Engineering Security

简介:
作为一个行业,我们几十年来一直在努力构建安全的系统,特别是在过去的十五年里,互联网渗透到日常生活中,计算机化设备和系统的使用越来越多,使得攻击的范围和规模前所未有。在所有的时间里,我们已经收集了相当多的洞察力,什么是有效的,什么是无效的。就像罗斯·安德森 (Ross Anderson) 的优秀书籍《安全工程》 (Security Engineering) 一样,这本书讨论了传统安全书籍通常不会做的所有事情: 安全 (或更准确地说,据称是安全的) 系统的问题故事,当它们受到攻击时,结果并不那么安全。
它还花了相当多的篇幅来讨论为什么一些被提出来作为各种问题的解决方案的机制和系统实际上并不能解决它们,在某些情况下根本不能真正解决任何问题 (使用本书中多次提到的一个短语,他们不防御攻击者正在做的任何事情)。
英文简介:
As an industry, we’ve been trying to build secure systems for many decades now, particularly in the last fifteen years or so as a combination of the penetration of the Internet into everyday life and the increasing use of computerised devices and systems has enabled attacks at a scope and scale never before possible. In all of that time, we’ve gathered quite a bit of insight into what works and what doesn’t. Like Ross Anderson’s excellent book Security Engineering, this book talks about all of the things that conventional security books usually don’t: Stories of problems with secure (or, to be more accurate, allegedly secure) systems that turned out to be not so secure when they were exposed to attack.
It also devotes quite a bit of space to discussing why some mechanisms and systems that have been proposed as solutions to various problems don’t actually solve them, and in some cases don’t really solve any problem at all (to use a phrase that comes up several times in this book, they don’t defend against anything that attackers are doing).
- 书名
- Engineering Security
- 译名
- 工程安全
- 语言
- 英语
- 年份
- 2014
- 页数
- 814页
- 大小
- 11.37 MB
- 下载
Engineering Security.pdf
- 密码
- 65536
最后更新:2025-04-12 23:58:09