{"title":"Network security Books","description":"","products":[{"product_id":"wireless-and-mobile-device-security-9781284211726","title":"Wireless and Mobile Device Security","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e","brand":"Jones and Bartlett Publishers, Inc","offers":[{"title":"Default Title","offer_id":48738511978839,"sku":"9781284211726","price":74.7,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9781284211726.jpg?v=1723812106"},{"product_id":"system-administration-ethics-9781484249871","title":"System Administration Ethics","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cdiv\u003eSuccessfully navigate through the ever-changing world of technology and ethics and reconcile system administration principles for separation of duty, account segmentation, administrative groups and data protection. As security breaches become more common, businesses need to protect themselves when facing ethical dilemmas in today''s digital landscape. This book serves as a equitable guideline in helping system administrators, engineers - as well as their managers - on coping with the ethical challenges of technology and security in the modern data center by providing real-life stories, scenarios, and use cases from companies both large and small. \u003c\/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c\/div\u003eYou''ll examine the problems and challenges that people working with customer data, security and system administration may face in the cyber world and review the boundaries and tools for remaining ethical in an environment where it is so easy to step over a line - intentionally or accidentally. You''ll also see h\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e\u003cb\u003e\u003ci\u003eSystem Administration Ethics\u003c\/i\u003e\u003c\/b\u003e\u003cbr\u003eChapter 1: In the Beginning\u003cbr\u003eChapter 2: Separate Roles\u003cbr\u003eChapter 3: Respect Privacy\u003cbr\u003eChapter 4: Do Not Change Data\u003cbr\u003eChapter 5: Don't Steal (Intellectual Property)\u003cbr\u003eChapter 6: Don't Steal (Computers)\u003cbr\u003eChapter 7: Do Not Go Where You Are Not Wanted\u003cbr\u003eChapter 8: Follow Procedures and Get Out\u003cbr\u003eChapter 9: Communicate Change\u003cbr\u003eChapter 10: Do No Harm\u003cbr\u003eChapter 11: Break Glass\u003cbr\u003e","brand":"APress","offers":[{"title":"Default Title","offer_id":48739665117527,"sku":"9781484249871","price":49.49,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9781484249871.jpg?v=1720052852"},{"product_id":"serverless-security-9781484260999","title":"Serverless Security","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003eApply the basics of security in serverless computing to new or existing projects. This hands-on guide provides practical examples and fundamentals. You will apply these fundamentals in all aspects of serverless computing: improving the code, securing the application, and protecting the infrastructure. You will come away having security knowledge that enables you to secure a project you are supporting and have technical conversations with cybersecurity personnel.\u003cp\u003e\u003c\/p\u003e\u003cp\u003eAt a time when there are many news stories on cybersecurity breaches, it is crucial to think about security in your applications. It is tempting to believe that having a third-party host the entire computing platform will increase security. This book shows you why cybersecurity is the responsibility of everyone working on the project.\u003c\/p\u003e\u003cp\u003e\u003cb\u003e\u003cbr\u003e\u003c\/b\u003e\u003c\/p\u003e\u003cp\u003e\u003cb\u003eWhat You Will Learn\u003c\/b\u003e\u003c\/p\u003e\u003cp\u003e\u003c\/p\u003e\u003cul\u003e\n\u003cli\u003eGain a deeper understanding of cybersecurity in serverless computing\u003c\/li\u003e\n\u003cli\u003eKnow how to use free and open source\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e\u003cb\u003eIntroduction\u003c\/b\u003e\u003cp\u003e\u003cb\u003e \u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003ePart I: The Need for Security\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003e \u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 1: Determining Scope\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eUnderstanding the Application\u003c\/p\u003e  \u003cp\u003eScoping\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 2: Performing a Risk Assessment\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eUnderstanding the Threat Landscape\u003c\/p\u003e  \u003cp\u003eThreat Modeling\u003c\/p\u003e  \u003cp\u003ePreparing the Risk Assessment\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003ePart II: Securing the Application\u003c\/p\u003e  \u003cp\u003e\u003cb\u003e \u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 3: Securing the Code\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eAssessing Dependencies\u003c\/p\u003e  \u003cp\u003eUsing Static Code Analysis Tools\u003c\/p\u003e  \u003cp\u003eWriting Unit Tests\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 4: Securing the Interfaces\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eIdentifying the Interfaces\u003c\/p\u003e  \u003cp\u003eDetermining the Interface Inputs\u003c\/p\u003e  \u003cp\u003eReducing the Attack Surface\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 5: Securing the Code Repository\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eUsing a Code Repository\u003c\/p\u003e  \u003cp\u003eLimiting Saved Content\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003ePart III: Securing the Infrastructure\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003e \u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 5: Restricting Permissions\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eUnderstanding Permissions\u003c\/p\u003e  \u003cp\u003eIdentifying the Services\u003c\/p\u003e  \u003cp\u003eUpdating the Permissions\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 6: Account Management\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eUnderstanding Account Access\u003c\/p\u003e  \u003cp\u003eRestricting Account Access\u003c\/p\u003e  \u003cp\u003eImplementing Multi-Factor Authentication\u003c\/p\u003e  Using Secrets\u003cp\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003e \u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003ePart IV: Monitoring and Alerting\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003e \u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 7: Monitoring Logs\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eUnderstanding Logging Methods\u003c\/p\u003e  \u003cp\u003eReviewing Logs\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 8: Monitoring Metrics\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eUnderstanding Metrics\u003c\/p\u003e  \u003cp\u003eReviewing Metrics\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 9: Monitoring Billing\u003c\/b\u003e\u003c\/p\u003e  Understanding Billing\u003cp\u003e\u003c\/p\u003e  \u003cp\u003eReviewing Billing\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 10: Monitoring Security Events\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eUnderstanding Security Events\u003c\/p\u003e  \u003cp\u003eReviewing Security Event\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 10: Alerting\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eUnderstanding Alerting\u003c\/p\u003e  \u003cp\u003eImplementing Alerting\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 11: Auditing\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eUnderstanding Auditing\u003c\/p\u003e  \u003cp\u003eImplementing Auditing\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cb\u003ePart V: Security Assessment and Report\u003c\/b\u003e\u003cp\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003e \u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 12: Finalizing the Risk Assessment\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eScoring the Identified Risks\u003c\/p\u003e  \u003cp\u003eDefining the Mitigation Steps\u003c\/p\u003e  \u003cp\u003eAssessing the Business Impact\u003c\/p\u003e  \u003cp\u003eDetermining the Overall Security Risk Level\u003c\/p\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"APress","offers":[{"title":"Default Title","offer_id":48739665936727,"sku":"9781484260999","price":41.24,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9781484260999.jpg?v=1720052855"},{"product_id":"tactical-wireshark-9781484292907","title":"Tactical Wireshark","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cp\u003eTake a systematic approach at identifying intrusions that range from the most basic to the most sophisticated, using Wireshark, an open source protocol analyzer. This book will show you how to effectively manipulate and monitor different conversations and perform statistical analysis of these conversations to identify the IP and TCP information of interest.\u003c\/p\u003e\u003cp\u003eNext, you''ll be walked through a review of the different methods malware uses, from inception through the spread across and compromise of a network of machines. The process from the initial click through intrusion, the characteristics of Command and Control (C2), and the different types of lateral movement will be detailed at the packet level.\u003c\/p\u003e\u003cp\u003eIn the final part of the book, you''ll explore the network capture file and identification of data for a potential forensics extraction, including inherent capabilities for the extraction of objects such as file data and other corresponding components in support of a foren\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003eChapter 1:  Customization of the Wireshark Interface \u003c\/p\u003e\u003cp\u003e\u003cb\u003eChapter Goal: - Learn how to edit the columns of the Wireshark user interface. Explore important items to include in the interface for performing intrusion and malware analysis\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eNo of pages - 18\u003c\/b\u003e         \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eSub -Topics\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e1.      Identifying columns to delete from the default displays\u003c\/p\u003e  \u003cp\u003e2.      Adding the source and destination ports for easy traffic analysis\u003c\/p\u003e  \u003cp\u003e3.      Specialty column customization for malware analysis\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  Intrusions Chapter 2:  Capturing Network Traffic \u003cp\u003e\u003cb\u003eChapter Goal: Setup a network capture in Wireshark\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eNo of pages\u003c\/b\u003e: - 24\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eSub - Topics\u003c\/b\u003e   \u003c\/p\u003e  \u003cp\u003e1.      Prerequisites for capturing live network data \u003c\/p\u003e  \u003cp\u003e2.       Working with Network Interfaces\u003c\/p\u003e  \u003cp\u003e3.      Exploring the network capture options\u003c\/p\u003e  \u003cp\u003e4.      Filtering While Capturing \u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  Chapter 3: Interpreting Network Protocols \u003cp\u003e\u003cb\u003eChapter Goal: A deep understanding of the network protocols at the packet level\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eNo of pages\u003c\/b\u003e : 30\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eSub - Topics:\u003c\/b\u003e   \u003c\/p\u003e  \u003cp\u003e1.      Investigating IP, the workhorse of the network\u003c\/p\u003e  2.      Analyzing ICMP and UDP\u003cp\u003e\u003c\/p\u003e  \u003cp\u003e3.      Dissection of TCP traffic\u003c\/p\u003e  \u003cp\u003e4.      Reassembly of packets\u003c\/p\u003e  \u003cp\u003e5.      Interpreting Name Resolution\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  Chapter 4: Analysis of Network Attacks \u003cp\u003e\u003cb\u003eChapter Goal: Understand the hacking mindset and leverage that to identify attacks\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eNo of pages\u003c\/b\u003e: 30\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eSub - Topics: \u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e1. Introducing a Hacking Methodology\u003c\/p\u003e  \u003cp\u003e2. Examination of reconnaissance network traffic artifacts\u003c\/p\u003e  \u003cp\u003e3. Leveraging the statistical properties of the capture file\u003c\/p\u003e  \u003cp\u003e4. Identifying SMB based attacks\u003c\/p\u003e  \u003cp\u003e5. Uncovering HTTP\/HTTPS based attack traffic\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  Chapter 5: Effective Network Traffic Filtering  \u003cp\u003e\u003cb\u003eChapter Goal: Use of the complex filtering capability of Wireshark to extract attack data\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003e \u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eNo of pages\u003c\/b\u003e: 35\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eSub - Topics: \u003c\/b\u003e\u003c\/p\u003e  1.      Identifying filter components\u003cp\u003e\u003c\/p\u003e  \u003cp\u003e2.      Investigating the conversations\u003c\/p\u003e  3.      Extracting the packet data\u003cp\u003e\u003c\/p\u003e  \u003cp\u003e4.      Building Filter Expressions\u003c\/p\u003e  5.      Decrypting HTTPS Traffic\u003cp\u003e\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e    Chapter 6: Advanced Features of Wireshark  \u003cp\u003e\u003cb\u003eChapter Goal: A fundamental review and understanding of the advanced features of Wireshark\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003e \u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eNo of pages\u003c\/b\u003e: 35\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eSub – Topics: \u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e1.      Working with cryptographic information in a packet\u003c\/p\u003e  \u003cp\u003e2.      Exploring the protocol dissectors of Wireshark\u003c\/p\u003e  3.      Viewing logged anomalies in Wireshark\u003cp\u003e\u003c\/p\u003e  \u003cp\u003e4.      Capturing traffic from remote computers\u003c\/p\u003e  5.      Command line tool tshark\u003cp\u003e\u003c\/p\u003e  \u003cp\u003e6.      Creating Firewall ACL rules\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  Chapter 7: Scripting and interacting with Wireshark  \u003cp\u003e\u003cb\u003eChapter Goal: Using scripts to extract and isolate data of interest from network capture files\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eNo of pages\u003c\/b\u003e: 30\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eSub – Topics:\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e1.       Lua scripting\u003c\/p\u003e  \u003cp\u003e2.       Interaction with Pandas\u003c\/p\u003e  \u003cp\u003e3.      Leveraging PyShark\u003c\/p\u003e  Malware Chapter 8: Basic Malware Traffic Analysis \u003cp\u003e\u003cb\u003eChapter Goal: Develop an understanding of the different stages of a malware infection\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003e \u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eNo of pages\u003c\/b\u003e: 36\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eSub – Topics:\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e1.       Customization of the interface for malware analysis\u003c\/p\u003e  2.       Extracting the files\u003cp\u003e\u003c\/p\u003e  \u003cp\u003e3.       Recognizing URL\/Domains of an infected site\u003c\/p\u003e  \u003cp\u003e4.       Determining the connections as part of the infected machine\u003c\/p\u003e  \u003cp\u003e5.       Scavenging the infected machine meta data\u003c\/p\u003e  \u003cp\u003e6.       Exporting the data objects\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  Chapter 9: Analyzing Encoding, Obfuscated and ICS Malware Traffic \u003cp\u003e\u003cb\u003eChapter Goal: Identify the encoding or obfuscated method in network traffic\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003e \u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eNo of pages\u003c\/b\u003e: 40\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eSub – Topics:\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e1.       Investigation of njRAT\u003c\/p\u003e  \u003cp\u003e2.       Analysis of Wanna Cry\u003c\/p\u003e  \u003cp\u003e3.       Exploring Cryptolocker\u003c\/p\u003e  \u003cp\u003e4.       Dissecting TRITON\u003c\/p\u003e  5.       Examining Trickbot\u003cp\u003e\u003c\/p\u003e  \u003cp\u003e6.       Understanding exploit kits\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  Chapter 10: Dynamic Malware Network Activities \u003cp\u003e\u003cb\u003eChapter Goal: Review and understand malware network activity as it happens\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003e \u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eNo of pages\u003c\/b\u003e: 40\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eSub – Topics: \u003c\/b\u003e\u003c\/p\u003e  1.       Setting up network and service simulation\u003cp\u003e\u003c\/p\u003e  \u003cp\u003e2.       Monitoring malware communications and connections at run time and beyond\u003c\/p\u003e  \u003cp\u003e3.       Detecting network evasion attempts\u003c\/p\u003e  \u003cp\u003e4.       Investigating Cobalt Strike Beacons\u003c\/p\u003e  \u003cp\u003e5.       Exploring C2 backdoor methods\u003c\/p\u003e  6.       Identifying Domain Generation Algorithms\u003cp\u003e\u003c\/p\u003e    Forensics Chapter 10: Extractions of Forensics Data with Wireshark  \u003cp\u003e\u003cb\u003eChapter Goal: Learn different methods of extracting different types of case related and potential forensics evidence\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003e \u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eNo of pages\u003c\/b\u003e: 30\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eSub – Topics:\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e1.       Interception of telephony data\u003c\/p\u003e  \u003cp\u003e2.       Discovering DOS\/DDoS\u003c\/p\u003e  \u003cp\u003e3.       Analysis of HTTP\/HTTPS Tunneling over DNS\u003c\/p\u003e  4.       Carving files from network data\u003cp\u003e\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003eChapter 11: \u003cb\u003eNetwork Traffic Forensics\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter Goal: An understanding of extraction of potential forensics data\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003e \u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eNo of pages\u003c\/b\u003e: 30\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eSub – Topics:\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e1.       Isolation of conversations\u003c\/p\u003e  \u003cp\u003e2.       Detection of Spoofing, port scanning and SSH attacks\u003c\/p\u003e  \u003cp\u003e3.       Reconstruction of timeline network attack data\u003c\/p\u003e  4.       Extracting compromise data\u003cp\u003e\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  Chapter 12: Conclusion \u003cp\u003e\u003cb\u003eChapter Goal: Review and summary of covered content\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003e \u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eNo of pages\u003c\/b\u003e: 10\u003c\/p\u003e  \u003cp\u003e\u003cbr\u003e\u003c\/p\u003e","brand":"APress","offers":[{"title":"Default Title","offer_id":48739669213527,"sku":"9781484292907","price":46.74,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9781484292907.jpg?v=1720052860"},{"product_id":"autonomous-cyber-deception-reasoning-adaptive-planning-and-evaluation-of-honeythings-9783030021092","title":"Autonomous Cyber Deception: Reasoning, Adaptive","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cp\u003e\u003c\/p\u003e\u003cp\u003eThis textbook surveys the knowledge base in automated and resilient cyber deception. It features four major parts: cyber deception reasoning frameworks, dynamic decision-making for cyber deception, network-based deception, and malware deception.\u003c\/p\u003e\u003cp\u003e An important distinguishing characteristic of this book is its inclusion of student exercises at the end of each chapter. Exercises include technical problems, short-answer discussion questions, or hands-on lab exercises, organized at a range of difficulties from easy to advanced,.\u003c\/p\u003e\u003cp\u003e This is a useful textbook for a wide range of classes and degree levels within the security arena and other related topics. It’s also suitable for researchers and practitioners with a variety of cyber security backgrounds from novice to experienced.\u003c\/p\u003e\u003cp\u003e\u003c\/p\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e1 Using Deep Learning to Generate Relational HoneyData.- 2 Towards Intelligent Cyber Deception Systems.- 3 Honeypot Deception Tactics.- 4 Modeling and Analysis of Deception Games based on Hypergame Theory.- 5 Dynamic Bayesian Games for Adversarial and Defensive Cyber Deception.- 6 CONCEAL: A Strategy Composition for Resilient Cyber Deception - Framework, Metrics and Deployment.- 7 NetShifter - A Comprehensive Multi-Dimensional Network Obfuscation and Deception Solution.- 8 Deception-Enhanced Threat Sensing for Resilient Intrusion Detection.- 9 HONEYSCOPE: IoT Device Protection with Deceptive Network Views.- 10 gExtractor: Automated Extraction of Malware Deception Parameters for Autonomous Cyber Deception.- 11 Malware Deception with Automatic Analysis and Generation of HoneyResource.","brand":"Springer Nature Switzerland AG","offers":[{"title":"Default Title","offer_id":48743021609303,"sku":"9783030021092","price":53.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9783030021092.jpg?v=1720063781"},{"product_id":"privacy-and-identity-management-fairness-accountability-and-transparency-in-the-age-of-big-data-13th-ifip-wg-9-2-9-6-11-7-11-6-sig-9-2-2-international-summer-school-vienna-austria-august-20-24-2018-revised-selected-papers-9783030167431","title":"Privacy and Identity Management. Fairness,","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cp\u003eThis book contains selected papers presented at the 13th IFIP WG 9.2, 9.6\/11.7, 11.6\/SIG 9.2.2 International Summer School on Privacy and Identity Management, held in Vienna, Austria, in August 2018.