after each chapter? You'll have a chance to grade yourself: Appendix F has correct answers.
To sum it up: this book is brilliantly written, easy to read and comprehend -- and *incredibly* useful.
It fills-in an important gap in today's SNMP literature: MIB Design Patterns and Practices.
Second to none, it establishes a Gold Standard on the subject -- for years to come.


Click Here to see more reviews about: SNMP MIB Handbook

Essential Guide to SNMP MIB Development, Use, and Diagnosis. The Simple Network Management Protocol (SNMP) allows Managers (software) to communicate with Agents (also software) on network-managed devices, to collect status, for configuration and control, and to receive unsolicited events (traps). A MIB (Management Information Base) is a file containing syntax defining data objects to be managed and traps to be sent. MIB objects and their values are the focus of the protocol. Simplicity of SNMP is the reason for its initial and continued success -- simple MIB objects define information sent using a simple message set. Yet it is flexible and scalable, used to manage small networks as well as large, distributed networks. This handbook is intended for developers (MIB and agent designers) and end-users (network engineers and IT-management specialists). It serves as an instructional manual and as a reference, and contains case descriptions, examples, practical advice, clear descriptions of standards, user exercises and quiz questions. It is an important book for anyone involved with SNMP, suitable for those new to the protocol as well as for experienced practitioners.

Buy NowGet 37% OFF

Click here for more information about SNMP MIB Handbook

Read More...

5/01/2012

Computer Security: Art and Science Review

Computer Security: Art and Science
Average Reviews:

(More customer reviews)
Please understand that the Amazon star system, while very powerful has limits, I feel this book is 5 stars as a textbook for an undergrad computer security course, 4 stars for a graduate student and 3 stars for a book on the average information security worker's shelf.
Computer Security Art and Science has been years in the making and for good reason; it is over a thousand pages. The book seems best suited for four groups of readers. The first group is college students; this will probably be a popular choice as a textbook for undergraduate level students and with additional materials, graduate level students. It is a complete guide to computer security terminology and theory. Other groups of readers that would benefit from this book include security knowledgeable managers seeking to assess the knowledge of potential employees especially in policy and architecture positions. A third group includes anyone preparing for information security certifications. If you are wish to certify you will benefit from a close reading of this text before attempting your examination. Finally, anyone seeking to understand the big picture of information security would benefit from Computer Security Art and Science. However the book's value is primarily as a textbook!
Like most authors writing a security book, Matt has chosen to start at a basic level beginning with a discussion of confidentiality, integrity and availability. As a reviewer I was quietly wondering how long he would stay there. The answer proved to be one chapter only and at the back of the chapter one the author has included insightful, thought provoking study questions. If I were considering hiring someone who claimed to have experience in information security that could not answer these questions, I would show them the door.
Now to consider the rest of the book! On the first page of chapter two we are introduced to logical equations. This is where the casual reader is likely to get off the bus while the diligent student with a qualified instructor gets on. As soon as I saw the equations with no explanation of how to read them, I could see someone browsing in a bookstore shut the cover and move on. Be brave and press on is my advice; the book is well worth it even if some of the illustrations are beyond comprehension without a teacher's guide. It says in the preface this book was designed to be a college level textbook. They have to put a few inscrutable pages in the book so the professors can appear to be smarter than the students.
The cryptography section, chapters 9 - 11 are very approachable and while not as in depth as some other sections, they would help anyone preparing for the various industry security certifications including CompTIA's Security +, ISC2's CISSP and SANS' GSEC. In fact the entire book would be beneficial for any of these.
The table of contents says that part 6 of the book, assurance, chapters 18 - 21, were contributed by a different author, Elisabeth Sullivan. I read those chapters closely and could not detect a different tone or level of quality; the authors are to be congratulated for that. Nice use of humor on the heading title for 18.1.1, "The Need for Assurance" and where else can you read about "Extreme Programming".
No book is perfect, the intrusion detection and penetration testing discussions need to be beefed up, but chapter 29, Program Security more than makes up for them. That chapter should be required reading before anyone is allowed to touch a compiler.
I donate most of the books people send me to review to my local library, but this one stays on the shelf and I am setting an iCal reminder to re-read the policy and audit sections a couple months from now.

Click Here to see more reviews about: Computer Security: Art and Science



Buy NowGet 28% OFF

Click here for more information about Computer Security: Art and Science

Read More...

Windows Server 2008 Security Resource Kit (PRO - Resource Kit) Review

Windows Server 2008 Security Resource Kit (PRO - Resource Kit)
Average Reviews:

(More customer reviews)
Full Disclosure: I wrote the small business chapter.
To Peter who was disappointed because he wanted to see "real world templates for use in his firm". Once upon a time I was just like you and I went and volunteered in a standard setting body to find that magical elixar of a cookie cutter template that would secure me. I found that there isn't a magical button, nor is there a template that I can just magically deploy. No one knows my network but me. Therefore no one but me can secure it.
Remember Dorothy and how she had the power to go home all along but had to learn it? Same thing here. I can't give you the security template that fits my network because it's based on my needs, my risk, my business. It won't fit your needs, your business, your risk.
Each network is unique. So for those of you disappointed in the fact that this doesn't have a slam it down your network and magically it's secure template, be disappointed in yourself first.
You have to determine your own risk, and then you start tweaking and seeing what breaks. Notch the security back for that part, see if you are comfortable with that.

Click Here to see more reviews about: Windows Server 2008 Security Resource Kit (PRO - Resource Kit)



Buy NowGet 23% OFF

Click here for more information about Windows Server 2008 Security Resource Kit (PRO - Resource Kit)

Read More...