Introduction to Computer Security..

Author: (USA) Bishop, M.
Publisher:
Publish Date: 2005-11-01
Features: In this authoritative textbook, author Matt Bishop provides readers with valuable information about information security technologies. With Bishop's deep understanding of information security and real-world examples, this book will help security professionals and students understand the relationship between security theory and the increasingly challenging security issues in today's IT environment. In this book, the author elaborates on the foundation of information security—various types of widely used security policies; the security mechanisms for implementing these policies; security principles under policies and mechanisms; how attackers exploit tools to carry out attacks; and how to defend these attacks. Each chapter's exercises focus on how to apply these policies and mechanisms to real-world corporate environments. The main content of the book includes: confidentiality, integrity, and availability; operational issues, cost-benefit analysis, and risk analysis, legal factors, and human factors; planning and implementing effective access control; defining security policies, confidentiality policies, and integrity policies; utilizing cryptography and public key systems, recognizing their limitations; security design principles: Principle of Least Privilege, Principle of Fail-safe Defaults, Principle of Open Design, Principle of Mechanism Simplicity, etc.; understanding and using authentication mechanisms from passwords to biometrics; utilizing system and network controls to manage information flow; ensuring security throughout the entire system lifecycle; methods for defending against Trojans, boot sector viruses, executable viruses, rabbits, bacteria, logic bombs, etc.; vulnerability analysis, penetration testing,, intrusion detection, and protection; applying security principles to networks, systems, users, and programs. This book is an authoritative textbook that comprehensively and systematically introduces the fundamental principles and application technologies of computer security. The entire book consists of 29 chapters, primarily exploring the basic and common issues in the field of computer security. In addition to briefly introducing cryptographic theory, it provides a detailed explanation of non-cryptographic security mechanisms, including security design principles, identity expression, access control mechanisms, and information flow control. Additionally, it introduces the principles and technologies of malicious code, vulnerability analysis, system auditing, and intrusion detection in a thematic format. The book also offers a relatively in-depth discussion of security policy models and security assurance systems, such as various security models, the construction of trusted systems, and the theory and technology of evaluating secure systems. This book can serve as a textbook for graduate students and senior undergraduate students and can also be referenced by professionals in the fields of information security, computer science, and communications.

📌 Related Posts