\u003c\/p\u003e  \u003cp\u003eThe 10 full papers included in this volume were carefully reviewed and selected from 27 submissions. Also included are reviewed papers summarizing the results of workshops and tutorials that were held at the Summer School as well as papers contributed by several of the invited speakers. The papers combine interdisciplinary approaches to bring together a host of perspectives: technical, legal, regulatory, socio-economic, social, societal, political, ethical, anthropological, philosophical, historical, and psychological. \u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e\u003cbr\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e\u003cp\u003eA Causal Bayesian Networks Viewpoint on Fairness.- Sharing is caring, a boundary object approach to mapping and discussing personal data processing.- Who You Gonna Call When There's Something Wrong in Your Processing? Risk Assessment and Data Breach Notications in Practice.- Design and Security Assessment of Usable Multi-Factor Authentication and Single Sign-On Solutions for Mobile Applications: A Workshop Experience Report.- Towards Empowering the Human for Privacy Online.- Trust and Distrust: On Sense and Nonsense in Big Data.- GDPR transparency requirements and data privacy vocabularies.- Glycos: the basis for a peer-to-peer, private online social network.- GDPR and the Concept of Risk: The Role of risk, the Scope of risk and the technology involved.- Privacy Patterns for Pseudonymity.- Implementing GDPR in the Charity Sector: A Case Study.- Me and My Robot! Sharing Information with a New Friend.- chownIoT: Enhancing IoT Privacy by Automated Handling of Ownership Change.- Is Privacy Controllable?.- Assessing Theories for Research on Personal Data Transparency.- Data Protection by Design for cross-border electronic identication: does the eIDAS Interoperability Framework need to be modernised?.- Risk proling by law enforcement agencies in the Big Data era: Is there a need for transparency?\u003c\/p\u003e\u003cbr\u003e","brand":"Springer Nature Switzerland AG","offers":[{"title":"Default Title","offer_id":48743025639767,"sku":"9783030167431","price":62.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9783030167431.jpg?v=1720063797"},{"product_id":"open-source-intelligence-and-cyber-crime-social-media-analytics-9783030412500","title":"Open Source Intelligence and Cyber Crime: Social","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cp\u003eThis book shows how open source intelligence can be a powerful tool for combating crime by linking local and global patterns to help understand how criminal activities are connected. Readers will encounter the latest advances in cutting-edge data mining, machine learning and predictive analytics combined with natural language processing and social network analysis to detect, disrupt, and neutralize cyber and physical threats. Chapters contain state-of-the-art social media analytics and open source intelligence research trends. This multidisciplinary volume will appeal to students, researchers, and professionals working in the fields of open source intelligence, cyber crime and social network analytics.\u003c\/p\u003e  \u003cp\u003e Chapter Automated Text Analysis for Intelligence Purposes: A Psychological Operations Case Study is available open access under a Creative Commons Attribution 4.0 International License via link.springer.com.\u003c\/p\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003eChapter1. Studying the Weaponization of Social Media: Case Studies of Anti-NATO Disinformation Campaigns.- Chapter2. Cognitively-Inspired Inference for Malware Task Indentation.- Chapter3. Beyond the ‘Silk Road’: Assessing Illicit Drug Marketplaces on the Public Web.- Chapter4. Protecting the Web from Misinformation.- Chapter5. Social Media for Mental Health: Data, Methods, and Findings.- Chapter6. Twitter Bots and the Swedish Election.- Chapter7. Automated Text Analysis for Intelligence Purposes: A Psychological Operations Case Study.- Chapter8. You are Known by Your Friends: Leveraging Network Metrics for Bot Detection in Twitter.- Chapter9. Inferring Systemic Nets with Applications to Islamist Forums.\u003cbr\u003e","brand":"Springer Nature Switzerland AG","offers":[{"title":"Default Title","offer_id":48743035109719,"sku":"9783030412500","price":89.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9783030412500.jpg?v=1720063824"},{"product_id":"applied-cryptography-and-network-security-19th-international-conference-acns-2021-kamakura-japan-june-21-24-2021-proceedings-part-i-9783030783716","title":"Applied Cryptography and Network Security: 19th","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cp\u003eThe two-volume set LNCS 12726 + 12727 constitutes the proceedings of the 19th International Conference on Applied Cryptography and Network Security, ACNS 2021, which took place virtually during June 21-24, 2021. \u003c\/p\u003e  \u003cp\u003eThe 37 full papers presented in the proceedings were carefully reviewed and selected from a total of 186 submissions. They were organized in topical sections as follows:\u003c\/p\u003e  \u003cp\u003ePart I: Cryptographic protocols; secure and fair protocols; cryptocurrency and smart contracts; digital signatures; embedded system security; lattice cryptography; \u003c\/p\u003e  \u003cp\u003ePart II: Analysis of applied systems; secure computations; cryptanalysis; system security; and cryptography and its applications. \u003c\/p\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e\u003cp\u003eCryptographic Protocols.- Adaptive-ID Secure Hierarchical ID-Based Authenticated Key Exchange under Standard Assumptions without Random Oracles.- Analysis of Client-side Security for Long-term Time-stamping Services.- Towards Efficient and Strong Backward Private Searchable Encryption with Secure Enclaves.- Secure and Fair Protocols.- CECMLP: New Cipher-Based Evaluating Collaborative Multi-Layer Perceptron Scheme in Federated Learning.- Blind Polynomial Evaluation and Data Trading.- Coin-Based Multi-Party Fair Exchange.- Cryptocurrency and Smart Contracts.- P2DEX: Privacy-Preserving Decentralized Cryptocurrency Exchange.- WOTS+ up my Sleeve! A Hidden Secure Fallback for Cryptocurrency Wallets.- Terrorist Attacks for Fake Exposure Notifications in Contact Tracing Systems.- Digital Signatures.- Unlinkable and Invisible -Sanitizable Signatures.- Partially Structure-Preserving Signatures: Lower Bounds, Constructions and More.- An Efficient Certificate-Based Signature Scheme in the Standard Model.- Embedded System Security.- SnakeGX: a sneaky attack against SGX Enclaves.- Telepathic Headache: Mitigating Cache Side-Channel Attacks on Convolutional Neural Networks.- Efficient FPGA Design of Exception-Free Generic Elliptic Curve Cryptosystems.- Lattice Cryptography.- Access Control Encryption from Group Encryption.- Password Protected Secret Sharing from Lattices.- Efficient Homomorphic Conversion Between (Ring) LWE Ciphertexts.\u003c\/p\u003e","brand":"Springer Nature Switzerland AG","offers":[{"title":"Default Title","offer_id":48743049920855,"sku":"9783030783716","price":44.99,"currency_code":"GBP","in_stock":true}]},{"product_id":"modern-data-strategy-9783319689920","title":"Modern Data Strategy","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cp\u003eThis book contains practical steps business users can take to implement data management in a number of ways, including data governance, data architecture, master data management, business intelligence, and others. It defines data strategy, and covers chapters that illustrate how to align a data strategy with the business strategy, a discussion on valuing data as an asset, the evolution of data management, and who should oversee a data strategy. This provides the user with a good understanding of what a data strategy is and its limits.\u003c\/p\u003e  \u003cp\u003eCritical to a data strategy is the incorporation of one or more data management domains. Chapters on key data management domains—data governance, data architecture, master data management and analytics, offer the user a practical approach to data management execution within a data strategy. The intent is to enable the user to identify how execution on one or more data management domains can help solve business issues.\u003c\/p\u003e  \u003cp\u003eThis book is intended for business users who work with data, who need to manage one or more aspects of the organization’s data, and who want to foster an integrated approach for how enterprise data is managed. This book is also an excellent reference for students studying computer science and business management or simply for someone who has been tasked with starting or improving existing data management.\u003c\/p\u003e\u003cp\u003e\u003c\/p\u003e\u003cp\u003e\u003c\/p\u003e\u003cp\u003e\u003c\/p\u003e\u003cp\u003e\u003c\/p\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e1 Evolution to Modern Data Management.- 2 Big Data and Data Management.- 3 Valuing Data as an Asset.- 4 Physical Asset Management vs. Data Management.- 5 Leading Data Strategy.- 6 Implementing a Data Strategy.- 7 Overview of Data Management Frameworks.- 8 Data Governance.- 9 Data Architecture.- 10 Master Data Management.- 11 Data Quality.- 12 Data Warehousing and Business Intelligence.- 13 Data Analytics.- 14 Data Privacy.- 15 Data Security.- 16 Metadata.- 17 Records Management.","brand":"Springer International Publishing AG","offers":[{"title":"Default Title","offer_id":48743102153047,"sku":"9783319689920","price":999.99,"currency_code":"GBP","in_stock":false}]},{"product_id":"secure-systems-development-with-uml-9783642056352","title":"Secure Systems Development with UML","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cp\u003eAttacks against computer systems can cause considerable economic or physical damage. High-quality development of security-critical systems is difficult, mainly because of the conflict between development costs and verifiable correctness.\u003c\/p\u003e \u003cp\u003eJürjens presents the UML extension UMLsec for secure systems development. It uses the standard UML extension mechanisms, and can be employed to evaluate UML specifications for vulnerabilities using a formal semantics of a simplified fragment of UML. Established rules of security engineering can be encapsulated and hence made available even to developers who are not specialists in security. As one example, Jürjens uncovers a flaw in the Common Electronic Purse Specification, and proposes and verifies a correction.\u003c\/p\u003e \u003cp\u003eWith a clear separation between the general description of his approach and its mathematical foundations, the book is ideally suited both for researchers and graduate students in UML or formal methods and security, and for advanced professionals writing critical applications.\u003c\/p\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003ePrologue.- Walk-through: Using UML for Security.- Background.- Developing Secure Systems.- Model-based Security Engineering with UML.- Applications.- Tool Support.- Tool support for UMLsec.- A Formal Foundation.- Formal Systems Development with UML.- Epilogue.- Further Material.- Outlook.","brand":"Springer-Verlag Berlin and Heidelberg GmbH \u0026 Co. KG","offers":[{"title":"Default Title","offer_id":48743132758359,"sku":"9783642056352","price":999.99,"currency_code":"GBP","in_stock":false}]},{"product_id":"ios-17-app-development-for-beginners-get-started-with-ios-app-development-using-swift-5-9-swiftui-and-xcode-15-9789355515858","title":"iOS 17 App Development for Beginners: Get started","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e","brand":"BPB Publications","offers":[{"title":"Default Title","offer_id":48743244300631,"sku":"9789355515858","price":999.99,"currency_code":"GBP","in_stock":false}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9789355515858.jpg?v=1720064749"},{"product_id":"information-privacy-engineering-and-privacy-by-design-9780135302156","title":"Information Privacy Engineering and Privacy by","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cb\u003eDr. William Stallings\u003c\/b\u003e has made a unique contribution to understanding the broad sweep of technical developments in computer security, computer networking, and computer architecture. He has authored 18 textbooks and, counting revised editions, a total of 70 books on various aspects of these subjects. His writings have appeared in numerous ACM and IEEE publications, including the \u003ci\u003eProceedings of the IEE\u003c\/i\u003eE and \u003ci\u003eACM Computing Reviews\u003c\/i\u003e. He has 13 times received the award for the best computer science textbook of the year from the Text and Academic Authors Association. \u003cbr\u003e \u003cbr\u003eWith more than 30 years in the field, he has been a technical contributor, a technical manager, and an executive with several high-technology firms. He has designed and implemented both TCP\/IP-based and OSI-based protocol suites on a variety of computers and operating systems, ranging from microcomputers to mainframes. Currently he is an independent consultant whose clients have included computer and \u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e\u003cul\u003e\n\u003cli\u003ePart I: Planning for Privacy\u003c\/li\u003e\n\u003cli\u003e1. Information Privacy Concepts\u003c\/li\u003e\n\u003cli\u003e2. Security Governance and Management\u003c\/li\u003e\n\u003cli\u003e3. Risk Assessment \u003c\/li\u003e\n\u003cli\u003ePart II: Privacy Threats\u003c\/li\u003e\n\u003cli\u003e4. Information Storage and Processing\u003c\/li\u003e\n\u003cli\u003e5. Information Collection and Dissemination\u003c\/li\u003e\n\u003cli\u003e6. Intrusion and Interference \u003c\/li\u003e\n\u003cli\u003ePart III: Information Privacy Technology\u003c\/li\u003e\n\u003cli\u003e7. Basic Privacy Controls\u003c\/li\u003e\n\u003cli\u003e8. Privacy Enhancing Technology\u003c\/li\u003e\n\u003cli\u003e9. Data Loss Prevention\u003c\/li\u003e\n\u003cli\u003e10. Online Privacy\u003c\/li\u003e\n\u003cli\u003e11. Detection of Conflicts In Security Policies\u003c\/li\u003e\n\u003cli\u003e12. Privacy Evaluation \u003c\/li\u003e\n\u003cli\u003ePart IV: Information Privacy Regulations\u003c\/li\u003e\n\u003cli\u003e13. GDPR\u003c\/li\u003e\n\u003cli\u003e14. U.S. Privacy Laws and Regulations\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"Pearson Education (US)","offers":[{"title":"Default Title","offer_id":48864172998999,"sku":"9780135302156","price":49.39,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9780135302156.jpg?v=1722270733"},{"product_id":"modern-security-operations-center-the-9780135619858","title":"Modern Security Operations Center The","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cp\u003e\u003cstrong\u003eJoseph Muniz\u003c\/strong\u003e is an architect and security researcher in the Cisco Security Sales and Engineering Organization. He is driven by making the world a safer place through education and adversary research. Joseph has extensive experience in designing security solutions and architectures as a trusted advisor for top Fortune 500 corporations and the U.S. government.\u003c\/p\u003e \u003cp\u003eJoseph is a researcher and industry thought leader. He speaks regularly at international conferences, writes for technical magazines, and is involved with developing training for various industry certifications. He invented the fictitious character of Emily Williams to create awareness around social engineering. Joseph runs The Security Blogger website, a popular resource for security and product implementation. He is the author and contributor of several publications including titles ranging from security best practices to exploitation tactics.\u003c\/p\u003e \u003cp\u003eWhen Joseph is not using technology, you can find him\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e\u003c\/p\u003e\u003cp\u003ePreface \u003cbr\u003e\u003cstrong\u003eChapter 1:\u003c\/strong\u003e Introducing Security Operations and the SOC \u003cbr\u003eIntroducing the SOC\u003cbr\u003eFactors Leading to a Dysfunctional SOC\u003cbr\u003eCyberthreats\u003cbr\u003eInvesting in Security\u003cbr\u003eThe Impact of a Breach\u003cbr\u003eEstablishing a Baseline\u003cbr\u003e The Impact of Change\u003cbr\u003eFundamental Security Capabilities\u003cbr\u003e Signature Detection\u003cbr\u003e Behavior Detection\u003cbr\u003e Anomaly Detection\u003cbr\u003e Best of Breed vs. Defense in Depth\u003cbr\u003eStandards, Guidelines, and Frameworks\u003cbr\u003e NIST Cybersecurity Framework\u003cbr\u003e ISO 3100:2018\u003cbr\u003e FIRST Service Frameworks\u003cbr\u003e Applying Frameworks\u003cbr\u003eIndustry Threat Models\u003cbr\u003e The Cyber Kill Chain Model\u003cbr\u003e The Diamond Model\u003cbr\u003e MITRE ATT\u0026amp;CK Model\u003cbr\u003e Choosing a Threat Model\u003cbr\u003eVulnerabilities and Risk\u003cbr\u003e Endless Vulnerabilities\u003cbr\u003eBusiness Challenges\u003cbr\u003eIn-House vs. Outsourcing\u003cbr\u003e Services Advantages\u003cbr\u003e Services Disadvantages\u003cbr\u003e Hybrid Services\u003cbr\u003eSOC Services\u003cbr\u003eSOC Maturity Models\u003cbr\u003e SOC Maturity Assessment\u003cbr\u003e SOC Program Maturity\u003cbr\u003eSOC Goals Assessment\u003cbr\u003e Defining Goals\u003cbr\u003e SOC Goals Ranking\u003cbr\u003e Threats Ranking\u003cbr\u003e SOC Goals Assessment Summarized\u003cbr\u003eSOC Capabilities Assessment\u003cbr\u003e Capability Maps\u003cbr\u003e SOC Capabilities Gaps Analysis\u003cbr\u003e Capability Map Next Steps\u003cbr\u003eSOC Development Milestones\u003cbr\u003eSummary\u003cbr\u003eReferences\u003cbr\u003e\u003cstrong\u003eChapter 2:\u003c\/strong\u003e Developing a Security Operations Center \u003cbr\u003eMission Statement and Scope Statement\u003cbr\u003e Developing Mission and Scope Statements\u003cbr\u003e SOC Scope Statement\u003cbr\u003eDeveloping a SOC\u003cbr\u003eSOC Procedures\u003cbr\u003e Designing Procedures\u003cbr\u003eSecurity Tools\u003cbr\u003e Evaluating Vulnerabilities\u003cbr\u003e Preventive Technologies\u003cbr\u003e Detection Technologies\u003cbr\u003e Mobile Device Security Concerns\u003cbr\u003ePlanning a SOC\u003cbr\u003e Capacity Planning\u003cbr\u003e Developing a Capacity Plan\u003cbr\u003eDesigning a SOC Facility\u003cbr\u003e Physical SOC vs. Virtual SOC\u003cbr\u003e SOC Location\u003cbr\u003e SOC Interior\u003cbr\u003e SOC Rooms\u003cbr\u003e SOC Computer Rooms\u003cbr\u003e SOC Layouts\u003cbr\u003eNetwork Considerations\u003cbr\u003e Segmentation\u003cbr\u003e Logical Segmentation\u003cbr\u003e Choosing Segmentation\u003cbr\u003e Client\/Server Segmentation\u003cbr\u003e Active Directory Segmentation\u003cbr\u003e Throughput\u003cbr\u003e Connectivity and Redundancy\u003cbr\u003eDisaster Recovery\u003cbr\u003eSecurity Considerations\u003cbr\u003e Policy and Compliance\u003cbr\u003e Network Access Control\u003cbr\u003e Encryption\u003cbr\u003eInternal Security Tools\u003cbr\u003e Intrusion Detection and Prevention\u003cbr\u003e Network Flow and Capturing Packets\u003cbr\u003e Change Management\u003cbr\u003e Host Systems\u003cbr\u003eGuidelines and Recommendations for Securing Your SOC Network\u003cbr\u003e Tool Collaboration\u003cbr\u003eSOC Tools\u003cbr\u003e Reporting and Dashboards\u003cbr\u003e Throughput and Storage\u003cbr\u003e Centralized Data Management\u003cbr\u003eSummary\u003cbr\u003eReferences\u003cbr\u003e\u003cstrong\u003eChapter 3:\u003c\/strong\u003e SOC Services \u003cbr\u003eFundamental SOC Services\u003cbr\u003e SOC Challenges\u003cbr\u003eThe Three Pillars of Foundational SOC Support Services\u003cbr\u003e Pillar 1: Work Environment\u003cbr\u003e Pillar 2: People\u003cbr\u003e Pillar 3: Technology\u003cbr\u003e Evaluating the Three Pillars of Foundational SOC Support Services\u003cbr\u003eSOC Service Areas\u003cbr\u003e FIRST’s CSIRT\u003cbr\u003e Developing SOC Service Areas\u003cbr\u003e In-House Services vs. External Services\u003cbr\u003e Contracted vs. Employee Job Roles\u003cbr\u003eSOC Service Job Goals\u003cbr\u003e Resource Planning\u003cbr\u003eService Maturity: If You Build It, They Will Come\u003cbr\u003eSOC Service 1: Risk Management\u003cbr\u003e Four Responses to Risk\u003cbr\u003e Reducing Risk\u003cbr\u003e Addressing Risk\u003cbr\u003eSOC Service 2: Vulnerability Management\u003cbr\u003e Vulnerability Management Best Practice\u003cbr\u003e Vulnerability Scanning Tools\u003cbr\u003e Penetration Testing\u003cbr\u003eSOC Service 3: Compliance\u003cbr\u003e Meeting Compliance with Audits\u003cbr\u003eSOC Service 4: Incident Management\u003cbr\u003e NIST Special Publication 800-61 Revision 2 \u003cbr\u003e Incident Response Planning\u003cbr\u003e Incident Impact\u003cbr\u003e Playbooks\u003cbr\u003eSOC Service 5: Analysis \u003cbr\u003e Static Analysis\u003cbr\u003e Dynamic Analysis\u003cbr\u003eSOC Service 6: Digital Forensics\u003cbr\u003eSOC Service 7: Situational and Security Awareness\u003cbr\u003e User Training\u003cbr\u003eSOC Service 8: Research and Development\u003cbr\u003eSummary\u003cbr\u003eReferences\u003cbr\u003e\u003cstrong\u003eChapter 4:\u003c\/strong\u003e People and Process \u003cbr\u003eCareer vs. Job\u003cbr\u003eDeveloping Job Roles\u003cbr\u003e General Schedule Pay Scale\u003cbr\u003e IT Industry Job Roles\u003cbr\u003e Common IT Job Roles\u003cbr\u003eSOC Job Roles\u003cbr\u003e Security Analyst\u003cbr\u003e Penetration Tester\u003cbr\u003e Assessment Officer\u003cbr\u003e Incident Responder\u003cbr\u003e Systems Analyst\u003cbr\u003e Security Administrator\u003cbr\u003e Security Engineer\u003cbr\u003e Security Trainer\u003cbr\u003e Security Architect\u003cbr\u003e Cryptographer\/Cryptologist \u003cbr\u003e Forensic Engineer\u003cbr\u003e Chief Information Security Officer\u003cbr\u003eNICE Cybersecurity Workforce Framework\u003cbr\u003e Nice Framework Components\u003cbr\u003eRole Tiers\u003cbr\u003eSOC Services and Associated Job Roles\u003cbr\u003e Risk Management Service\u003cbr\u003e Vulnerability Management Service\u003cbr\u003e Incident Management Service\u003cbr\u003e Analysis Service\u003cbr\u003e Compliance Service\u003cbr\u003e Digital Forensics Service\u003cbr\u003e Situational and Security Awareness Service\u003cbr\u003e Research and Development Service\u003cbr\u003eSoft Skills\u003cbr\u003e Evaluating Soft Skills\u003cbr\u003e SOC Soft Skills\u003cbr\u003eSecurity Clearance Requirements\u003cbr\u003ePre-Interviewing\u003cbr\u003eInterviewing\u003cbr\u003e Interview Prompter\u003cbr\u003e Post Interview\u003cbr\u003eOnboarding Employees\u003cbr\u003e Onboarding Requirements\u003cbr\u003eManaging People\u003cbr\u003eJob Retention\u003cbr\u003eTraining\u003cbr\u003e Training Methods\u003cbr\u003eCertifications\u003cbr\u003eCompany Culture\u003cbr\u003eSummary\u003cbr\u003eReferences\u003cbr\u003e\u003cstrong\u003eChapter 5:\u003c\/strong\u003e Centralizing Data \u003cbr\u003eData in the SOC\u003cbr\u003e Strategic and Tactical Data\u003cbr\u003e Data Structure\u003cbr\u003e Data Types\u003cbr\u003e Data Context\u003cbr\u003eData-Focused Assessment\u003cbr\u003e Data Assessment Example: Antivirus\u003cbr\u003e Threat Mapping Data\u003cbr\u003e Applying Data Assessments to SOC Services\u003cbr\u003eLogs\u003cbr\u003e Log Types\u003cbr\u003e Log Formats\u003cbr\u003eSecurity Information and Event Management\u003cbr\u003e SIEM Data Processing\u003cbr\u003e Data Correlation\u003cbr\u003e Data Enrichment\u003cbr\u003e SIEM Solution Planning\u003cbr\u003e SIEM Tuning\u003cbr\u003eTroubleshooting SIEM Logging\u003cbr\u003e SIEM Troubleshooting Part 1: Data Input\u003cbr\u003e SIEM Troubleshooting Part 2: Data Processing and Validation\u003cbr\u003e SIEM Troubleshooting Examples\u003cbr\u003e Additional SIEM Features\u003cbr\u003eAPIs\u003cbr\u003e Leveraging APIs\u003cbr\u003e API Architectures\u003cbr\u003e API Examples\u003cbr\u003eBig Data\u003cbr\u003e Hadoop\u003cbr\u003e Big Data Threat Feeds\u003cbr\u003eMachine Learning\u003cbr\u003e Machine Learning in Cybersecurity\u003cbr\u003e Artificial Intelligence\u003cbr\u003e Machine Learning Models\u003cbr\u003eSummary\u003cbr\u003eReferences\u003cbr\u003e\u003cstrong\u003eChapter 6:\u003c\/strong\u003e Reducing Risk and Exceeding Compliance\u003cbr\u003eWhy Exceeding Compliance\u003cbr\u003ePolicies\u003cbr\u003e Policy Overview\u003cbr\u003e Policy Purpose\u003cbr\u003e Policy Scope\u003cbr\u003e Policy Statement\u003cbr\u003e Policy Compliance\u003cbr\u003e Related Standards, Policies, Guidelines, and Processes\u003cbr\u003e Definitions and Terms\u003cbr\u003e History\u003cbr\u003eLaunching a New Policy\u003cbr\u003e Steps for Launching a New Policy\u003cbr\u003ePolicy Enforcement\u003cbr\u003e Certification and Accreditation\u003cbr\u003eProcedures\u003cbr\u003e Procedure Document\u003cbr\u003eTabletop Exercise\u003cbr\u003e Tabletop Exercise Options\u003cbr\u003e Tabletop Exercise Execution\u003cbr\u003e Tabletop Exercise Format\u003cbr\u003e Tabletop Exercise Template Example\u003cbr\u003eStandards, Guidelines, and Frameworks\u003cbr\u003e NIST Cybersecurity Framework\u003cbr\u003e ISO\/IEC 27005\u003cbr\u003e CIS Controls\u003cbr\u003e ISACA COBIT 2019\u003cbr\u003e FIRST CSIRT Services Framework\u003cbr\u003e Exceeding Compliance\u003cbr\u003eAudits\u003cbr\u003e Audit Example\u003cbr\u003e Internal Audits\u003cbr\u003e External Auditors\u003cbr\u003e Audit Tools\u003cbr\u003eAssessments\u003cbr\u003e Assessment Types\u003cbr\u003e Assessment Results\u003cbr\u003e Assessment Template\u003cbr\u003e Vulnerability Scanners\u003cbr\u003e Assessment Program Weaknesses\u003cbr\u003ePenetration Test\u003cbr\u003e NIST Special Publication 800-115\u003cbr\u003e Additional NIST SP 800-115 Guidance\u003cbr\u003e Penetration Testing Types\u003cbr\u003e Penetration Testing Planning\u003cbr\u003eIndustry Compliance\u003cbr\u003e Compliance Requirements\u003cbr\u003eSummary\u003cbr\u003eReferences\u003cbr\u003e\u003cstrong\u003eChapter 7:\u003c\/strong\u003e Threat Intelligence \u003cbr\u003eThreat Intelligence Overview\u003cbr\u003e Threat Data\u003cbr\u003eThreat Intelligence Categories\u003cbr\u003e Strategic Threat Intelligence\u003cbr\u003e Tactical Threat Intelligence\u003cbr\u003e Operational Threat Intelligence\u003cbr\u003e Technical Threat Intelligence\u003cbr\u003eThreat Intelligence Context\u003cbr\u003e Threat Context\u003cbr\u003eEvaluating Threat Intelligence\u003cbr\u003e Threat Intelligence Checklist\u003cbr\u003e Content Quality\u003cbr\u003e Testing Threat Intelligence\u003cbr\u003ePlanning a Threat Intelligence Project\u003cbr\u003e Data Expectations for Strategic Threat Intelligence\u003cbr\u003e Data Expectations for Tactical Threat Intelligence\u003cbr\u003e Data Expectations for Operational Threat Intelligence\u003cbr\u003e Data Expectations for Technical Threat Intelligence\u003cbr\u003eCollecting and Processing Intelligence\u003cbr\u003e Processing Nontechnical Data\u003cbr\u003e Operational Data and Web Processing\u003cbr\u003e Technical Processing\u003cbr\u003e Technical Threat Intelligence Resources \u003cbr\u003eActionable Intelligence\u003cbr\u003e Security Tools and Threat Intelligence\u003cbr\u003eFeedback\u003cbr\u003eSummary\u003cbr\u003eReferences\u003cbr\u003e\u003cstrong\u003eChapter 8:\u003c\/strong\u003e Threat Hunting and Incident Response \u003cbr\u003eSecurity Incidents\u003cbr\u003eIncident Response Lifecycle\u003cbr\u003ePhase 1: Preparation\u003cbr\u003e Assigning Tasks with Playbooks\u003cbr\u003e Communication\u003cbr\u003e Third-Party Interaction\u003cbr\u003e Law Enforcement\u003cbr\u003e Law Enforcement Risk\u003cbr\u003e Ticketing Systems\u003cbr\u003e Other Incident Response Planning Templates\u003cbr\u003e Phase 1: Preparation Summary\u003cbr\u003ePhase 2: Detection and Analysis\u003cbr\u003e Incident Detection\u003cbr\u003e Core Security Capabilities\u003cbr\u003e Threat Analysis\u003cbr\u003e Detecting Malware Behavior\u003cbr\u003e Infected Systems\u003cbr\u003e Analyzing Artifacts\u003cbr\u003e Identifying Artifact Types\u003cbr\u003e Packing Files\u003cbr\u003e Basic Static Analysis\u003cbr\u003e Advanced Static Analysis\u003cbr\u003e Dynamic Analysis\u003cbr\u003e Phase 2: Detection and Analysis Summary\u003cbr\u003ePhase 3: Containment, Eradication, and Recovery\u003cbr\u003e Containment\u003cbr\u003e Responding to Malware\u003cbr\u003e Threat Hunting Techniques\u003cbr\u003e Eradicate\u003cbr\u003e Recovery\u003cbr\u003eDigital Forensics\u003cbr\u003e Digital Forensic Process\u003cbr\u003e First Responder\u003cbr\u003e Chain of Custody\u003cbr\u003e Working with Evidence\u003cbr\u003e Duplicating Evidence \u003cbr\u003e Hashes\u003cbr\u003e Forensic Static Analysis\u003cbr\u003e Recovering Data\u003cbr\u003e Forensic Dynamic Analysis\u003cbr\u003e Digital Forensics Summary\u003cbr\u003e Phase 3: Containment, Eradication, and Recovery Summary\u003cbr\u003ePhase 4: Post-Incident Activity\u003cbr\u003e Post-Incident Response Process\u003cbr\u003e Phase 4: Post-Incident Response Summary\u003cbr\u003eIncident Response Guidelines\u003cbr\u003e FIRST Services Frameworks\u003cbr\u003eSummary\u003cbr\u003eReferences\u003cbr\u003e\u003cstrong\u003eChapter 9:\u003c\/strong\u003e Vulnerability Management \u003cbr\u003eVulnerability Management\u003cbr\u003e Phase 1: Asset Inventory\u003cbr\u003e Phase 2: Information Management\u003cbr\u003e Phase 3: Risk Assessment\u003cbr\u003e Phase 4: Vulnerability Assessment\u003cbr\u003e Phase 5: Report and Remediate \u003cbr\u003e Phase 6: Respond and Repeat\u003cbr\u003eMeasuring Vulnerabilities\u003cbr\u003e Common Vulnerabilities and Exposures\u003cbr\u003e Common Vulnerability Scoring System\u003cbr\u003e CVSS Standards\u003cbr\u003eVulnerability Technology\u003cbr\u003e Vulnerability Scanners\u003cbr\u003e Currency and Coverage\u003cbr\u003e Tuning Vulnerability Scanners\u003cbr\u003e Exploitation Tools\u003cbr\u003e Asset Management and Compliance Tools\u003cbr\u003e Network Scanners and Network Access Control\u003cbr\u003e Threat Detection Tools\u003cbr\u003eVulnerability Management Service \u003cbr\u003e Scanning Services\u003cbr\u003e Vulnerability Management Service Roles\u003cbr\u003e Vulnerability Evaluation Procedures\u003cbr\u003eVulnerability Response \u003cbr\u003e Vulnerability Accuracy\u003cbr\u003e Responding to Vulnerabilities\u003cbr\u003e Cyber Insurance\u003cbr\u003e Patching Systems\u003cbr\u003e Residual Risk\u003cbr\u003e Remediation Approval\u003cbr\u003e Reporting\u003cbr\u003e Exceptions\u003cbr\u003eVulnerability Management Process Summarized\u003cbr\u003eSummary\u003cbr\u003eReferences\u003cbr\u003e\u003cstrong\u003eChapter 10:\u003c\/strong\u003e Data Orchestration \u003cbr\u003eIntroduction to Data Orchestration\u003cbr\u003e Comparing SIEM and SOAR\u003cbr\u003e The Rise of XDR\u003cbr\u003eSecurity Orchestration, Automation, and Response\u003cbr\u003e SOAR Example: Phantom\u003cbr\u003eEndpoint Detection and Response\u003cbr\u003e EDR Example: CrowdStrike\u003cbr\u003ePlaybooks\u003cbr\u003e Playbook Components\u003cbr\u003e Constructing Playbooks\u003cbr\u003e Incident Response Consortium\u003cbr\u003e Playbook Examples: Malware Outbreak\u003cbr\u003eAutomation\u003cbr\u003e Automating Playbooks\u003cbr\u003e Common Targets for Automation\u003cbr\u003e Automation Pitfalls\u003cbr\u003e Playbook Workflow\u003cbr\u003eDevOps Programming\u003cbr\u003e Data Management\u003cbr\u003e Text-File Formats\u003cbr\u003e Common Data Formats\u003cbr\u003e Data Modeling\u003cbr\u003eDevOps Tools\u003cbr\u003e DevOps Targets\u003cbr\u003e Manual DevOps\u003cbr\u003e Automated DevOps\u003cbr\u003e DevOps Lab Using Ansible\u003cbr\u003e Ansible Playbooks\u003cbr\u003eBlueprinting with Osquery\u003cbr\u003e Running Osquery\u003cbr\u003eNetwork Programmability\u003cbr\u003e Learning NetDevOps\u003cbr\u003e APIs\u003cbr\u003e NetDevOps Example\u003cbr\u003eCloud Programmability\u003cbr\u003e Orchestration in the Cloud\u003cbr\u003e Amazon DevOps\u003cbr\u003e SaaS DevOps\u003cbr\u003eSummary\u003cbr\u003eReferences\u003cbr\u003e\u003cstrong\u003eChapter 11:\u003c\/strong\u003e Future of the SOC \u003cbr\u003eAll Eyes on SD-WAN and SASE\u003cbr\u003e VoIP Adoption As Prologue to SD-WAN Adoption\u003cbr\u003e Introduction of SD-WAN\u003cbr\u003e Challenges with the Traditional WAN\u003cbr\u003e SD-WAN to the Rescue\u003cbr\u003e SASE Solves SD-WAN Problems\u003cbr\u003e SASE Defined\u003cbr\u003e Future of SASE\u003cbr\u003eIT Services Provided by the SOC\u003cbr\u003e IT Operations Defined\u003cbr\u003e Hacking IT Services\u003cbr\u003e IT Services Evolving\u003cbr\u003e Future of IT Services\u003cbr\u003eFuture of Training\u003cbr\u003e Training Challenges\u003cbr\u003e Training Today\u003cbr\u003e Case Study: Training I Use Today\u003cbr\u003e Free Training\u003cbr\u003e Gamifying Learning\u003cbr\u003e On-Demand and Personalized Learning\u003cbr\u003e Future of Training\u003cbr\u003eFull Automation with Machine Learning\u003cbr\u003e Machine Learning\u003cbr\u003e Machine Learning Hurdles\u003cbr\u003e Machine Learning Applied\u003cbr\u003e Training Machine Learning\u003cbr\u003e Future of Machine Learning\u003cbr\u003eFuture of Your SOC: Bringing It All Together\u003cbr\u003e Your Future Facilities and Capabilities\u003cbr\u003e Group Tags\u003cbr\u003e Your Future SOC Staff\u003cbr\u003e Audits, Assessments, and Penetration Testing\u003cbr\u003e Future Impact to Your Services\u003cbr\u003e Hunting for Tomorrow’s Threats\u003cbr\u003eSummary\u003cbr\u003eReferences\u003cbr\u003e9780135619858 TOC 3\/24\/2021\u003c\/p\u003e","brand":"Pearson Education (US)","offers":[{"title":"Default Title","offer_id":48864173064535,"sku":"9780135619858","price":40.49,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9780135619858.jpg?v=1722270733"},{"product_id":"ccnp-security-virtual-private-networks-svpn-300730-official-cert-guide-9780136660606","title":"CCNP Security Virtual Private Networks SVPN","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cp\u003e\u003cstrong\u003eJoseph Muniz\u003c\/strong\u003e is an architect and security researcher in the Cisco Security Sales and Engineering organization. He is driven by making the world a safer place through education and adversary research. Joseph has extensive experience in designing security solutions and architectures as a trusted advisor for top Fortune 500 corporations and the U.S. government. \u003cbr\u003e\u003c\/p\u003e \u003cp\u003eJoseph is a researcher and industry thought leader. He speaks regularly at international conferences, writes for technical magazines, and is involved with developing training for various industry certifications. He invented the fictitious character Emily Williams to create awareness around social engineering. Joseph runs The Security Blogger website, a popular resource for security and product implementation. He is the author of and contributor to several publications, including titles ranging from security best practices to exploitation tactics.\u003c\/p\u003e \u003cp\u003eWhen Joseph is not using technology, you can fi\u003c\/p\u003e","brand":"Pearson Education","offers":[{"title":"Default Title","offer_id":48864174145879,"sku":"9780136660606","price":47.73,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9780136660606.jpg?v=1722270738"},{"product_id":"security-in-computing-9780137891214","title":"Security in Computing","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cp\u003e\u003cstrong\u003eCharles P. Pfleeger\u003c\/strong\u003e is an internationally known expert on computer and communications security. He spent 14 years as professor of computer science at the University of Tennessee, before moving on to computer research and consulting company, Trusted Information Systems, where he was director of European operations and senior consultant. He was also director of research, member of the staff, and chief security officer at Cable and Wireless. He has chaired the IEEE Computer Society Technical Committee on Security and Privacy and was on the editorial board of IEEE \u003cem\u003eSecurity \u0026amp; Privacy\u003c\/em\u003e magazine.\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eShari Lawrence Pfleeger\u003c\/strong\u003e is a widely known software engineering and computer security researcher. She served as president of Systems\/Software and then as senior researcher with the Rand Corporation. As research director of the Institute for Information Infrastructure Protection, she oversaw large, high-impact computer security research projects for i\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e\u003c\/p\u003e\u003cp\u003e\u003cem\u003eForeword xix\u003c\/em\u003e\u003cbr\u003e\u003cem\u003ePreface xxv\u003c\/em\u003e\u003cbr\u003e\u003cem\u003eAcknowledgments xxxi\u003c\/em\u003e\u003cbr\u003e\u003cem\u003eAbout the Authors xxxiii\u003c\/em\u003e\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 1: Introduction 1\u003c\/strong\u003e\u003cbr\u003e1.1 What Is Computer Security? 3\u003cbr\u003e1.2 Threats 6\u003cbr\u003e1.3 Harm 24\u003cbr\u003e1.4 Vulnerabilities 30\u003cbr\u003e1.5 Controls 30\u003cbr\u003e1.6 Conclusion 33\u003cbr\u003e1.7 What's Next? 34\u003cbr\u003e1.8 Exercises 36\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 2: Toolbox: Authentication, Access Control, and Cryptography 38\u003c\/strong\u003e\u003cbr\u003e2.1 Authentication 40\u003cbr\u003e2.2 Access Control 78\u003cbr\u003e2.3 Cryptography 93\u003cbr\u003e2.4 Conclusion 137\u003cbr\u003e2.5 Exercises 138\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 3: Programs and Programming 141\u003c\/strong\u003e\u003cbr\u003e3.1 Unintentional (Nonmalicious) Programming Oversights 143\u003cbr\u003e3.2 Malicious Code--Malware 178\u003cbr\u003e3.3 Countermeasures 211\u003cbr\u003e3.4 Conclusion 245\u003cbr\u003e3.5 Exercises 245\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 4: The Internet--User Side 248\u003c\/strong\u003e\u003cbr\u003e4.1 Browser Attacks 251\u003cbr\u003e4.2 Attacks Targeting Users 265\u003cbr\u003e4.3 Obtaining User or Website Data 280\u003cbr\u003e4.4 Mobile Apps 289\u003cbr\u003e4.5 Email and Message Attacks 310\u003cbr\u003e4.6 Conclusion 320\u003cbr\u003e4.7 Exercises 321\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 5: Operating Systems 323\u003c\/strong\u003e\u003cbr\u003e5.1 Security in Operating Systems 323\u003cbr\u003e5.2 Security in the Design of Operating Systems 351\u003cbr\u003e5.3 Rootkits 371\u003cbr\u003e5.4 Conclusion 382\u003cbr\u003e5.5 Exercises 382\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 6: Networks 385\u003c\/strong\u003e\u003cbr\u003e6.1 Network Concepts 386\u003cbr\u003e\u003cem\u003ePart I--War on Networks: Network Security Attacks 399\u003c\/em\u003e\u003cbr\u003e6.2 Threats to Network Communications 400\u003cbr\u003e6.3 Wireless Network Security 421\u003cbr\u003e6.4 Denial of Service 443\u003cbr\u003e6.5 Distributed Denial of Service 468\u003cbr\u003e\u003cem\u003ePart II--Strategic Defenses: Security Countermeasures 479\u003c\/em\u003e\u003cbr\u003e6.6 Cryptography in Network Security 479\u003cbr\u003e6.7 Firewalls 497\u003cbr\u003e6.8 Intrusion Detection and Prevention Systems 522\u003cbr\u003e6.9 Network Management 536\u003cbr\u003e6.10 Conclusion 545\u003cbr\u003e6.11 Exercises 545\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 7: Data and Databases 549\u003c\/strong\u003e\u003cbr\u003e7.1 Introduction to Databases 550\u003cbr\u003e7.2 Security Requirements of Databases 555\u003cbr\u003e7.3 Reliability and Integrity 561\u003cbr\u003e7.4 Database Disclosure 566\u003cbr\u003e7.5 Data Mining and Big Data 585\u003cbr\u003e7.6 Conclusion 599\u003cbr\u003e7.7 Exercises 599\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 8: New Territory 601\u003c\/strong\u003e\u003cbr\u003e8.1 Introduction 601\u003cbr\u003e8.2 Cloud Architectures and Their Security 605\u003cbr\u003e8.3 IoT and Embedded Devices 627\u003cbr\u003e8.4 Cloud, IoT, and Embedded Devices--The Smart Home 638\u003cbr\u003e8.5 Smart Cities, IoT, Embedded Devices, and Cloud 643\u003cbr\u003e8.6 Cloud, IoT, and Critical Services 648\u003cbr\u003e8.7 Conclusion 657\u003cbr\u003e8.8 Exercises 658\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 9: Privacy 659\u003c\/strong\u003e\u003cbr\u003e9.1 Privacy Concepts 660\u003cbr\u003e9.2 Privacy Principles and Policies 671\u003cbr\u003e9.3 Authentication and Privacy 688\u003cbr\u003e9.4 Data Mining 694\u003cbr\u003e9.5 Privacy on the Internet 698\u003cbr\u003e9.6 Email and Message Security 713\u003cbr\u003e9.7 Privacy Impacts of Newer Technologies 717\u003cbr\u003e9.8 Conclusion 724\u003cbr\u003e9.9 Exercises 725\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 10: Management and Incidents 727\u003c\/strong\u003e\u003cbr\u003e10.1 Security Planning 727\u003cbr\u003e10.2 Business Continuity Planning 738\u003cbr\u003e10.3 Handling Incidents 742\u003cbr\u003e10.4 Risk Analysis 749\u003cbr\u003e10.5 Physical Threats to Systems 767\u003cbr\u003e10.6 New Frontiers in Security Management 776\u003cbr\u003e10.7 Conclusion 778\u003cbr\u003e10.8 Exercises 779\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 11: Legal Issues and Ethics 781\u003c\/strong\u003e\u003cbr\u003e11.1 Protecting Programs and Data 783\u003cbr\u003e11.2 Information and the Law 800\u003cbr\u003e11.3 Rights of Employees and Employers 805\u003cbr\u003e11.4 Redress for Software Failures 808\u003cbr\u003e11.5 Computer Crime 814\u003cbr\u003e11.6 Ethical Issues in Computer Security 822\u003cbr\u003e11.7 An Ethical Dive into Artificial Intelligence 828\u003cbr\u003e11.8 Incident Analyses with Ethics 830\u003cbr\u003e11.9 Conclusion 846\u003cbr\u003e11.10 Exercises 847\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 12: Details of Cryptography 850\u003c\/strong\u003e\u003cbr\u003e12.1 Cryptology 851\u003cbr\u003e12.2 Symmetric Encryption Algorithms 863\u003cbr\u003e12.3 Asymmetric Encryption 877\u003cbr\u003e12.4 Message Digests 883\u003cbr\u003e12.5 Digital Signatures 888\u003cbr\u003e12.6 Quantum Key Distribution 889\u003cbr\u003e12.7 Conclusion 894\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 13: Emerging Topics 895\u003c\/strong\u003e\u003cbr\u003e13.1 AI and Cybersecurity 896\u003cbr\u003e13.2 Blockchains and Cryptocurrencies 908\u003cbr\u003e13.3 Offensive Cyber and Cyberwarfare 924\u003cbr\u003e13.4 Quantum Computing and Computer Security 936\u003cbr\u003e13.5 Conclusion 937\u003c\/p\u003e \u003cp\u003e\u003cem\u003eBibliography 939\u003c\/em\u003e\u003cbr\u003e\u003cem\u003eIndex 963\u003c\/em\u003e\u003c\/p\u003e","brand":"Pearson Education (US)","offers":[{"title":"Default Title","offer_id":48864176472407,"sku":"9780137891214","price":85.72,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9780137891214.jpg?v=1722270749"},{"product_id":"zero-trust-architecture-9780137899739","title":"Zero Trust Architecture","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cp\u003e\u003cstrong\u003eCindy Green-Ortiz\u003c\/strong\u003e is a Cisco senior security architect, cybersecurity strategist, architect, and entrepreneur. She works in the Customer Experience, Global Enterprise Segment for Cisco. She holds the CISSP, CISM, CSSLP, CRISC, PMP, and CSM Certifications, along with two degreesa BS-CIS Magna Cum Laude and AS-CIS with Honors. She has been with Cisco for 6+ years. Cindy has been in the cybersecurity field for 40 years, where she has held D-CIO, D-CISO, and Corporate Security Architecture Leadership roles, founding two technology businesses as CEO. Cindy is a Cisco Chairman's Club winner (Club Cisco). She is an active blogger for Cisco and has published whitepapers for Cisco and the US Department of Homeland Security. She has spoken to many groups, including PMI International Information Systems \u0026amp; Technology Symposium-Cybersecurity Keynote; Cisco SecCon, and Cisco Live. Cindy is President Emeritus and serves now as the treasurer of Charlotte InfraGard and cofounder of \u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003eForeword Introduction Part I: Concepts 1. Overview of Zero Trust (ZT): It's a Journey 2. Cisco Zero Trust: Security Capability Requirements 3. Zero Trust Reference Architecture and Enclave Design 4. Security Capability Use Cases 5. Segmentation Part II: Implementation 6. Segmentation Methods: Pros and Cons 7. Segmentation Foundational Functions and Applications (CMDB, App Inv, VLAN, Host Naming) 8. Map Functions to Segments \/ Implement Solutions 9. Test and Monitor ZT Segmentation and Solutions (LLD \/ SVS) - Phased Conclusion (Journey) Afterword Bibliography Acknowledgements\u003c\/p\u003e","brand":"Pearson Education (US)","offers":[{"title":"Default Title","offer_id":48864176505175,"sku":"9780137899739","price":40.49,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9780137899739.jpg?v=1722270749"},{"product_id":"cybersecurity-myths-and-misconceptions-9780137929238","title":"Cybersecurity Myths and Misconceptions","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cp\u003e\u003cstrong\u003eEugene H. Spafford\u003c\/strong\u003e, PhD, is a professor in Computer Science at Purdue University. In his 35-year career, Spaf has been honored with every major award in cybersecurity. \u003cstrong\u003eLeigh Metcalf\u003c\/strong\u003e, PhD, is a Senior Network Security Research Analyst at the Carnegie Mellon University Software Engineering Institute's cybersecurity-focused CERT division. \u003cstrong\u003eJosiah Dykstra\u003c\/strong\u003e, PhD, is a cybersecurity practitioner, researcher, author, and speaker. He is the owner of Designer Security and has worked at the US National Security Agency for 18 years.\u003c\/p\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTrade Review\u003c\/b\u003e\u003cbr\u003e\u003cp\u003e\"Many security leaders are traditionally in charge of correcting misconceptions just as much as they are in charge of building up solid security practices. We have plenty of resources on practices--but this book is the crucial guide to that essential myth busting.\"\u003cbr\u003e\u003cem\u003e--\u003cstrong\u003ePhil Venables\u003c\/strong\u003e, CISO, Google Cloud\u003c\/em\u003e\u003c\/p\u003e \u003cp\u003e\"I'm writing this on my phone, over Wi-Fi, in an airplane on my way to Black Hat, one of the world's largest security conferences. The fact that I'm able to do this at all shows how much we've really learned about cybersecurity over the decades. Now it's all collected in one place for everyone to share. Thank the wise authors, and most importantly: GET OFF THEIR LAWN.\"\u003cbr\u003e\u003cem\u003e--\u003cstrong\u003eWendy Nather\u003c\/strong\u003e, Head of Advisory CISOs, Cisco\u003c\/em\u003e\u003c\/p\u003e \u003cp\u003e\"This book is astounding. A true tour de force--which I have never said about any other book. Inverting the viewpoint is a stroke of genius. This is going to be on my grabbable-at-any-time shelf. What I learned, recalled, and was refreshed on with technically astute agnosticism cannot be measured; just appreciated as a profound historical compilation of security practice and theory. Bravo!\"\u003cbr\u003e\u003cem\u003e--\u003cstrong\u003eWinn Schwartaul\u003c\/strong\u003e, Founder and Chief Visionary Officer, The Security Awareness Company\u003c\/em\u003e\u003c\/p\u003e \u003cp\u003e\"I am happy to endorse the central idea of this book--that cybersecurity is rife with myths that are themselves part of the problem. The brain wants to understand, the world grows ever more complicated, and the sum of the two is myth-making. As the authors say, even if some understanding is true at some time, with enough change what was true becomes a myth soon enough. As such, an acquired immunity to myths is a valuable skill for the cybersecurity practitioner if no other. The paramount goal of all security engineering is No Silent Failure, but myths perpetuate if not create silent failure. Why? Because a state of security is the absence of unmitigable surprise and you cannot mitigate what you don't know is going on. Myths blind us to reality. Ignorance of them is not bliss. This book is a vaccine.\"\u003cbr\u003e\u003cem\u003e--\u003cstrong\u003eDan Geer\u003c\/strong\u003e, CISO, In-Q-Tel\u003c\/em\u003e\u003c\/p\u003e \u003cp\u003e\"This is a fun read for all levels. I like their rapid fire delivery and the general light they cast on so many diverse myths. This book will change the cybersecurity industry for the better.\"\u003cbr\u003e\u003cem\u003e--\u003cstrong\u003eMichael Sikorski\u003c\/strong\u003e, Author of\u003c\/em\u003e Practical Malware Analysis \u003cem\u003e\u0026amp; CTO, Unit 42 at Palo Alto Networks\u003c\/em\u003e\u003c\/p\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e\u003cp\u003e\u003cem\u003eForeword by Vint Cerf xxiii\u003c\/em\u003e\u003cbr\u003e\u003cem\u003eIntroduction xxiv\u003c\/em\u003e\u003cbr\u003e\u003cem\u003eAcknowledgments xxxiii\u003c\/em\u003e\u003cbr\u003e\u003cem\u003eAbout the Authors xxxiv\u003c\/em\u003e\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003ePart I: General Issues 1\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 1: What Is Cybersecurity? 2\u003c\/strong\u003e\u003cbr\u003eEveryone Knows What \"Cybersecurity\" Means 2\u003cbr\u003eWe Can Measure How Secure Our Systems Are 5\u003cbr\u003eThe Primary Goal of Cybersecurity Is Security 11\u003cbr\u003eCybersecurity Is About Obvious Risks 12\u003cbr\u003eSharing More Cyber Threat Intel Will Make Things Better 14\u003cbr\u003eWhat Matters to You Matters to Everyone Else 16\u003cbr\u003eProduct X Will Make You Secure 17\u003cbr\u003eMacs Are Safer Than PCs, Linux Is Safer Than Windows 18\u003cbr\u003eOpen Source Software Is More Secure Than Closed Source Software 19\u003cbr\u003eTechnology X Will Make You Secure 20\u003cbr\u003eProcess X Will Make You Secure 21\u003cbr\u003eFærie Dust Can Make Old Ideas Magically Revolutionary 22\u003cbr\u003ePasswords Should Be Changed Often 23\u003cbr\u003eBelieve and Fear Every Hacking Demo You See 26\u003cbr\u003eCyber Offense Is Easier Than Defense 27\u003cbr\u003eOperational Technology (OT) Is Not Vulnerable 29\u003cbr\u003eBreaking Systems Is the Best Way to Establish Yourself 30\u003cbr\u003eBecause You Can, You Should 30\u003cbr\u003eBetter Security Means Worse Privacy 32\u003cbr\u003eFurther Reading 33\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 2: What Is the Internet? 36\u003c\/strong\u003e\u003cbr\u003eEveryone Knows What the \"Internet\" Means 36\u003cbr\u003eAn IP Address Identifies a Unique Machine 37\u003cbr\u003eThe Internet Is Managed and Controlled by a Central Body 39\u003cbr\u003eThe Internet Is Largely Static 40\u003cbr\u003eYour Network Is Static 41\u003cbr\u003eEmail Is Private 43\u003cbr\u003eCryptocurrency Is Untraceable 44\u003cbr\u003eEverything Can Be Fixed with Blockchain 46\u003cbr\u003eThe Internet Is Like an Iceberg 46\u003cbr\u003eA VPN Makes You Anonymous 48\u003cbr\u003eA Firewall Is Enough 49\u003cbr\u003eFurther Reading 51\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003ePart II: Human Issues 55\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 3: Faulty Assumptions and Magical Thinking 56\u003c\/strong\u003e\u003cbr\u003eHumans Will Behave Rationally, So Blame the User! 57\u003cbr\u003eWe Know Everything We Need to Know About Cybersecurity Problems 62\u003cbr\u003eCompliance Equals (Complete) Security 63\u003cbr\u003eAuthentication Provides Confidentiality 65\u003cbr\u003eI Can Never Be Secure, So Why Bother? 65\u003cbr\u003eI Am Too Small\/Insignificant to Be a Target 66\u003cbr\u003eEverybody Is Out to Get Me 69\u003cbr\u003eI Engage Only with Trusted Websites, So My Data Is Safe from a Breach 71\u003cbr\u003eSecurity by Obscurity Is Reasonably Secure 72\u003cbr\u003eThe Illusions of Visibility and Control 74\u003cbr\u003eFive 9's Is the Key to Cybersecurity 76\u003cbr\u003eEverybody Has Top-of-the-Line Technology 78\u003cbr\u003eWe Can Predict Future Threats 80\u003cbr\u003eSecurity People Control Security Outcomes 81\u003cbr\u003eAll Bad Outcomes Are the Result of a Bad Decision 82\u003cbr\u003eMore Security Is Always Better 84\u003cbr\u003eBest Practices Are Always Best 85\u003cbr\u003eBecause It Is Online It Must Be True\/Correct 86\u003cbr\u003eFurther Reading 87\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 4: Fallacies and Misunderstandings 88\u003c\/strong\u003e\u003cbr\u003eThe False Cause Fallacy: Correlation Is Causation 89\u003cbr\u003eAbsence of Evidence Is Evidence of Absence 92\u003cbr\u003eThe Straw Hacker Fallacy 94\u003cbr\u003e\u003cem\u003eAd Hominem\u003c\/em\u003e Fallacy 95\u003cbr\u003eHasty Generalization Fallacy 96\u003cbr\u003eRegression Fallacy 97\u003cbr\u003eBase Rate Fallacy 98\u003cbr\u003eGambler's Fallacy 100\u003cbr\u003eFallacies of Anomalies 100\u003cbr\u003eIgnorance of Black Swans 101\u003cbr\u003eConjunction and Disjunction Fallacies 103\u003cbr\u003eValence Effect 104\u003cbr\u003eEndowment Effect 104\u003cbr\u003eSunk Cost Fallacy 105\u003cbr\u003eBonus Fallacies 107\u003cbr\u003eFurther Reading 109\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 5: Cognitive Biases 110\u003c\/strong\u003e\u003cbr\u003eAction Bias 112\u003cbr\u003eOmission Bias 113\u003cbr\u003eSurvivorship Bias 115\u003cbr\u003eConfirmation Bias 116\u003cbr\u003eChoice Affirmation Bias 117\u003cbr\u003eHindsight Bias 117\u003cbr\u003eAvailability Bias 119\u003cbr\u003eSocial Proof 121\u003cbr\u003eOverconfidence Bias 122\u003cbr\u003eZero Risk Bias 123\u003cbr\u003eFrequency Bias 124\u003cbr\u003eBonus Biases 125\u003cbr\u003eFurther Reading 128\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 6: Perverse Incentives and the Cobra Effect 130\u003c\/strong\u003e\u003cbr\u003eThe Goal of a Security Vendor Is to Keep You Secure 131\u003cbr\u003eYour Cybersecurity Decisions Affect Only You 132\u003cbr\u003eBug Bounties Eliminate Bugs from the Offensive Market 134\u003cbr\u003eCyber Insurance Causes People to Take Less Risk 135\u003cbr\u003eFines and Penalties Cause People to Take Less Risk 136\u003cbr\u003eAttacking Back Would Help Stop Cyber Crime 137\u003cbr\u003eInnovation Increases Security and Privacy Incidents 138\u003cbr\u003eFurther Reading 139\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 7: Problems and Solutions 140\u003c\/strong\u003e\u003cbr\u003eFailure Is Not an Option in Cybersecurity 141\u003cbr\u003eEvery Problem Has a Solution 142\u003cbr\u003eAnecdotes Are Good Leads for Cybersecurity Solutions 147\u003cbr\u003eDetecting More \"Bad Stuff\" Means the New Thing Is an Improvement 148\u003cbr\u003eEvery Security Process Should Be Automated 149\u003cbr\u003eProfessional Certifications Are Useless 151\u003cbr\u003eFurther Reading 158\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003ePart III: Contextual Issues 161\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 8: Pitfalls of Analogies and Abstractions 162\u003c\/strong\u003e\u003cbr\u003eCybersecurity Is Like the Physical World 165\u003cbr\u003eCybersecurity Is Like Medicine and Biology 170\u003cbr\u003eCybersecurity Is Like Fighting a War 172\u003cbr\u003eCybersecurity Law Is Analogous to Physical-World Law 175\u003cbr\u003eTips for Analogies and Abstractions 175\u003cbr\u003eFurther Reading 178\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 9: Legal Issues 180\u003c\/strong\u003e\u003cbr\u003eCybersecurity Law Is Analogous to Physical-World Law 181\u003cbr\u003eYour Laws Do Not Apply to Me Where I Am 182\u003cbr\u003eThat Violates My First Amendment Rights! 184\u003cbr\u003eLegal Code Supersedes Computer Code 186\u003cbr\u003eLaw Enforcement Will Never Respond to Cyber Crimes 191\u003cbr\u003eYou Can Always Hide Information by Suing 193\u003cbr\u003eSuing to Suppress a Breach Is a Good Idea 194\u003cbr\u003eTerms and Conditions Are Meaningless 194\u003cbr\u003eThe Law Is on My Side, So I Do Not Need to Worry 195\u003cbr\u003eFurther Reading 196\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 10: Tool Myths and Misconceptions 198\u003c\/strong\u003e\u003cbr\u003eThe More Tools, The Better 199\u003cbr\u003eDefault Configurations Are Always Secure 201\u003cbr\u003eA Tool Can Stop All Bad Things 203\u003cbr\u003eIntent Can Be Determined from Tools 205\u003cbr\u003eSecurity Tools Are Inherently Secure and Trustworthy 207\u003cbr\u003eNothing Found Means All Is Well 209\u003cbr\u003eFurther Reading 212\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 11: Vulnerabilities 214\u003c\/strong\u003e\u003cbr\u003eWe Know Everything There Is to Know About Vulnerabilities 215\u003cbr\u003eVulnerabilities Are Sparse 218\u003cbr\u003eAttackers Are Getting More Proficient 218\u003cbr\u003eZero-Day Vulnerabilities Are Most Important 219\u003cbr\u003eAll Attacks Hinge on a Vulnerability 223\u003cbr\u003eExploits and Proofs of Concept Are Bad 226\u003cbr\u003eVulnerabilities Happen Only in Complex Code 228\u003cbr\u003eFirst Movers Should Sacrifice Security 230\u003cbr\u003ePatches Are Always Perfect and Available 231\u003cbr\u003eDefenses Might Become Security Vulnerabilities with Time 236\u003cbr\u003eAll Vulnerabilities Can Be Fixed 237\u003cbr\u003eScoring Vulnerabilities Is Easy and Well Understood 239\u003cbr\u003eBecause You Can, You Should--Vulnerabilities Edition 240\u003cbr\u003eVulnerability Names Reflect Their Importance 241\u003cbr\u003eFurther Reading 242\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 12: Malware 244\u003c\/strong\u003e\u003cbr\u003eUsing a Sandbox Will Tell Me Everything I Need to Know 246\u003cbr\u003eReverse Engineering Will Tell Me Everything I Need to Know 249\u003cbr\u003eMalware and Geography Are\/Are Not Related 251\u003cbr\u003eI Can Always Determine Who Made the Malware and Attacked Me 253\u003cbr\u003eMalware Is Always a Complex Program That Is Difficult to Understand 254\u003cbr\u003eFree Malware Protection Is Good Enough 256\u003cbr\u003eOnly Shady Websites Will Infect Me 257\u003cbr\u003eBecause You Can, You Should--Malware Edition 258\u003cbr\u003eRansomware Is an Entirely New Kind of Malware 259\u003cbr\u003eSigned Software Is Always Trustworthy 261\u003cbr\u003eMalware Names Reflect Their Importance 263\u003cbr\u003eFurther Reading 264\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 13: Digital Forensics and Incident Response 266\u003c\/strong\u003e\u003cbr\u003eMovies and Television Reflect the Reality of Cyber 267\u003cbr\u003eIncidents Are Discovered as Soon as They Occur 269\u003cbr\u003eIncidents Are Discrete and Independent 270\u003cbr\u003eEvery Incident Is the Same Severity 271\u003cbr\u003eStandard Incident Response Techniques Can Deal with Ransomware 272\u003cbr\u003eIncident Responders Can Flip a Few Switches and Magically Everything\u003cbr\u003eIs Fixed 273\u003cbr\u003eAttacks Are Always Attributable 276\u003cbr\u003eAttribution Is Essential 278\u003cbr\u003eMost Attacks\/Exfiltration of Data Originate from Outside the Organization 280\u003cbr\u003eThe Trojan Horse Defense Is Dead 281\u003cbr\u003eEndpoint Data Is Sufficient for Incident Detection 282\u003cbr\u003eRecovering from an Event Is a Simple and Linear Process 284\u003cbr\u003eFurther Reading 285\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003ePart IV: Data Issues 287\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 14: Lies, Damn Lies, and Statistics 288\u003c\/strong\u003e\u003cbr\u003eLuck Prevents Cyber Attacks 289\u003cbr\u003eThe Numbers Speak for Themselves 290\u003cbr\u003eProbability Is Certainty 290\u003cbr\u003eStatistics Are Laws 293\u003cbr\u003eData Is Not Important to Statistics 303\u003cbr\u003eArtificial Intelligence and Machine Learning Can Solve All\u003cbr\u003eCybersecurity Problems 306\u003cbr\u003eFurther Reading 310\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 15: Illustrations, Visualizations, and Delusions 312\u003c\/strong\u003e\u003cbr\u003eVisualizations and Dashboards Are Inherently and Universally Helpful 313\u003cbr\u003eCybersecurity Data Is Easy to Visualize 319\u003cbr\u003eFurther Reading 324\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 16: Finding Hope 326\u003c\/strong\u003e\u003cbr\u003eCreating a Less Myth-Prone World 328\u003cbr\u003eThe Critical Value of Documentation 329\u003cbr\u003eMeta-Myths and Recommendations 331\u003cbr\u003eAvoiding Other and Future Traps 334\u003cbr\u003eParting Thoughts 334\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eAppendix: Short Background Explanations 336\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e\u003cem\u003eAcronyms 344\u003c\/em\u003e\u003cbr\u003e\u003cem\u003eIndex 350\u003c\/em\u003e\u003c\/p\u003e","brand":"Pearson Education (US)","offers":[{"title":"Default Title","offer_id":48864176800087,"sku":"9780137929238","price":29.69,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9780137929238.jpg?v=1722270751"},{"product_id":"computer-security-fundamentals-9780137984787","title":"Computer Security Fundamentals","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cp\u003e\u003cstrong\u003eDr. Chuck Easttom \u003c\/strong\u003eis the author of 37 books, including several on computer security, forensics, and cryptography. He has also authored scientific papers on digital forensics, cyber warfare, cryptography, and applied mathematics. He is an inventor with 25 computer science patents. He holds a doctor of science degree in cybersecurity (dissertation topic: a study of lattice-based algorithms for post quantum cryptography), a Ph.D. in Computer Science (dissertation topic: A Systematic Framework for Network Forensics Using Graph Theory), and a Ph.D. in Nanotechnology (dissertation topic: The Effects of Complexity on Carbon Nanotube Failures) and three master's degrees (one in applied computer science, one in education, and one in systems engineering). He also holds more than 70 industry certifications (CISSP, CEH, etc.). He is a frequent speaker at cybersecurity, computer science, and engineering conferences. He is a Distinguished Speaker and senior member of the ACM and \u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e\u003c\/p\u003e\u003cp\u003e\u003cstrong\u003eIntroduction xxix\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 1: Introduction to Computer Security 2\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e            Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2\u003c\/p\u003e \u003cp\u003e            How Seriously Should You Take Threats to Network Security?. . . . . . . . . . 4\u003c\/p\u003e \u003cp\u003e            Identifying Types of Threats.. . . . . . . . . . . . . . . . . . . . . . . . 7\u003c\/p\u003e \u003cp\u003e            Assessing the Likelihood of an Attack on Your Network.. . . . . . . . . . . . 17\u003c\/p\u003e \u003cp\u003e            Basic Security Terminology. . . . . . . . . . . . . . . . . . . . . . . . 18\u003c\/p\u003e \u003cp\u003e            Concepts and Approaches.. . . . . . . . . . . . . . . . . . . . . . . . 21\u003c\/p\u003e \u003cp\u003e            How Do Legal Issues Impact Network Security?.. . . . . . . . . . . . . . . 24\u003c\/p\u003e \u003cp\u003e            Online Security Resources.. . . . . . . . . . . . . . . . . . . . . . . . 25\u003c\/p\u003e \u003cp\u003e            Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 2: Networks and the Internet 34\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e            Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34\u003c\/p\u003e \u003cp\u003e            Network Basics.. . . . . . . . . . . . . . . . . . . . . . . . . . . . 35\u003c\/p\u003e \u003cp\u003e            How the Internet Works. . . . . . . . . . . . . . . . . . . . . . . . . 43\u003c\/p\u003e \u003cp\u003e            History of the Internet.. . . . . . . . . . . . . . . . . . . . . . . . . . 50\u003c\/p\u003e \u003cp\u003e            Basic Network Utilities.. . . . . . . . . . . . . . . . . . . . . . . . . 52\u003c\/p\u003e \u003cp\u003e            Other Network Devices.. . . . . . . . . . . . . . . . . . . . . . . . . 59\u003c\/p\u003e \u003cp\u003e            Advanced Network Communications Topics.. . . . . . . . . . . . . . . . 60\u003c\/p\u003e \u003cp\u003e            Cloud Computing. . . . . . . . . . . . . . . . . . . . . . . . . . . . 61\u003c\/p\u003e \u003cp\u003e            Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 65\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 3: Cyber Stalking, Fraud, and Abuse 74\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e            Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 74\u003c\/p\u003e \u003cp\u003e            How Internet Fraud Works.. . . . . . . . . . . . . . . . . . . . . . . . 75\u003c\/p\u003e \u003cp\u003e            Identity Theft.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 80\u003c\/p\u003e \u003cp\u003e            Cyber Stalking.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 82\u003c\/p\u003e \u003cp\u003e            Protecting Yourself Against Cybercrime.. . . . . . . . . . . . . . . . . . 91\u003c\/p\u003e \u003cp\u003e            Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 99\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 4: Denial of Service Attacks 106\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e            Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 106\u003c\/p\u003e \u003cp\u003e            DoS Attacks.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 107\u003c\/p\u003e \u003cp\u003e            Illustrating an Attack.. . . . . . . . . . . . . . . . . . . . . . . . . . 107\u003c\/p\u003e \u003cp\u003e            Common Tools Used for DoS Attacks.. . . . . . . . . . . . . . . . . . . 109\u003c\/p\u003e \u003cp\u003e            DoS Weaknesses.. . . . . . . . . . . . . . . . . . . . . . . . . . . 112\u003c\/p\u003e \u003cp\u003e            Specific DoS Attacks. . . . . . . . . . . . . . . . . . . . . . . . . . 112\u003c\/p\u003e \u003cp\u003e            Real-World Examples of DoS Attacks.. . . . . . . . . . . . . . . . . . . 120\u003c\/p\u003e \u003cp\u003e            How to Defend Against DoS Attacks.. . . . . . . . . . . . . . . . . . . 121\u003c\/p\u003e \u003cp\u003e            Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 123\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 5: Malware 130\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e            Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 130\u003c\/p\u003e \u003cp\u003e            Viruses.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 131\u003c\/p\u003e \u003cp\u003e            Trojan Horses.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 142\u003c\/p\u003e \u003cp\u003e            The Buffer-Overflow Attack. . . . . . . . . . . . . . . . . . . . . . . 145\u003c\/p\u003e \u003cp\u003e            Spyware.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 146\u003c\/p\u003e \u003cp\u003e            Other Forms of Malware.. . . . . . . . . . . . . . . . . . . . . . . . 149\u003c\/p\u003e \u003cp\u003e            Detecting and Eliminating Viruses and Spyware. . . . . . . . . . . . . . . 153\u003c\/p\u003e \u003cp\u003e            Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 159\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 6: Techniques Used by Hackers 166\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e            Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 166\u003c\/p\u003e \u003cp\u003e            Basic Terminology.. . . . . . . . . . . . . . . . . . . . . . . . . . . 167\u003c\/p\u003e \u003cp\u003e            The Reconnaissance Phase.. . . . . . . . . . . . . . . . . . . . . . . 167\u003c\/p\u003e \u003cp\u003e            Actual Attacks.. . . . . . . . . . . . . . . . . . . . . . . . . . . . 177\u003c\/p\u003e \u003cp\u003e            Malware Creation. . . . . . . . . . . . . . . . . . . . . . . . . . . 184\u003c\/p\u003e \u003cp\u003e            Penetration Testing.. . . . . . . . . . . . . . . . . . . . . . . . . . 187\u003c\/p\u003e \u003cp\u003e            The Dark Web. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 189\u003c\/p\u003e \u003cp\u003e            Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 194\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 7: Industrial Espionage in Cyberspace 200\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e            Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 200\u003c\/p\u003e \u003cp\u003e            What Is Industrial Espionage?.. . . . . . . . . . . . . . . . . . . . . . 202\u003c\/p\u003e \u003cp\u003e            Information as an Asset. . . . . . . . . . . . . . . . . . . . . . . . . 203\u003c\/p\u003e \u003cp\u003e            Real-World Examples of Industrial Espionage.. . . . . . . . . . . . . . . 205\u003c\/p\u003e \u003cp\u003e            How Does Espionage Occur?. . . . . . . . . . . . . . . . . . . . . . 207\u003c\/p\u003e \u003cp\u003e            Protecting Against Industrial Espionage.. . . . . . . . . . . . . . . . . . 212\u003c\/p\u003e \u003cp\u003e            Trade Secrets.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 215\u003c\/p\u003e \u003cp\u003e            The Industrial Espionage Act.. . . . . . . . . . . . . . . . . . . . . . 218\u003c\/p\u003e \u003cp\u003e            Spear Phishing.. . . . . . . . . . . . . . . . . . . . . . . . . . . . 219\u003c\/p\u003e \u003cp\u003e            Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 220\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 8: Encryption 226\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e            Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 226\u003c\/p\u003e \u003cp\u003e            Cryptography Basics.. . . . . . . . . . . . . . . . . . . . . . . . . . 227\u003c\/p\u003e \u003cp\u003e            History of Encryption.. . . . . . . . . . . . . . . . . . . . . . . . . . 228\u003c\/p\u003e \u003cp\u003e            Modern Cryptography Methods.. . . . . . . . . . . . . . . . . . . . . 236\u003c\/p\u003e \u003cp\u003e            Public Key (Asymmetric) Encryption.. . . . . . . . . . . . . . . . . . . 245\u003c\/p\u003e \u003cp\u003e            PGP. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 250\u003c\/p\u003e \u003cp\u003e            Legitimate Versus Fraudulent Encryption Methods.. . . . . . . . . . . . . 251\u003c\/p\u003e \u003cp\u003e            Digital Signatures. . . . . . . . . . . . . . . . . . . . . . . . . . . 252\u003c\/p\u003e \u003cp\u003e            Hashing. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 253\u003c\/p\u003e \u003cp\u003e            MAC and HMAC.. . . . . . . . . . . . . . . . . . . . . . . . . . . 254\u003c\/p\u003e \u003cp\u003e            Steganography. . . . . . . . . . . . . . . . . . . . . . . . . . . . 255\u003c\/p\u003e \u003cp\u003e            Cryptanalysis.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 257\u003c\/p\u003e \u003cp\u003e            Cryptography Used on the Internet.. . . . . . . . . . . . . . . . . . . . 259\u003c\/p\u003e \u003cp\u003e            Quantum Computing Cryptography. . . . . . . . . . . . . . . . . . . . 259\u003c\/p\u003e \u003cp\u003e            Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 261\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 9: Computer Security Technology 268\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e            Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 268\u003c\/p\u003e \u003cp\u003e            Virus Scanners.. . . . . . . . . . . . . . . . . . . . . . . . . . . . 269\u003c\/p\u003e \u003cp\u003e            Firewalls.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 272\u003c\/p\u003e \u003cp\u003e            Antispyware.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 278\u003c\/p\u003e \u003cp\u003e            IDSs. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 279\u003c\/p\u003e \u003cp\u003e            Digital Certificates.. . . . . . . . . . . . . . . . . . . . . . . . . . . 292\u003c\/p\u003e \u003cp\u003e            SSL\/TLS.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 293\u003c\/p\u003e \u003cp\u003e            Virtual Private Networks.. . . . . . . . . . . . . . . . . . . . . . . . 296\u003c\/p\u003e \u003cp\u003e            Wi-Fi Security. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 298\u003c\/p\u003e \u003cp\u003e            Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 299\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 10: Security Policies 304\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e            Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 304\u003c\/p\u003e \u003cp\u003e            What Is a Policy?.. . . . . . . . . . . . . . . . . . . . . . . . . . . 305\u003c\/p\u003e \u003cp\u003e            Important Standards.. . . . . . . . . . . . . . . . . . . . . . . . . . 305\u003c\/p\u003e \u003cp\u003e            Defining User Policies.. . . . . . . . . . . . . . . . . . . . . . . . . 308\u003c\/p\u003e \u003cp\u003e            Defining System Administration Policies.. . . . . . . . . . . . . . . . . . 316\u003c\/p\u003e \u003cp\u003e            Security Breaches.. . . . . . . . . . . . . . . . . . . . . . . . . . . 319\u003c\/p\u003e \u003cp\u003e            Defining Access Control.. . . . . . . . . . . . . . . . . . . . . . . . 321\u003c\/p\u003e \u003cp\u003e            Development Policies.. . . . . . . . . . . . . . . . . . . . . . . . . 322\u003c\/p\u003e \u003cp\u003e            Standards, Guidelines, and Procedures.. . . . . . . . . . . . . . . . . . 323\u003c\/p\u003e \u003cp\u003e            Disaster Recovery.. . . . . . . . . . . . . . . . . . . . . . . . . . . 324\u003c\/p\u003e \u003cp\u003e            Zero Trust.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 327\u003c\/p\u003e \u003cp\u003e            Important Laws.. . . . . . . . . . . . . . . . . . . . . . . . . . . . 328\u003c\/p\u003e \u003cp\u003e            Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 330\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 11: Network Scanning and Vulnerability Scanning 336\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e            Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 336\u003c\/p\u003e \u003cp\u003e            Basics of Assessing a System.. . . . . . . . . . . . . . . . . . . . . . 337\u003c\/p\u003e \u003cp\u003e            Securing Computer Systems.. . . . . . . . . . . . . . . . . . . . . . 346\u003c\/p\u003e \u003cp\u003e            Scanning Your Network. . . . . . . . . . . . . . . . . . . . . . . . . 352\u003c\/p\u003e \u003cp\u003e            Testing and Scanning Standards.. . . . . . . . . . . . . . . . . . . . . 363\u003c\/p\u003e \u003cp\u003e            Getting Professional Help.. . . . . . . . . . . . . . . . . . . . . . . . 366\u003c\/p\u003e \u003cp\u003e            Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 369\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 12: Cyber Terrorism and Information Warfare 378\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e            Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 378\u003c\/p\u003e \u003cp\u003e            Actual Cases of Cyber Terrorism.. . . . . . . . . . . . . . . . . . . . . 379\u003c\/p\u003e \u003cp\u003e            Weapons of Cyber Warfare.. . . . . . . . . . . . . . . . . . . . . . . 382\u003c\/p\u003e \u003cp\u003e            Economic Attacks.. . . . . . . . . . . . . . . . . . . . . . . . . . . 384\u003c\/p\u003e \u003cp\u003e            Military Operations Attacks. . . . . . . . . . . . . . . . . . . . . . . 386\u003c\/p\u003e \u003cp\u003e            General Attacks.. . . . . . . . . . . . . . . . . . . . . . . . . . . . 387\u003c\/p\u003e \u003cp\u003e            Supervisory Control and Data Acquisitions (SCADA).. . . . . . . . . . . . . 387\u003c\/p\u003e \u003cp\u003e            Information Warfare.. . . . . . . . . . . . . . . . . . . . . . . . . . 388\u003c\/p\u003e \u003cp\u003e            Actual Cases of Cyber Terrorism.. . . . . . . . . . . . . . . . . . . . . 391\u003c\/p\u003e \u003cp\u003e            Future Trends.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 395\u003c\/p\u003e \u003cp\u003e            Defense Against Cyber Terrorism.. . . . . . . . . . . . . . . . . . . . . 399\u003c\/p\u003e \u003cp\u003e            Terrorist Recruiting and Communication.. . . . . . . . . . . . . . . . . . 399\u003c\/p\u003e \u003cp\u003e            TOR and the Dark Web.. . . . . . . . . . . . . . . . . . . . . . . . . 400\u003c\/p\u003e \u003cp\u003e            Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 402\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 13: Cyber Detective 408\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e            Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 408\u003c\/p\u003e \u003cp\u003e            General Searches. . . . . . . . . . . . . . . . . . . . . . . . . . . 410\u003c\/p\u003e \u003cp\u003e            Company Searches.. . . . . . . . . . . . . . . . . . . . . . . . . . 413\u003c\/p\u003e \u003cp\u003e            Court Records and Criminal Checks.. . . . . . . . . . . . . . . . . . . 413\u003c\/p\u003e \u003cp\u003e            Usenet. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 417\u003c\/p\u003e \u003cp\u003e            Google.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 418\u003c\/p\u003e \u003cp\u003e            Maltego. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 418\u003c\/p\u003e \u003cp\u003e            Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 421\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 14: Introduction to Forensics 426\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e            Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 426\u003c\/p\u003e \u003cp\u003e            General Guidelines. . . . . . . . . . . . . . . . . . . . . . . . . . . 427\u003c\/p\u003e \u003cp\u003e            Finding Evidence on a PC. . . . . . . . . . . . . . . . . . . . . . . . 440\u003c\/p\u003e \u003cp\u003e            Finding Evidence in System Logs.. . . . . . . . . . . . . . . . . . . . 441\u003c\/p\u003e \u003cp\u003e            Getting Back Deleted Files.. . . . . . . . . . . . . . . . . . . . . . . 442\u003c\/p\u003e \u003cp\u003e            Operating System Utilities. . . . . . . . . . . . . . . . . . . . . . . . 445\u003c\/p\u003e \u003cp\u003e            The Windows Registry. . . . . . . . . . . . . . . . . . . . . . . . . 447\u003c\/p\u003e \u003cp\u003e            Mobile Forensics: Cell Phone Concepts.. . . . . . . . . . . . . . . . . . 452\u003c\/p\u003e \u003cp\u003e            The Need for Forensic Certification.. . . . . . . . . . . . . . . . . . . . 457\u003c\/p\u003e \u003cp\u003e            Expert Witnesses.. . . . . . . . . . . . . . . . . . . . . . . . . . . 458\u003c\/p\u003e \u003cp\u003e            Additional Types of Forensics.. . . . . . . . . . . . . . . . . . . . . . 459\u003c\/p\u003e \u003cp\u003e            Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 463\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 15: Cybersecurity Engineering 466\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e            Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 466\u003c\/p\u003e \u003cp\u003e            Defining Cybersecurity Engineering.. . . . . . . . . . . . . . . . . . . . 467\u003c\/p\u003e \u003cp\u003e            Standards.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 475\u003c\/p\u003e \u003cp\u003e            SecML. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 480\u003c\/p\u003e \u003cp\u003e            Modeling. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 489\u003c\/p\u003e \u003cp\u003e            Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 491\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eGlossary 494\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eAppendix A: Resources 500\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eAppendix B: Answers to the Multiple Choice Questions 502\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e \u003c\/p\u003e \u003cp\u003e9780137984787, TOC, 12\/6\/2022\u003c\/p\u003e","brand":"Pearson Education (US)","offers":[{"title":"Default Title","offer_id":48864177389911,"sku":"9780137984787","price":999.99,"currency_code":"GBP","in_stock":false}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9780137984787.jpg?v=1722270753"},{"product_id":"ghostinthewiresmyadventuresastheworldsmostwantedhacker-9780316037723","title":"ghostinthewiresmyadventuresastheworldsmostwantedha","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e","brand":"Little, Brown \u0026 Company","offers":[{"title":"Default Title","offer_id":48864406176087,"sku":"9780316037723","price":16.49,"currency_code":"GBP","in_stock":true}]},{"product_id":"unauthorised-access-9780470747612","title":"Unauthorised Access","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003eA guide to planning and performing a physical penetration test on your computer's security. It guides you through the entire process from gathering intelligence, getting inside, dealing with threats, staying hidden (often in plain sight), and getting access to networks and data.\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e\u003cp\u003ePreface xi\u003c\/p\u003e \u003cp\u003eAcknowledgements xv\u003c\/p\u003e \u003cp\u003eForeword xvii\u003c\/p\u003e \u003cp\u003e\u003cb\u003e1 The Basics of Physical Penetration Testing 1\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eWhat Do Penetration Testers Do? 2\u003c\/p\u003e \u003cp\u003eSecurity Testing in the Real World 2\u003c\/p\u003e \u003cp\u003eLegal and Procedural Issues 4\u003c\/p\u003e \u003cp\u003eKnow the Enemy 8\u003c\/p\u003e \u003cp\u003eEngaging a Penetration Testing Team 9\u003c\/p\u003e \u003cp\u003eSummary 10\u003c\/p\u003e \u003cp\u003e\u003cb\u003e2 Planning Your Physical Penetration Tests 11\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eBuilding the Operating Team 12\u003c\/p\u003e \u003cp\u003eProject Planning and Workflow 15\u003c\/p\u003e \u003cp\u003eCodes, Call Signs and Communication 26\u003c\/p\u003e \u003cp\u003eSummary 28\u003c\/p\u003e \u003cp\u003e\u003cb\u003e3 Executing Tests 29\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eCommon Paradigms for Conducting Tests 30\u003c\/p\u003e \u003cp\u003eConducting Site Exploration 31\u003c\/p\u003e \u003cp\u003eExample Tactical Approaches 34\u003c\/p\u003e \u003cp\u003eMechanisms of Physical Security 36\u003c\/p\u003e \u003cp\u003eSummary 50\u003c\/p\u003e \u003cp\u003e\u003cb\u003e4 An Introduction to Social Engineering Techniques 51\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eIntroduction to Guerilla Psychology 53\u003c\/p\u003e \u003cp\u003eTactical Approaches to Social Engineering 61\u003c\/p\u003e \u003cp\u003eSummary 66\u003c\/p\u003e \u003cp\u003e\u003cb\u003e5 Lock Picking 67\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eLock Picking as a Hobby 68\u003c\/p\u003e \u003cp\u003eIntroduction to Lock Picking 72\u003c\/p\u003e \u003cp\u003eAdvanced Techniques 80\u003c\/p\u003e \u003cp\u003eAttacking Other Mechanisms 82\u003c\/p\u003e \u003cp\u003eSummary 86\u003c\/p\u003e \u003cp\u003e\u003cb\u003e6 Information Gathering 89\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eDumpster Diving 90\u003c\/p\u003e \u003cp\u003eShoulder Surfing 99\u003c\/p\u003e \u003cp\u003eCollecting Photographic Intelligence 102\u003c\/p\u003e \u003cp\u003eFinding Information From Public Sources and the Internet 107\u003c\/p\u003e \u003cp\u003eElectronic Surveillance 115\u003c\/p\u003e \u003cp\u003eCovert Surveillance 117\u003c\/p\u003e \u003cp\u003eSummary 119\u003c\/p\u003e \u003cp\u003e\u003cb\u003e7 Hacking Wireless Equipment 121\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eWireless Networking Concepts 122\u003c\/p\u003e \u003cp\u003eIntroduction to Wireless Cryptography 125\u003c\/p\u003e \u003cp\u003eCracking Encryption 131\u003c\/p\u003e \u003cp\u003eAttacking a Wireless Client 144\u003c\/p\u003e \u003cp\u003eMounting a Bluetooth Attack 150\u003c\/p\u003e \u003cp\u003eSummary 153\u003c\/p\u003e \u003cp\u003e\u003cb\u003e8 Gathering the Right Equipment 155\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eThe ‘‘Get of Jail Free’’ Card 155\u003c\/p\u003e \u003cp\u003ePhotography and Surveillance Equipment 157\u003c\/p\u003e \u003cp\u003eComputer Equipment 159\u003c\/p\u003e \u003cp\u003eWireless Equipment 160\u003c\/p\u003e \u003cp\u003eGlobal Positioning Systems 165\u003c\/p\u003e \u003cp\u003eLock Picking Tools 167\u003c\/p\u003e \u003cp\u003eForensics Equipment 169\u003c\/p\u003e \u003cp\u003eCommunications Equipment 170\u003c\/p\u003e \u003cp\u003eScanners 171\u003c\/p\u003e \u003cp\u003eSummary 175\u003c\/p\u003e \u003cp\u003e\u003cb\u003e9 Tales from the Front Line 177\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eSCADA Raiders 177\u003c\/p\u003e \u003cp\u003eNight Vision 187\u003c\/p\u003e \u003cp\u003eUnauthorized Access 197\u003c\/p\u003e \u003cp\u003eSummary 204\u003c\/p\u003e \u003cp\u003e\u003cb\u003e10 Introducing Security Policy Concepts 207\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003ePhysical Security 208\u003c\/p\u003e \u003cp\u003eProtectively Marked or Classified GDI Material 213\u003c\/p\u003e \u003cp\u003eProtective Markings in the Corporate World 216\u003c\/p\u003e \u003cp\u003eCommunications Security 218\u003c\/p\u003e \u003cp\u003eStaff Background Checks 221\u003c\/p\u003e \u003cp\u003eData Destruction 223\u003c\/p\u003e \u003cp\u003eData Encryption 224\u003c\/p\u003e \u003cp\u003eOutsourcing Risks 225\u003c\/p\u003e \u003cp\u003eIncident Response Policies 226\u003c\/p\u003e \u003cp\u003eSummary 228\u003c\/p\u003e \u003cp\u003e\u003cb\u003e11 Counter Intelligence 229\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eUnderstanding the Sources of Information Exposure 230\u003c\/p\u003e \u003cp\u003eSocial Engineering Attacks 235\u003c\/p\u003e \u003cp\u003eProtecting Against Electronic Monitoring 239\u003c\/p\u003e \u003cp\u003eSecuring Refuse 240\u003c\/p\u003e \u003cp\u003eProtecting Against Tailgating and Shoulder Surfing 241\u003c\/p\u003e \u003cp\u003ePerforming Penetration Testing 242\u003c\/p\u003e \u003cp\u003eBaseline Physical Security 245\u003c\/p\u003e \u003cp\u003eSummary 247\u003c\/p\u003e \u003cp\u003e\u003cb\u003eAppendix A: UK Law 249\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eComputer Misuse Act 249\u003c\/p\u003e \u003cp\u003eHuman Rights Act 251\u003c\/p\u003e \u003cp\u003eRegulation of Investigatory Powers Act 252\u003c\/p\u003e \u003cp\u003eData Protection Act 253\u003c\/p\u003e \u003cp\u003e\u003cb\u003eAppendix B: US Law 255\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eComputer Fraud and Abuse Act 255\u003c\/p\u003e \u003cp\u003eElectronic Communications Privacy Act 256\u003c\/p\u003e \u003cp\u003eSOX and HIPAA 257\u003c\/p\u003e \u003cp\u003e\u003cb\u003eAppendix C: EU Law 261\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eEuropean Network and Information Security Agency 261\u003c\/p\u003e \u003cp\u003eData Protection Directive 263\u003c\/p\u003e \u003cp\u003e\u003cb\u003eAppendix D: Security Clearances 265\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eClearance Procedures in the United Kingdom 266\u003c\/p\u003e \u003cp\u003eLevels of Clearance in the United Kingdom 266\u003c\/p\u003e \u003cp\u003eLevels of Clearance in the United States 268\u003c\/p\u003e \u003cp\u003e\u003cb\u003eAppendix E: Security Accreditations 271\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eCertified Information Systems Security Professional 271\u003c\/p\u003e \u003cp\u003eCommunication–Electronics Security Group CHECK 272\u003c\/p\u003e \u003cp\u003eGlobal Information Assurance Certification 274\u003c\/p\u003e \u003cp\u003eINFOSEC Assessment and Evaluation 275\u003c\/p\u003e \u003cp\u003eIndex 277\u003c\/p\u003e","brand":"John Wiley \u0026 Sons Inc","offers":[{"title":"Default Title","offer_id":48864639025495,"sku":"9780470747612","price":25.5,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9780470747612.jpg?v=1722272845"},{"product_id":"the-art-of-intrusion-9780471782667","title":"The Art of Intrusion","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003eKevin Mitnick, the world's most celebrated hacker, now devotes his life to helping businesses and governments combat data thieves, cybervandals, and other malicious computer intruders. In The Art of Intrusion, Mitnick offers hair-raising stories of real-life computer break-ins, and shows how the victims could have prevented them.\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e\u003cp\u003eChapter 1 Hacking the Casinos for a Million Bucks 1\u003c\/p\u003e \u003cp\u003eChapter 2 When Terrorists Come Calling 23\u003c\/p\u003e \u003cp\u003eChapter 3 The Texas Prison Hack 49\u003c\/p\u003e \u003cp\u003eChapter 4 Cops and Robbers 69\u003c\/p\u003e \u003cp\u003eChapter 5 The Robin Hood Hacker 91\u003c\/p\u003e \u003cp\u003eChapter 6 The Wisdom and Folly of Penetration Testing 115\u003c\/p\u003e \u003cp\u003eChapter 7 Of Course Your Bank Is Secure — Right? 139\u003c\/p\u003e \u003cp\u003eChapter 8 Your Intellectual Property Isn’t Safe 153\u003c\/p\u003e \u003cp\u003eChapter 9 On the Continent 195\u003c\/p\u003e \u003cp\u003eChapter 10 Social Engineers — How They Work and How to Stop Them 221\u003c\/p\u003e \u003cp\u003eChapter 11 Short Takes 247\u003c\/p\u003e \u003cp\u003eIndex 261\u003c\/p\u003e","brand":"John Wiley \u0026 Sons Inc","offers":[{"title":"Default Title","offer_id":48864652558679,"sku":"9780471782667","price":12.6,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9780471782667.jpg?v=1722272908"},{"product_id":"the-art-of-deception-9780764542800","title":"The Art of Deception","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003eFocusing on the human factors involved with information security, this book explains why all the firewalls and encryption protocols in the world will never be enough to stop a savvy grifter intent on rifling a corporate database or an irate employee determined to crash a system.\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTrade Review\u003c\/b\u003e\u003cbr\u003e“…a fascinating read…” (\u003ci\u003eForTean Times\u003c\/i\u003e, June 2004)  \u003cp\u003e\"...a lot of interesting cautionary tales...\" (\u003ci\u003eNew Scientist\u003c\/i\u003e, January 2004)\u003c\/p\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003eForeword.  \u003cp\u003ePreface.\u003c\/p\u003e \u003cp\u003eIntroduction.\u003c\/p\u003e \u003cp\u003ePart 1: Behind the Scenes.\u003c\/p\u003e \u003cp\u003eChapter 1: Security's Weakest Link.\u003c\/p\u003e \u003cp\u003ePart 2: The Art of the Attacker.\u003c\/p\u003e \u003cp\u003eChapter 2: When Innocuous Information Isn't.\u003c\/p\u003e \u003cp\u003eChapter 3: The Direct Attack: Just Asking for It.\u003c\/p\u003e \u003cp\u003eChapter 4: Building Trust.\u003c\/p\u003e \u003cp\u003eChapter 5: \"Let Me Help You\".\u003c\/p\u003e \u003cp\u003eChapter 6: \"Can You Help Me?\".\u003c\/p\u003e \u003cp\u003eChapter 7: Phony Sites and Dangerous Attachments.\u003c\/p\u003e \u003cp\u003eChapter 8: Using Sympathy, Guilt, and Intimidation.\u003c\/p\u003e \u003cp\u003eChapter 9: The Reverse Sting.\u003c\/p\u003e \u003cp\u003ePart 3: Intruder Alert.\u003c\/p\u003e \u003cp\u003eChapter 10: Entering the Premises.\u003c\/p\u003e \u003cp\u003eChapter 11: Combining Technology and Social Engineering.\u003c\/p\u003e \u003cp\u003eChapter 12: Attacks on the Entry-Level Employee.\u003c\/p\u003e \u003cp\u003eChapter 13: Clever Cons.\u003c\/p\u003e \u003cp\u003eChapter 14: Industrial Espionage.\u003c\/p\u003e \u003cp\u003ePart 4: Raising the Bar.\u003c\/p\u003e \u003cp\u003eChapter 15: Information Security Awareness and Training.\u003c\/p\u003e \u003cp\u003eChapter 16: Recommended Corporate Information Security Policies.\u003c\/p\u003e \u003cp\u003eSecurity at a Glance.\u003c\/p\u003e \u003cp\u003eSources.\u003c\/p\u003e \u003cp\u003eAcknowledgments.\u003c\/p\u003e \u003cp\u003eIndex.\u003c\/p\u003e","brand":"John Wiley \u0026 Sons Inc","offers":[{"title":"Default Title","offer_id":48865859076439,"sku":"9780764542800","price":9.5,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9780764542800.jpg?v=1722275918"},{"product_id":"network-programmability-and-automation-9781098110833","title":"Network Programmability and Automation","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003eThe updated second edition of this practical guide shows network engineers how to use a range of technologies and tools, including Linux, Python, APIs, and Git, to automate systems through code. This edition also includes brand new topics such as network development environments, cloud and programming with Go.","brand":"O'Reilly Media","offers":[{"title":"Default Title","offer_id":48866331197783,"sku":"9781098110833","price":35.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9781098110833.jpg?v=1722278166"},{"product_id":"comptia-security-practice-tests-exam-sy0601-9781119735465","title":"CompTIA Security Practice Tests Exam SY0601","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e\u003cp\u003eIntroduction xix\u003c\/p\u003e \u003cp\u003eChapter 1 Threats, Attacks, and Vulnerabilities 1\u003c\/p\u003e \u003cp\u003eChapter 2 Architecture and Design 45\u003c\/p\u003e \u003cp\u003eChapter 3 Implementation 81\u003c\/p\u003e \u003cp\u003eChapter 4 Operations and Incident Response 129\u003c\/p\u003e \u003cp\u003eChapter 5 Governance, Risk, and Compliance 159\u003c\/p\u003e \u003cp\u003eAppendix Answers and Explanations 185\u003c\/p\u003e \u003cp\u003eIndex 299\u003c\/p\u003e","brand":"John Wiley \u0026 Sons Inc","offers":[{"title":"Default Title","offer_id":48866413707607,"sku":"9781119735465","price":28.05,"currency_code":"GBP","in_stock":false}]},{"product_id":"ccsk-certificate-of-cloud-security-knowledge-allinone-exam-guide-9781260460087","title":"CCSK Certificate of Cloud Security Knowledge","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cp\u003e\u003cspan\u003e\u003cstrong\u003ePublisher's Note: Products purchased from Third Party sellers are not guaranteed by the publisher for quality, authenticity, or access to any online entitlements included with the product.\u003c\/strong\u003e\u003c\/span\u003e\u003c\/p\u003e\u003cp\u003e\u003cspan\u003e\u003cbr\u003e\u003c\/span\u003e\u003c\/p\u003e\u003ch4\u003e\u003c\/h4\u003e\u003ch4\u003eThis effective study guide provides 100% coverage of every topic on the challenging CCSK exam from the Cloud Security Alliance\u003c\/h4\u003e\u003cp\u003eThis highly effective self-study guide covers all domains of the challenging Certificate of Cloud Security Knowledge v4 exam. Written by a cloud security trainer and consultant in collaboration with the Cloud Security Alliance, \u003cem\u003eCCSK Certificate of Cloud Security Knowledge All-in-One Exam Guide\u003c\/em\u003e offers clear explanations, real-world examples, and practice questions that match the content and format of those on the actual exam. To aid in retention, each chapter includes exam tips that highlight key information, a review that serves as a quick recap of salient points, and practice questions t\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e\u003cb\u003eChapter 1:\u003c\/b\u003e Cloud Computing Concepts and Architectures\u003cbr\u003e\u003cb\u003eChapter 2:\u003c\/b\u003e Governance and Enterprise Risk Management\u003cbr\u003e\u003cb\u003eChapter 3:\u003c\/b\u003e Legal Issues, Contracts, and Electronic Discovery\u003cbr\u003e\u003cb\u003eChapter 4:\u003c\/b\u003e Compliance and Audit Management\u003cbr\u003e\u003cb\u003eChapter 5:\u003c\/b\u003e Information Governance\u003cbr\u003e\u003cb\u003eChapter 6:\u003c\/b\u003e Management Plan E and Business Continuity\u003cbr\u003e\u003cb\u003eChapter 7:\u003c\/b\u003e Infrastructure Security\u003cbr\u003e\u003cb\u003eChapter 8:\u003c\/b\u003e Virtualization and Containers\u003cbr\u003e\u003cb\u003eChapter 9:\u003c\/b\u003e Incident Response\u003cbr\u003e\u003cb\u003eChapter 10:\u003c\/b\u003e Application Security\u003cbr\u003e\u003cb\u003eChapter 11:\u003c\/b\u003e Data Security and Encryption\u003cbr\u003e\u003cb\u003eChapter 12:\u003c\/b\u003e Identity, Entitlement, and Access Management\u003cbr\u003e\u003cb\u003eChapter 13:\u003c\/b\u003e Security as a Service\u003cbr\u003e\u003cb\u003eChapter 14:\u003c\/b\u003e Related Technologies\u003cbr\u003e\u003cb\u003eChapter 15:\u003c\/b\u003e ENISA Cloud Computing: Benefits, Risks and Recommendations for Information Security\u003cbr\u003e\u003cb\u003eAppendix A:\u003c\/b\u003e Cloud Security Lexicon\u003cbr\u003e\u003cb\u003eAppendix B:\u003c\/b\u003e Cloud Security Standards and Certifications\u003cbr\u003e\u003cb\u003eAppendix C:\u003c\/b\u003e Sample Cloud Policy\u003c\/p\u003e","brand":"McGraw-Hill Education","offers":[{"title":"Default Title","offer_id":48866491924823,"sku":"9781260460087","price":999.99,"currency_code":"GBP","in_stock":false}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9781260460087.jpg?v=1722278912"},{"product_id":"gcih-giac-certified-incident-handler-allinone-exam-guide-9781260461626","title":"GCIH GIAC Certified Incident Handler AllinOne","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cp\u003e\u003cstrong\u003ePublisher's Note: Products purchased from Third Party sellers are not guaranteed by the publisher for quality, authenticity, or access to any online entitlements included with the product.\u003c\/strong\u003e\u003c\/p\u003e\u003cp\u003e\u003cstrong\u003eThis self-study guide delivers complete coverage of every topic on the GIAC Certified Incident Handler exam\u003c\/strong\u003e\u003c\/p\u003e\u003cp\u003ePrepare for the challenging GIAC Certified Incident Handler exam using the detailed information contained in this effective exam preparation guide. Written by a recognized cybersecurity expert and seasoned author, GCIH GIAC Certified Incident Handler All-in-One Exam Guide clearly explains all of the advanced security incident handling skills covered on the test. Detailed examples and chapter summaries throughout demonstrate real-world threats and aid in retention. You will get online access to 300 practice questions that match those on the live test in style, format, and tone. Designed to help you prepare for the exam, this resource also serves a\u003c\/p\u003e","brand":"McGraw-Hill Education","offers":[{"title":"Default Title","offer_id":48866492088663,"sku":"9781260461626","price":37.59,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9781260461626.jpg?v=1722278913"},{"product_id":"rational-cybersecurity-for-business-9781484259511","title":"Rational Cybersecurity for Business","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cp\u003eUse the guidance in this comprehensive field guide to gain the support of your top executives for aligning a rational cybersecurity plan with your business. You will learn how to improve working relationships with stakeholders in complex digital businesses, IT, and development environments. You will know how to prioritize your security program, and motivate and retain your team.\u003cbr\u003e\u003c\/p\u003e\u003cp\u003eMisalignment between security and your business can start at the top at the C-suite or happen at the line of business, IT, development, or user level. It has a corrosive effect on any security project it touches. But it does not have to be like this. \u003c\/p\u003e\u003cp\u003eAuthor Dan Blum presents valuable lessons learned from interviews with over 70 security and business leaders. You will discover how to successfully solve issues related to: risk management, operational security, privacy protection, hybrid cloud management, security culture and user awareness, and communication challenges.\u003cbr\u003e\u003c\/p\u003e\u003cdiv\u003eThis o\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e\u003cp\u003e\u003cb\u003eIntroduction\u003c\/b\u003e \u003c\/p\u003e  \u003cp\u003eExplain the book’s focus, audience, organization, and contents.\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 1: Rationalize Cybersecurity for your Business Landscape\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eDescribes the six cybersecurity priority focus areas.\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 2: Identify and Empower Security-Related Roles\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eExplains how the people in the business each contribute to the secure operation of the business and its digital systems.\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 3: Establish a Control Baseline\u003c\/b\u003e\u003c\/p\u003e  Combs through control frameworks such as ISO 27001 and the NIST Cybersecurity Framework to select controls providing a minimum viable program (MVP) for many businesses. It also details how to align people, process, and technology for these controls; how to scale the implementation for different types of businesses; and how to sure share responsibility for delivering the controls with third parties.\u003cp\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 4: Simplify and Rationalize IT and Security\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eArgues that security leaders have a stake in developing an effective IT strategy, what that strategy might look like, and how security leaders – who don’t own IT - can still engage IT functions to help develop and deliver on the strategy. \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 5: Manage Risk in the Language of Business\u003c\/b\u003e\u003c\/p\u003e  Clarifies why risk management literally must be the brains of the security program. It must analyze, monitor, and communicate what potential losses or circumstances constitute the business’s top risk scenarios. An effective tiered risk analysis process can efficiently address the myriad secondary risk issues that arise through processes and prioritize controls or other risk treatments.\u003cp\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 6: Create a Strong Security Culture\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eBrings the cultural subtext that can make or break a cybersecurity environment into the foreground. It analyzes the components of security culture and provides guidance on how to devise a security culture improvement process and measure its effectiveness. User awareness, training, and appropriate day to day engagement with the business can all play a part in forging a constructive security culture. \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 7: Put the Right Governance Model in Place\u003c\/b\u003e\u003c\/p\u003e  Contrasts basic security governance structures that businesses can use, and provides guidance on how to select one and make it work. It describes core elements of the security program such as steering committees and security policy life cycle management. It also offers guidance on where the CISO should report in an organization. \u003cp\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 8: Control Access with Minimal Drag on the Business\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eExplains why access is the critical balance beam for the business, compliance mandates, and the security program. It addresses the need for information classification, data protection, and identity and access management (IAM) controls to implement access restrictions as required to reduce risk or attain regulatory compliance but do so in a way that enables appropriate digital relationships and data sharing with internal and external users.\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 9: Institute Resilience, Detection, and Response\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eGuides readers on how to formulate contingency plans and strategies for detection, response, and recovery which together comprise cyber-resilience. \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 10: Putting the Pieces Together\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eSummarizes guidance given throughout the book in the “keys” for aligning with the business. It reiterates guidance on how to scale security programs and the way they align to the business based on business size, complexity, and other factors.\u003c\/p\u003e\n\u003c\/div\u003e","brand":"APress","offers":[{"title":"Default Title","offer_id":48867298083159,"sku":"9781484259511","price":999.99,"currency_code":"GBP","in_stock":false}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9781484259511.jpg?v=1722282663"},{"product_id":"cyber-threats-and-nuclear-weapons-9781503630390","title":"Cyber Threats and Nuclear Weapons","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cp\u003eThe technology controlling United States nuclear weapons predates the Internet. Updating the technology for the digital era is necessary, but it comes with the risk that anything digital can be hacked. Moreover, using new systems for both nuclear and non-nuclear operations will lead to levels of nuclear risk hardly imagined before. This book is the first to confront these risks comprehensively. \u003c\/p\u003e \u003cp\u003eWith \u003ci\u003eCyber Threats and Nuclear Weapons\u003c\/i\u003e, Herbert Lin provides a clear-eyed breakdown of the cyber risks to the U.S. nuclear enterprise. Featuring a series of scenarios that clarify the intersection of cyber and nuclear risk, this book guides readers through a little-understood element of the risk profile that government decision-makers should be anticipating. What might have happened if the Cuban Missile Crisis took place in the age of Twitter, with unvetted information swirling around? What if an adversary announced that malware had compromised nuclear systems, clouding the confidence of nuclear decision-makers? \u003c\/p\u003e \u003cp\u003e\u003ci\u003eCyber Threats and Nuclear Weapons\u003c\/i\u003e, the first book to consider cyber risks across the entire nuclear enterprise, concludes with crucial advice on how government can manage the tensions between new nuclear capabilities and increasing cyber risk. This is an invaluable handbook for those ready to confront the unique challenges of cyber nuclear risk.\u003c\/p\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTrade Review\u003c\/b\u003e\u003cbr\u003e\"Perhaps the only thing more frightening than nuclear weapons is the thought of those weapons being connected to modern software systems. Herbert Lin, an expert in both realms, has written a sobering, enlightening book that should be required reading for all those thinking about the security of these weapons in the internet age.\"—Jim Waldo, Former Distinguished Engineer, Sun Labs\u003cbr\u003e\"Herbert Lin is one of this country's leading experts on nuclear and cyber issues. In this important book, he provides a careful but chilling analysis of the risks we face in efforts to modernize the nuclear enterprise. \u003ci\u003eCyber Threats and Nuclear Weapons\u003c\/i\u003e should be read carefully in Washington.\" —Joseph S. Nye, Jr, Harvard University\u003cbr\u003e\"In this wide-ranging and well-crafted book, Herbert Lin wisely encapsulates his careful analysis in a series of easy-to-digest observations, with the policy imperatives that flow from them. The result is a guide for policy makers as they cope with the hair-raising prospect of nuclear modernization amidst increasing cyber risk.\"—Rose Gottemoeller, Former Deputy Secretary General of NATO\u003cbr\u003e\"Lin's purpose in writing this excellent book is to acknowledge the new and sobering reality that computerization makes nuclear weapons much less secure than readers might assume. Highly recommended.\"—J. A. Stever, \u003ci\u003eCHOICE\u003c\/i\u003e June 2022\u003cbr\u003e\"an informative read for novices and experts alike.\"—Melissa K. Griffith, \u003ci\u003eSurvival: Global Politics and Strategy\u003c\/i\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e1. Introduction and Background\u003cbr\u003e  2. The Cyber-Nuclear Connection\u003cbr\u003e  3. The U.S. Nuclear Enterprise\u003cbr\u003e  4. Cybersecurity Lessons for Nuclear Modernization\u003cbr\u003e  5. Cyber Risks in Selected Nuclear Scenarios\u003cbr\u003e  6. Designing the Cyber-Nuclear Future: Observations and Imperatives\u003cbr\u003e  7. Moving Forward\u003cbr\u003e","brand":"Stanford University Press","offers":[{"title":"Default Title","offer_id":48867351036247,"sku":"9781503630390","price":19.79,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9781503630390.jpg?v=1722282922"},{"product_id":"foundations-of-information-security-a-straightforward-introduction-9781718500044","title":"Foundations Of Information Security: A","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003eFoundations of Information Security provides readers with fundamental knowledge of information security in both theoretical and practical aspects. Each chapter explores one main security concept, lists scenarios in which the concept is applicable, and discusses the implementation of that concept in detail, often by going over rival models or strategies. Readers will come away with a sense of what types of assets need protecting, what kinds of risks exist, and what kinds of defensive measures can be taken.\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTrade Review\u003c\/b\u003e\u003cbr\u003e“This book is an excellent starting point for future security professionals but also network and system administrators.”\u003cbr\u003e\u003cb\u003e—Help Net Security\u003cbr\u003e\u003c\/b\u003e\u003cbr\u003e\"A thorough overview for many different areas within security. The author explains what and more importantly why, then illustrates each concept with concrete, realistic examples. Definitely a great addition to any security engineer's library, but also less technical people who want to learn more about common topics like defense in depth.\"\u003cbr\u003e\u003cb\u003e—Seth Foley\u003cbr\u003e\u003c\/b\u003e\u003cbr\u003e\"If you’re new to info security or are looking to refresh your knowledge, then this is an ideal book. It’s easy to read and makes the information fun to consume.\"\u003cbr\u003e\u003cb\u003e—HaXez, Blogger and YouTuber\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003eIntroduction\u003cbr\u003e\u003cbr\u003eChapter 1: What is Information Security?\u003cbr\u003eChapter 2: Indentification and Authentication\u003cbr\u003eChapter 3: Authorization and Access Control\u003cbr\u003eChapter 4: Auditing and Accountability\u003cbr\u003eChapter 5: Cryptography\u003cbr\u003eChapter 6: Compliance, Laws, and Regulations\u003cbr\u003eChapter 7: Operations Security\u003cbr\u003eChapter 8: Human Element Security\u003cbr\u003eChapter 9: Physical Security\u003cbr\u003eChapter 10: Network Security\u003cbr\u003eChapter 11: Operating System Security\u003cbr\u003eChapter 12: Mobile, Embedded, and Internet of Things Security\u003cbr\u003eChapter 13: Application Security\u003cbr\u003eChapter 14: Assessing Security\u003cbr\u003e\u003cbr\u003eNotes","brand":"No Starch Press,US","offers":[{"title":"Default Title","offer_id":48868101783895,"sku":"9781718500044","price":34.19,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9781718500044.jpg?v=1722286396"},{"product_id":"the-art-of-cyberwarfare-an-investigators-guide-to-espionage-ransomware-and-organized-cybercrime-9781718502147","title":"The Art Of Cyberwarfare: An Investigator's Guide","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003eToday, companies find themselves targeted by sophisticated nation state cyber attackers armed with the resources to craft scarily effective campaigns. This book is a detailed guide to understanding the major players, the techniques they use, and the process of analysing their advanced attacks. Whether you're an individual researcher or part of a team within a Security Operations Center (SoC), you'll learn to approach, track, and attribute attacks to these advanced actors. Jon DiMaggio demonstrates some of the techniques he has employed to uncover crucial information about the 2021 Colonial Pipeline attacks, among others.\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTrade Review\u003c\/b\u003e\u003cbr\u003e\"Encompasses useful knowledge from the past and modern advanced threats seen today. Regardless of your expertise level, this book is an insightful read . . .”\u003cbr\u003e\u003cb\u003e—Brittany Day, Director of Communications, Guardian Digital\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003e“For those looking for a guide to help them understand the new world of cyberwar, \u003ci\u003eThe Art of Cyberwarfare\u003c\/i\u003e provides readers with a good overview of this expanding threat and what they can do to avoid being victims.”\u003cbr\u003e\u003cb\u003e—Ben Rothke, Senior Information Security Manager, Tapad\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003e\"An informative and explanatory guide for cybersecurity experts and an enlightening read for novices. DiMaggio effectively details both the history of cybercrime and how it is seen today.\"\u003cbr\u003e\u003cb\u003e—Justice Levine, Communications Manager and Cloud Email Security Expert, Guardian Digital\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003e\"This book deserves to find a place on the shelf of everyone whose role involves protecting networks.\"\u003cbr\u003e\u003cb\u003e—Ian Barker, BetaNews\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003e\"A cross between an IBM presentation . . . and a Tom Clancy novel!\"\u003cbr\u003e\u003cb\u003e—The Shepherdess, Amazon Reviewer\u003c\/b\u003e","brand":"No Starch Press,US","offers":[{"title":"Default Title","offer_id":48868102701399,"sku":"9781718502147","price":28.49,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9781718502147.jpg?v=1722286399"},{"product_id":"blown-to-bits-9780134850016","title":"Blown to Bits","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cb\u003eHal Abelson\u003c\/b\u003e is Class of 1922 Professor of Computer Science and Engineering at MIT, and an IEEE Fellow. He has helped drive innovative educational technology initiatives such MIT OpenCourseWare, co-founded Creative Commons and Public Knowledge, and was founding director of the Free Software Foundation. \u003cbr\u003e \u003cbr\u003e \u003cbr\u003e \u003cb\u003eKen Ledeen\u003c\/b\u003e, Chairman\/CEO of Nevo Technologies, is a serial entrepreneur who has served on the boards of numerous technology companies. \u003cbr\u003e \u003cbr\u003e \u003cbr\u003e \u003cb\u003eHarry Lewis\u003c\/b\u003e, former Dean of Harvard College and of Harvard's School of Engineering and Applied Sciences, is Gordon McKay Research Professor of Computer Science at Harvard and Faculty Associate of the Berkman Klein Center for Internet and Society. He is author of \u003ci\u003eExcellence Without a Soul: Does Liberal Education Have a Future\u003c\/i\u003e? and editor of \u003ci\u003eIdeas that Created the Future: Classic Papers of Computer Science\u003c\/i\u003e. \u003cbr\u003e \u003cbr\u003e \u003cbr\u003e \u003cb\u003eWendy Seltzer\u003c\/b\u003e is Counsel and Strategy Lead at the World Wide Web C\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003ePreface     xvii    \u003cbr\u003e    \u003cb\u003eChapter 1  Digital Explosion\u003c\/b\u003e    \u003cbr\u003e    Why Is It Happening, and What Is at Stake?     1    \u003cbr\u003e    The Explosion of Bits, and Everything Else     4    \u003cbr\u003e    The Koans of Bits     7    \u003cbr\u003e    Good and Ill, Promise and Peril     17    \u003cbr\u003e    Endnotes     19    \u003cbr\u003e    \u003cb\u003eChapter 2  Naked in the Sunlight\u003c\/b\u003e    \u003cbr\u003e    Privacy Lost, Privacy Abandoned     21    \u003cbr\u003e    1984 Is Here, and We Like It     21    \u003cbr\u003e    Location, Location, Location     27    \u003cbr\u003e    Big Brother, Abroad and in the United States     32    \u003cbr\u003e    The Internet of Things     42    \u003cbr\u003e    Endnotes     48    \u003cbr\u003e    \u003cb\u003eChapter 3  Who Owns Your Privacy?\u003c\/b\u003e    \u003cbr\u003e    The Commercialization of Personal Data     51    \u003cbr\u003e    What Kind of Vegetable Are You?     51    \u003cbr\u003e    Footprints and Fingerprints     57    \u003cbr\u003e    Fair Information Practice Principles     64    \u003cbr\u003e    Always On     70    \u003cbr\u003e    Endnotes     71    \u003cbr\u003e    \u003cb\u003eChapter 4  Gatekeepers\u003c\/b\u003e    \u003cbr\u003e    Who's in Charge Here?     75    \u003cbr\u003e    Who Controls the Flow of Bits?     75    \u003cbr\u003e    The Open Internet?     76    \u003cbr\u003e    Connecting the Dots: Designed for Sharing and Survival     79    \u003cbr\u003e    The Internet Has No Gatekeepers?     85    \u003cbr\u003e    Links Gatekeepers: Getting Connected     86    \u003cbr\u003e    Search Gatekeepers: If You Can't Find It, Does It Exist?     94    \u003cbr\u003e    Social Gatekeepers: Known by the Company You Keep     104    \u003cbr\u003e    Endnotes     112    \u003cbr\u003e    \u003cb\u003eChapter 5  Secret Bits\u003c\/b\u003e    \u003cbr\u003e    How Codes Became Unbreakable     117    \u003cbr\u003e    Going Dark     117    \u003cbr\u003e    Historical Cryptography     122    \u003cbr\u003e    Lessons for the Internet Age     131    \u003cbr\u003e    Secrecy Changes Forever     135    \u003cbr\u003e    Cryptography Unsettled     147    \u003cbr\u003e    Endnotes     148    \u003cbr\u003e    \u003cb\u003eChapter 6  Balance Toppled\u003c\/b\u003e    \u003cbr\u003e    Who Owns the Bits?     153    \u003cbr\u003e    Stealing Music     153    \u003cbr\u003e    Automated Crimes, Automated Justice     155    \u003cbr\u003e    The Peer-to-Peer Upheaval     160    \u003cbr\u003e    No Commercial Skipping     167    \u003cbr\u003e    Authorized Use Only     168    \u003cbr\u003e    Forbidden Technology     172    \u003cbr\u003e    Copyright Koyaanisqatsi: Life Out of Balance     177    \u003cbr\u003e    The Limits of Property     183    \u003cbr\u003e    Endnotes     187    \u003cbr\u003e    \u003cb\u003eChapter 7  You Can't Say That on the Internet\u003c\/b\u003e    \u003cbr\u003e    Guarding the Frontiers of Digital Expression     193    \u003cbr\u003e    Child Sex Trafficking Goes Digital     193    \u003cbr\u003e    Publisher or Distributor?     198    \u003cbr\u003e    Protecting Good Samaritans—and a Few Bad Ones     205    \u003cbr\u003e    Digital Protection, Digital Censorship, and Self-Censorship     215    \u003cbr\u003e    What About Social Media?     219    \u003cbr\u003e    Takedowns     221    \u003cbr\u003e    Endnotes     222    \u003cbr\u003e    \u003cb\u003eChapter 8  Bits in the Air\u003c\/b\u003e    \u003cbr\u003e    Old Metaphors, New Technologies, and Free Speech     227    \u003cbr\u003e    Censoring the Candidate     227    \u003cbr\u003e    How Broadcasting Became Regulated     228    \u003cbr\u003e    The Path to Spectrum Deregulation     241    \u003cbr\u003e    The Most Beautiful Inventor in the World     245    \u003cbr\u003e    What Does the Future Hold for Radio?     255    \u003cbr\u003e    Endnotes     261    \u003cbr\u003e    \u003cb\u003eChapter 9  The Next Frontier\u003c\/b\u003e    \u003cbr\u003e    AI and the Bits World of the Future     265    \u003cbr\u003e    Thrown Under a Jaywalking Bus     266    \u003cbr\u003e    What's Intelligent About Artificial Intelligence?     267    \u003cbr\u003e    Machine Learning: I'll Figure It Out     268    \u003cbr\u003e    Algorithmic Decisions: I Thought Only People Could Do That     273    \u003cbr\u003e    What's Next     277    \u003cbr\u003e    Bits Lighting Up the World     282    \u003cbr\u003e    A Few Bits in Conclusion     287    \u003cbr\u003e    \u003cb\u003eEndnotes     288\u003c\/b\u003e    \u003cbr\u003e    \u003cb\u003eIndex     293\u003c\/b\u003e    \u003cbr\u003e    \u003cbr\u003e    \u003cbr\u003e    \u003cbr\u003e","brand":"Pearson Education (US)","offers":[{"title":"Default Title","offer_id":48883796574551,"sku":"9780134850016","price":20.69,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9780134850016.jpg?v=1722529083"},{"product_id":"ceh-certified-ethical-hacker-cert-guide-9780137489985","title":"CEH Certified Ethical Hacker Cert Guide","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cp\u003e\u003cstrong\u003eMichael Gregg\u003c\/strong\u003e (CISSP, SSCP, CISA, MCSE, MCT, CTT+, A+, N+, Security+, CCNA, CASP, CISA, CISM, CEH, CHFI, and GSEC) directs the cybersecurity operations for a multinational organization that operates facilities worldwide. As the CISO, Michael is responsible for securing the organization's assets on a global scale. Michael is responsible for developing cost-effective and innovative technology solutions for security issues and for evaluating emerging technologies.\u003c\/p\u003e \u003cp\u003eHe has more than 20 years of experience in the IT field and holds two associate's degrees, a bachelor's degree, and a master's degree. In addition to coauthoring the first, second, and third editions of \u003cem\u003eSecurity Administrator Street Smarts\u003c\/em\u003e, Michael has written or coauthored more than 20 other books.\u003c\/p\u003e \u003cp\u003eMichael has testified before a U.S. congressional committee, has been quoted in newspapers such as the \u003cem\u003eNew York Times\u003c\/em\u003e, and was featured on various television and radio shows, includ\u003c\/p\u003e","brand":"Pearson Education (US)","offers":[{"title":"Default Title","offer_id":48883799851351,"sku":"9780137489985","price":999.99,"currency_code":"GBP","in_stock":false}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9780137489985.jpg?v=1722529099"},{"product_id":"in-zero-trust-we-trust-9780138237400","title":"In Zero Trust We Trust","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cp\u003e\u003cstrong\u003eAvinash Naduvath \u003c\/strong\u003eis a renowned security architect in the Customer Experience (CX) Security Services division at Cisco Systems. As part of CX-Security, he has delivered multiple solutions to help secure customer networks. The range of services included incepting secure architectures, designs, technology advisories, best practice recommendations, and security assessments.\u003c\/p\u003e \u003cp\u003e \u003c\/p\u003e \u003cp\u003ePrior to his current role in Cisco, Avinash was part of the technical services for security in Cisco-Bangalore and has helped troubleshoot and secure networks for multiple customers. He is a subject matter expert in next-generation firepower technology. Previous to this, Avinash was part of the professional services team in Cisco-Bangalore as a network consulting engineer.\u003c\/p\u003e \u003cp\u003e \u003c\/p\u003e \u003cp\u003eAvinash has over 10 years of experience in the information security domain, having worked on multiple aspects of security such as secure engineering and secure architecture. He has a passio\u003c\/p\u003e","brand":"Pearson Education","offers":[{"title":"Default Title","offer_id":48883801751895,"sku":"9780138237400","price":32.39,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9780138237400.jpg?v=1722529106"},{"product_id":"protective-security-9781484269077","title":"Protective Security","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e\u003cp\u003e\u003cb\u003eChapter 1:  What is Protective Security (PS)?\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eAn introduction to the term ‘Protective Security’ and a description of why this differs to other industry terms (e.g.  Cyber Security, Information Security, IT Security, Network Security, etc.)?\u003c\/p\u003e  \u003cp\u003eWhy PS should be an integral for your business operations?\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 2:  Protective Security (PS) in terms of the Legal \u0026amp; Regulatory Perspective.\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eA deep dive into the Legal and Regulatory perspectives and how an effective PS strategy can help fulfil these ever-changing requirements?\u003c\/p\u003e  \u003cp\u003ePS and the European Union General Data Protection Act (EU-GDPR).\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 3:  The integration of Compliance with Protective Security (PS).\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eA description of where compliance fits into a company-wide PS strategy.\u003c\/p\u003e  \u003cp\u003ePS and the Payment Card Industry Data Security Standard (PCI DSS).\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 4:  The Development of an Effective Protective Security (PS) Strategy.\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eA comprehensive guide to the development of an effective strategy, aligning business assets to their importance for the business objectives and goals, to incorporate the threats, risks, and core components of any strategy.\u003c\/p\u003e  \u003cp\u003eStrategic alignment with the business context.\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 5:  Cyber Security.\u003c\/b\u003e\u003c\/p\u003e  A deep dive into the concept of Cyber Security, with a focus on Point of Origins (PoO) that occur in the ‘Badlands’ (e.g.  outside the corporate network) to compromise internet-facing technologies (e.g.  Ecommerce, Digital, Mobile, etc.)\u003cp\u003e\u003c\/p\u003e  \u003cp\u003eSecuring your Digital Footprint.\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 6:  Network\/IT Security.\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eThe importance of secure by design\/default networks to help safeguard your most important business IT assets from compromise.\u003c\/p\u003e  \u003cp\u003eLateral Movement Attacks.\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 7:  Information Systems Security.\u003c\/b\u003e\u003c\/p\u003e  Providing a guide to the securing of these systems, as a separate asset type, based upon the value of the data assets to the business and to aid the application of the 5 Ds of Security (Defend, Detect, Delay, Disrupt \u0026amp; Deter).\u003cp\u003e\u003c\/p\u003e  \u003cp\u003eBuilding Effective 5 Ds Network Architectures.\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 8:  Physical Security.\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eA comprehensive guide to the development of appropriate physical security measures and its importance within the Protective Security strategy.\u003c\/p\u003e  \u003cp\u003eFortifying Your Business Operations.\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 9:  Industrial Systems Security\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eIncreasingly, Manufacturing systems are vulnerable to cyber-attacks.  Gain an insight how securing these environments can be balanced with a minimal impact on productivity.\u003c\/p\u003e  \u003cp\u003eManufacturing Secure Operations.\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 10:  Securing Your Supply Chain\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eGain an appreciation for securing your Supply Chains and the measures needed to ensure that the Supply Chain risks are minimized.\u003c\/p\u003e  \u003cp\u003eThe Weakest Link?\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 11:  Developing Your Internal Firewall.\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eA focus on the development of a robust Security Culture, through the proactive engagement with a business’ personnel assets.\u003c\/p\u003e  \u003cp\u003eSecurity Is Not A Dirty Word.\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 12:  Strict Access Restrictions\u003c\/b\u003e\u003c\/p\u003e  The ‘Need To Know’\/’Need To Access’ are the fundamental principles for any effective Protective Security strategy.  Gain an insight into why this is the case and how to ensure that this is the case within your organization.\u003cp\u003e\u003c\/p\u003e  \u003cp\u003eThe Keys To Your Empire.\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 13:  Building Resilient Systems\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eGain an appreciation for the business value of building resilient systems and an understanding on what is required to develop resilience into your PS strategy.\u003c\/p\u003e  \u003cp\u003eThe Ability To ‘Bounce Back’.\u003c\/p\u003e  \u003cp\u003e\u003cb\u003e \u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 14:  Demonstrating the Protective Security (PS) Return on Investments (RoI)\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eThe value of an effective PS strategy is often underappreciated by business leaders.  Gain an understanding on how to demonstrate to that their investments continue to deliver a robust security posture and continues to ensure that they remain a less viable target. \u003c\/p\u003e  The Value of PS.\u003cp\u003e\u003c\/p\u003e","brand":"APress","offers":[{"title":"Default Title","offer_id":48885826093399,"sku":"9781484269077","price":37.49,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9781484269077.jpg?v=1722537834"},{"product_id":"cloud-defense-strategies-with-azure-sentinel-9781484271315","title":"Cloud Defense Strategies with Azure Sentinel","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003eUse various defense strategies with Azure Sentinel to enhance your cloud security. This book will help you get hands-on experience, including threat hunting inside Azure cloud logs and metrics from services such as Azure Platform, Azure Active Directory, Azure Monitor, Azure Security Center, and others such as Azure Defender''s many security layers.\u003cdiv\u003e\u003cbr\u003e\u003c\/div\u003eThis book is divided into three parts. Part I helps you gain a clear understanding of Azure Sentinel and its features along with Azure Security Services, including Azure Monitor, Azure Security Center, and Azure Defender. Part II covers integration with third-party security appliances and you learn configuration support, including AWS. You will go through multi-Azure Tenant deployment best practices and its challenges. In Part III you learn how to improve cyber security threat hunting skills while increasing your ability to defend against attacks, stop data loss, prevent business disruption, and expose hidden ma\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e\u003cb\u003ePart I (page count 100) \u003c\/b\u003e\u003cp\u003e\u003cb\u003eGoals\u003c\/b\u003e: Introduction to Azure Sentinel es with technical featurthat benefit the business.  Initial configuration using Azure subscription data connectors, discuss 3rd party integration and alignment with other Azure Security Services. XDR introduction, why it is an industry standard and how to use it in Sentinel.\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eSub-Topics\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e1.      Overview of Technical Features\u003c\/p\u003e  \u003cp\u003e2.      Benefit and cost support for the business, initial configuration \u003c\/p\u003e  \u003cp\u003e3.      Azure Defender support into Azure Sentinel\u003c\/p\u003e  \u003cp\u003e4.      Azure Security Center support into Azure Sentinel \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 1 Azure Sentinel Overview\u003c\/b\u003e\u003c\/p\u003e\u003cp\u003ePlatform benefits, SOC security reference, alignment to Cyber framework, Log Analytics planning, cost structure \u003c\/p\u003e\u003cb\u003e Chapter 2 Other Azure Security Services \u003c\/b\u003e\u003cp\u003eAzure Monitor, Azure Security Center, Azure Defender, working together to support Azure Sentinel\u003c\/p\u003e\u003cb\u003e Chapter 3   Azure Sentinel XDR Capabilities \u003c\/b\u003e\u003cp\u003eIntegration with Azure Security standards, protection for additional Azure workloads, guidance for XDR and how it should be used to modernize security operations. \u003c\/p\u003e\u003cb\u003e Part II (page count 100) \u003c\/b\u003e\u003cp\u003e\u003cb\u003eGoals: \u003c\/b\u003eDeployment best practices, platform integration and support for AWS\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e  \u003cb\u003eSub - Topics\u003c\/b\u003e   \u003cp\u003e\u003c\/p\u003e  \u003cp\u003e1.       Enable integration with 3\u003csup\u003erd\u003c\/sup\u003e party security appliances\u003c\/p\u003e  2.      Configure support for AWS\u003cp\u003e\u003c\/p\u003e  \u003cp\u003e3.      Multi-Azure Tenant deployment best practices\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 4 Data Connection\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eSingle Tenant: Data connectors native, Log Analytics storage options, 3\u003csup\u003erd\u003c\/sup\u003e party data, KQL validation processes, AWS connection, Service NOW integration\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 5 Threat Intelligence (TI)\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eTI connectors and feeds, Sentinel Workbooks introduction, Sentinel Notebook usage, Python integration\u003c\/p\u003e  \u003cb\u003eChapter 6 Multi-Tenant Architecture\u003c\/b\u003e\u003cp\u003e\u003c\/p\u003e  \u003cp\u003eChallenges and cost of Azure log analytics workspace, KQL modification requirements, SOC alignment needed\u003c\/p\u003e\u003cb\u003e Part III (page count 100) \u003c\/b\u003e\u003cp\u003e\u003cb\u003eGoals: \u003c\/b\u003eImprove Cyber Security Threat Hunting Techniques\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e  \u003cb\u003eSub - Topics:\u003c\/b\u003e   \u003cp\u003e\u003c\/p\u003e  \u003cp\u003e1.      Threat Hunting with KQL Language deep dive with examples\u003c\/p\u003e  \u003cp\u003e2.      Integration with MITRE attack Matrix and support for TAXII\u003c\/p\u003e  \u003cp\u003e3.      Data flow examples: User logon, track and validate. Stop network connection to China, etc.\u003c\/p\u003e  \u003cp\u003e4.      Configuration changes needed for multiple Sentinel deployments\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 7 Threat Hunting with Azure Sentinel\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eKQL Hunting introduction, custom queries, Sentinel bookmarks, Sentinel notebooks\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 8 Introduction to MITRE Matrix\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eMITRE Attack Matrix overview and usage, STIX defined, TAXII defined, free TI -vs- service SLA\u003c\/p\u003e  \u003cp\u003e \u003c\/p\u003e  \u003cp\u003e\u003cb\u003eChapter 9 Azure Sentinel Operations\u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003eDaily, Weekly, Monthly tasks, SOC engineer alignment, Continued SOC operations support from official Microsoft supported forum\u003c\/p\u003e\u003cb\u003e Chapter Appendix:  \u003c\/b\u003e\u003cp\u003e\u003cb\u003eChapter Goal: Where to gain additional knowledge for Azure Sentinel \u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eNo of pages\u003c\/b\u003e: 20\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eSub - Topics: \u003c\/b\u003e\u003c\/p\u003e  \u003cp\u003e1.      Guidance to continue Azure Sentinel skill improvement\u003c\/p\u003e  \u003cp\u003e2.      Relating information to Cyber Security standards\u003c\/p\u003e","brand":"APress","offers":[{"title":"Default Title","offer_id":48885826715991,"sku":"9781484271315","price":41.24,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9781484271315.jpg?v=1722537835"},{"product_id":"azure-security-handbook-9781484272916","title":"Azure Security Handbook","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003eChapter 1. Introduction to Cloud Security Architecture.- Chapter 2. Identity and Access Management .- Chapter 3. Logging and Monitoring .- Chapter 4. Network Security.- Chapter 5. Workload Protection- Data.- Chapter 6. Workload Protection- Platform-as-a-Service.- Chapter 7. Workload Protection- Containers.- Chapter 8. Workload Protection- IaaS.\u003cdiv\u003e\u003cbr\u003e\u003c\/div\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e\u003cp\u003e1. Introduction to Cloud Security Architecture\u003c\/p\u003e  \u003cp\u003e 2.  Identity and Access Management \u003c\/p\u003e  \u003cp\u003e 3.  Logging and Monitoring \u003c\/p\u003e\u003cp\u003e 4.  Network Security\u003c\/p\u003e \u003cp\u003e5.  Workload Protection- Data\u003c\/p\u003e  \u003cp\u003e6. Workload Protection- Platform-as-a-Service\u003c\/p\u003e  \u003cp\u003e7. Workload Protection- Containers\u003c\/p\u003e8  Workload Protection- IaaS ","brand":"APress","offers":[{"title":"Default Title","offer_id":48885827174743,"sku":"9781484272916","price":41.24,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9781484272916.jpg?v=1722537838"},{"product_id":"phishing-and-communication-channels-9781484277430","title":"Phishing and Communication Channels","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003eMitigate the dangers posed by phishing activities, a common cybercrime carried out through email attacks. This book details tools and techniques to protect against phishing in various communication channels.   The aim of phishing is to fraudulently obtain sensitive credentials such as passwords, usernames, or social security numbers by impersonating a trustworthy entity in a digital communication. Phishing attacks have increased exponentially in recent years, and target all categories of web users, leading to huge financial losses to consumers and businesses. According to Verizon's 2020 Data Breach Investigations Report (DBIR), 22% of all breaches in 2019 involved phishing. And 65% of organizations in the USA experience a successful phishing attack.   This book discusses the various forms of phishing attacks, the communications most often used to carry out attacks, the devices used in the attacks, and the methods used to protect individuals and organizations fromphishing attacks.   Wha\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTrade Review\u003c\/b\u003e\u003cbr\u003e“It covers a wide range of topics. … Each chapter tackles a very different angle on phishing, which means the topics are covered in a succinct, telegraphic way: many concepts are presented as one or two paragraphs, very often fitting several of them on the same page. … The intended audience is intermediate; experts in different areas of computing will benefit from reading about their respective interests, but the book assumes an introductory to intermediate level throughout.” (Gunnar Wolf, Computing Reviews, January 12, 2023)\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e1: Introduction to Phishing.- 2: Types of Phishing.- 3: Communication Channels.- 4: What Does a Phishing URL Look Like?.- 5: Characteristics of a Phishing Website.- 6: Phishing Kits.- 7: Training Methods for Phishing Detection.- 8: Legal Solution: Phishing is Prohibited Under a Number of Laws.- 9: Phishing Detection Based on Technology.","brand":"APress","offers":[{"title":"Default Title","offer_id":48885827207511,"sku":"9781484277430","price":31.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9781484277430.jpg?v=1722537838"},{"product_id":"crypto-basics-9781484283202","title":"Crypto Basics","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003eUse this practical, step-by-step guide for developers and entrepreneurs to create and run your own cryptocurrency. Author Slava Gomzin has created two cryptocurrencies and describes in this book the technology and economics of cryptocurrencies as preparation for crypto trading, investing, and other business activities. A detailed overview of special topics includes security, privacy, and usability of crypto as a mainstream payment system.\u003cp\u003e\u003c\/p\u003e\u003cp\u003ePart I, Understanding Crypto, explains the technology and economic, security, and usability aspects of crypto. This is an introduction to the world of cryptography, blockchain tech, and other elements of crypto such as security, privacy, and a detailed review of payment processing.\u003c\/p\u003e\u003cp\u003ePart II, Using Crypto, provides the practical knowledge you need to dive into the crypto business such as investment, trading, and even creating your own crypto project.\u003c\/p\u003e\u003cp\u003ePart III, Creating Your Own Crypto, teaches you how to launch your own crypto proje\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003eForeword\u003cbr\u003ePrefaceIntroduction\u003cb\u003ePart 1\u003c\/b\u003e\u003cbr\u003eChapter 1: How Cryptography WorksChapter 2: How Bitcoin WorksChapter 3: How Other Crypto WorksChapter 4: Cryptosecurity Chapter 5: Crypto PrivacyChapter 6: How Monero WorksChapter 7: Crypto Payments\u003cb\u003ePart 2\u003c\/b\u003eChapter 8: How to Choose the WalletChapter 9: Getting Crypto for FreeChapter 10: How Crypto Exchanges WorkChapter 11: Crypto Investment and Trading\u003cb\u003ePart 3\u003c\/b\u003eChapter 12: Creating a TokenChapter 13: How to Start the Crypto ProjectChapter 14: Running A Crypto ProjectConclusion\u003c\/p\u003e","brand":"APress","offers":[{"title":"Default Title","offer_id":48885827895639,"sku":"9781484283202","price":999.99,"currency_code":"GBP","in_stock":false}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9781484283202.jpg?v=1722537841"},{"product_id":"connecting-the-internet-of-things-9781484288962","title":"Connecting the Internet of Things","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003eNavigating the fragmented IoT connectivity ecosystem of standards, protocols, and architectures can be a challenge. Not to mention scaling a solution to a viable product. This book guides you through this fractured landscape with real world examples and projects that can be leverage for an IoT product.Backed by an overview of IoT use cases and key connectivity elements of IoT solutions, you'll gain an understanding of the breadth of the IoT landscape and the fragmentation of connectivity standards and solutions and the challenge in navigating the many standards and technologies. You'll also be able to understand the essentials of connectivity including, hardware, software, and business models.?IoT is essential for increasing productivity of many industries and quality of life (making the world smart and autonomous). Both wired and wireless connectivity technologies are essential ingredients in an IoT product. Writtenby Intel engineers and architects, Connecting the Internet of Thingsun\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003eChapter 1: Introduction to IoT ConnectivityChapter Goal: This chapter provides an overview of key IoT use cases and key connectivity elements of IoT solutions. The reader will get an understanding of the breadth of the IoT landscape.•\tPurpose of this book•\tBackground and Terminology•\tKey IoT use caseso\tSmart citieso\tAsset trackingo\tSmart factorieso\tIndustrialo\tTransportationo\tDigital surveillance systemso\tRetailo\tMedical o\tIndoor location•\tEnd-to-end IoT building blockso\tThings\/devices\/sensorso\tEdge\/Gateway\/Fogo\tCloud•\tIoT Stakeholders\/Value Chaino\tChip Vendorso\tModule Vendorso\tSystem Integratorso\tODMso\tISVso\tEnd Customers\u003cbr\u003eChapter 2: Considerations in choosing a connectivity technologyChapter Goals: This chapter highlights the fragmentation of connectivity standards and solutions and the challenge in navigating the many standards and technologies and also discusses the tradeoffs between different wireless technologies and network topologies. Also, this chapter provides the motivation for using wireless technologies in IoT products as well as challenges.•\tCompute and connect are integral functions that are fully integrated in single SoC-for lower cost and low power solutions•\tBenefits of wireless•\tSeamless wireless connectivity for mobility applications•\tRemote Commissioning, ease of deployment, OTA update, device identification•\tChallenges of Wireless Connectivity•\tFragmentation of the IoT Ecosystemo\tDiscussion of IoT Framework Open Connectivity Foundation etc.o\tInteroperability (open standards)•\tCoexistence and interference•\tWireless security is vital•\tCertification (Industry, regulatory, operator)o\tCertified labs•\tAntenna design challenges•\tConsiderations in choosing a connectivity technologyo\tEnergy\/power\/cost tradeoffso\tSelection of network architectures and topologieso\tWireless standards and alignment to use cases-how to choose the right wireless protocol for the jobo\tSelection criteria-range, data rate, power, security, latency, capacity, etc.•\tWireless Standard BodiesSubchapter Goal: Overview of Connectivity standards including 15.4, ZigBee, Thread, 6LoWPAN, wi-fi, BT, LTE, 5G etc. and which is appropriate for each use case; include cost considerationso\tWiFi Allianceo\tBT SIGo\tZigBee Allianceo\tThread Groupo\tDot doto\tZ-Waveo\t3GPP (ITU-T)\u003cbr\u003eChapter Goals: The following chapters (3 to 10) provide a deep dive on each connectivity technology and considerations on selecting it for the IoT use cases\u003cbr\u003eChapter 3: Wi-Fi •\tWi-Fi mesh•\tWiFi 802.11a\/b\/g\/n\/ac•\tWiFi 6\u003cbr\u003eChapter 4: Bluetooth•\tBLE•\tBT mesh•\tBT direction finding•\tBT beacons\u003cbr\u003eChapter 5: 802.15.4 (unlicensed)•\tZigBee•\tThread\u003cbr\u003eChapter 6: LPWAN•\tLora•\tSigFoxChapter 7: Cellular Technologies •\tNB IoT•\t3G•\t4G LTE•\tCBRS (Private LTE) \/ OnGo\u003cbr\u003eChapter 8: 5G•\teMBB•\tmMTC•\turLLC•\t5G TSN\u003cbr\u003eChapter 9: Ethernet•\tTSN•\tIndustrial Ethernet Technologies\u003cbr\u003eChapter 10: GNSS\u003cbr\u003eChapter 11: IoT Connectivity Frameworks and StacksChapter Goal: This chapter goes into detail on how to assemble all of the components of a working solution and discusses how to scale your solution to a product•\tSoftware stacks, drivers, operating systems, RTOS•\tGateway architecture including protocolso\tIoT protocols\tCoAP\tMQTT\tOPCUA•\tRF: antenna, PA, etc.•\tCoexistence•\tEnvironmental considerations, reliability, long life etc.•\tSecurity and privacy•\tManaging the network•\tCertification•\tPutting it together•\tHow to integrate and validate (chip vs pre-certified module)•\tScaling from project to product •\tPutting it together: Sample Projects•\tGo through the earlier examples and discuss the complete products\u003cbr\u003eChapter 12: The Future of IoT ConnectivityChapter Goal: This chapter discusses emerging connectivity technologies for addressing new use cases as well as advancing and optimizing the performance of existing technologies•\tThings\/sensors (low power, battery powered, low compute, need wireless connectivity, small memory footprint, small RTOS footprint)•\tSoftware defined radio•\tWhat is coming next?•\tFuture technologies: Wi-Fi 7, etc.•\tNext steps for the reader•\tWhere to get more information\u003cbr\u003eReferencesIndex","brand":"APress","offers":[{"title":"Default Title","offer_id":48885829665111,"sku":"9781484288962","price":999.99,"currency_code":"GBP","in_stock":false}]},{"product_id":"employeecentric-it-9781484291856","title":"EmployeeCentric IT","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cdiv\u003e\n\u003cdiv\u003eGlobal surveys from McKinsey, BCG, Gartner, and others show that less than 30% of digital transformation programs succeed in their missions to improve a company''s performance and employee productivity. This is due to the fact that IT efforts within the company do not center around the employee. This book will provide concrete steps to allow both IT professionals and business leaders to transform the way they deliver IT to employees - with the employee (the human) centered in their transformation.\u003c\/div\u003e\n\u003cdiv\u003e\u003cbr\u003e\u003c\/div\u003e\n\u003cdiv\u003e\u003cdiv\u003eThe concepts, models, checklists, and playbook you''ll review are based on the author''s many years of experience, lessons learned, and proven outcomes. IT organizations want to improve their employee experience but don''t know how and this is the must have book for those who don''t know where to start. More than two-thirds of today''s jobs require good digital and IT skills from employees. The expectations\u0026amp;n\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e\u003cp\u003eIntroduction (introduction to the topic and why Employee centric IT is needed) \u003c\/p\u003e\n\u003cp\u003e○\tChapter 1: From Technology Centric to Employee Centric IT\u003c\/p\u003e\n\u003cp\u003e■\tDysfunctions of IT\u003c\/p\u003e\n\u003cp\u003e■\tUnderstanding Employees as Humans and not data points\u003c\/p\u003e\n\u003cp\u003e○\tChapter 2: Employee Experience and its core pillar – Employee Centric IT\u003c\/p\u003e■\tWhy Employees are Forgotten\u003cp\u003e\u003c\/p\u003e\n\u003cp\u003e■\tDimensions of Employee Centric IT\u003c\/p\u003e\n\u003cp\u003e■\tTrust Equation \u003c\/p\u003e\n\u003cp\u003ePart 1: Winning Employees’ Hearts (Covering the activities to achieve the first part of the trust equation which is winning the hearts) \u003c\/p\u003e\n\u003cp\u003e○\tChapter 3: Winning the Engagement\t\u003c\/p\u003e■\tEmployee Engagement\t\u003cp\u003e\u003c\/p\u003e\n\u003cp\u003e■\tCommunity Engagement\u003c\/p\u003e\n\u003cp\u003e■\tSummary and Self-Assessment\u003c\/p\u003e\n\u003cp\u003e■\tChecklist for Winning the Engagement\t\u003c\/p\u003e\n\u003cp\u003e○\tChapter 4: Winning the Support\t\u003c\/p\u003e\n\u003cp\u003e■\tFocused and employee-centered “care”\u003c\/p\u003e\n\u003cp\u003e■\tListening\u003c\/p\u003e\n\u003cp\u003e■\tSummary and Self-Assessment\u003c\/p\u003e\n\u003cp\u003e■\tChecklist for Winning the Support \u003c\/p\u003e\n\u003cp\u003e○\tChapter 5: Winning the Culture\u003c\/p\u003e\n\u003cp\u003e■\tCommunication\u003c\/p\u003e■\tCollaboration\u003cp\u003e\u003c\/p\u003e\n\u003cp\u003e■\tTechnology\u003c\/p\u003e\n\u003cp\u003e■\tSummary and Self-Assessment\u003c\/p\u003e\n\u003cp\u003e■\tChecklist for Winning the Culture\u003c\/p\u003e\n\u003cp\u003ePart 2: Winning Employees’ Minds (Covering the activities to achieve the second part of the trust equation which is winning their minds) \u003c\/p\u003e\n\u003cp\u003e○\tChapter 6: Winning the Operations\t\u003c\/p\u003e\n\u003cp\u003e■\tData Driven\t\u003c\/p\u003e\n\u003cp\u003e■\tEducation Driven\t\u003c\/p\u003e\n\u003cp\u003e■\tPersonas\u003c\/p\u003e\n\u003cp\u003e■\tProductivity Driven\u003c\/p\u003e\n\u003cp\u003e■\tSummary and Self-Assessment\u003c\/p\u003e■\tChecklist for Winning the Operations\t\u003cp\u003e\u003c\/p\u003e\n\u003cp\u003e○\tChapter 7: Winning the Transformation\t\u003c\/p\u003e\n\u003cp\u003e■\tPriming of the change\u003c\/p\u003e\n\u003cp\u003e■\tChange Impact Analysis\u003c\/p\u003e\n\u003cp\u003e■\tSummary and Self-Assessment\u003c\/p\u003e\n\u003cp\u003e■\tChecklist for Winning the Transformation\t\u003c\/p\u003e\n\u003cp\u003e○\tChapter 8: Winning the Innovation\u003c\/p\u003e\n\u003cp\u003e■\tIncremental \u003c\/p\u003e\n\u003cp\u003e■\tRadical\u003c\/p\u003e\n\u003cp\u003e■\tSummary and Self-Assessment\u003c\/p\u003e\n\u003cp\u003e■\tChecklist for Winning the Innovation\t\u003c\/p\u003e\n\u003cp\u003ePart 3: Winning your IT Team\t(steps to take to win IT team’s acceptance of the change needed towards employee-centricity and how to achieve it)\u003c\/p\u003e\n\u003cp\u003e○\tChapter 9: Winning the IT Team’s Structure\u003c\/p\u003e\n\u003cp\u003e■\tSummary and Self-Assessment\u003c\/p\u003e\n\u003cp\u003e■\tChecklist for Winning the Structure\u003c\/p\u003e\n\u003cp\u003e○\tChapter 10: Winning the IT Team’s processes\t\u003c\/p\u003e\n\u003cp\u003e■\tSummary and Self-Assessment\u003c\/p\u003e\n\u003cp\u003e■\tChecklist for Winning the Processes\u003c\/p\u003e\n\u003cp\u003e○\tChapter 11: Winning the IT Talent \u0026amp; Skills\u003c\/p\u003e\n\u003cp\u003e■\tSummary and Self-Assessment\u003c\/p\u003e\n\u003cp\u003e■\tChecklist for Winning the Talent \u0026amp; Skills\u003c\/p\u003e○\tChapter 12: Winning the IT Leadership \u0026amp; Culture\t\u003cp\u003e\u003c\/p\u003e\n\u003cp\u003e■\tCollaboration\u003c\/p\u003e\n\u003cp\u003e■\tPsychological Safety\u003c\/p\u003e\n\u003cp\u003e■\tSummary and Self-Assessment\u003c\/p\u003e\n\u003cp\u003e■\tChecklist for Winning the Leadership \u0026amp; Culture\u003c\/p\u003e\n\u003cp\u003ePart 4: Evangelizing Employee Centric IT in your organization (Putting all the steps together in a playbook to be used in implementing Employee centricity in an organization) \u003c\/p\u003e\n\u003cp\u003e○\tChapter 13: Implementing \u0026amp; Scaling Employee Centric IT for your Company\u003c\/p\u003e\n\u003cp\u003e■\tPreparation \u003c\/p\u003e\n\u003cp\u003e■\tImplementation \u003c\/p\u003e\n\u003cp\u003e■\tLessons Learnt and Pitfalls\u003c\/p\u003e\n\u003cp\u003e○\tChapter 14: How to deal with the Hybrid Way of working and Employee Centricity\u003c\/p\u003e\n\u003cp\u003e○\tChapter 15: There is no End in Sight\u003c\/p\u003e\n\u003cp\u003e●\tConclusion\u003c\/p\u003e\n\u003cbr\u003e\n\u003c\/div\u003e\u003c\/div\u003e\n\u003c\/div\u003e","brand":"APress","offers":[{"title":"Default Title","offer_id":48885831696727,"sku":"9781484291856","price":37.49,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9781484291856.jpg?v=1722537855"},{"product_id":"beginning-aws-security-9781484296806","title":"Beginning AWS Security","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003eImprove cloud security within your organization by leveragingAWS's Shared Responsibility Model, Well-Architected Framework, and the Cloud Adoption Framework. This book will show you to use these tools to make the best decisions for securing your cloud environment.You'll start by understanding why security is important in the cloud and then review the relevant services offered to meet an organization's needs. You'll then move on to the finer points of building a secure architecture and take a deep look into the differences of responsibility of managed services and those that allow customers more control.   With multiple AWS services available, organizations must weigh the tradeoffs between those that provide granular control (IaaS), a managed service (PaaS), delivering applications remotely over the internet instead of locally on machines (SaaS). This book will help you to identify the appropriate resources and show you how to implement them to meet an organization's business, technical\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003eChapter 1:  Why Do I Care About Security?  Isn’t that AWS’s problem?Chapter Goal:  Identify why security is important in the cloud.No of pages: 40 -50 pagesSub -Topics1.\tIntroduce some real life security breaches and outcomes that have happened in the cloud.2.\tDescribe how AWS provides resources to build a cloud architecture but it’s important to understand the tradeoffs of each service.3.\tIntroduce the Shared Responsibility Model (covered more in Chapter 2)4.\tIntroduce the Well-Architected Framework (will be used as reference throughout the book)5.\tDescribe the similarities and differences between cloud and traditional computing.\u003cbr\u003eChapter 2:  Who is Responsible Again?Chapter Goal: Develop an understanding of the Shared Responsibility Model and the tradeoffs of responsibilities based on services used.No of pages: 40 -50Sub - Topics\t1.\t  Detailed overview of the Shared Responsibility Model2.\t  Elaborate what is meant by “tradeoffs” and why understanding this is important.3.\t Review of AWS’s security precautions 4.\t Align how the Well-Architected Framework supports the Shared Responsibility Model5.\tDescribe the purpose and responsibilities for Identity and access management\u003cbr\u003eChapter 3: How Do I Build a Secure Architecture?Chapter Goal: Dive deeper into the differences of responsibility of managed services and those that allow customers more control.  Identify tradeoffs on specific categories.No of pages : 40 - 50Sub - Topics:\t 1.\tIdentify and understand services, responsibilities, and tradeoffs for computing services.2.\tIdentify and understand services, responsibilities, and tradeoffs for storage services.3.  Identify and understand services, responsibilities and tradeoffs for networking services.4.  Identify and understand services, responsibilities and tradeoffs for database services.6.\tIdentify and understand services to protect data at rest and in transit.7.\tIdentify and understand services to monitor access and notifications.\u003cbr\u003eChapter 4:  Security is Not Built in a DayChapter Goal: Develop an understanding that security is not “one and done” and that updates and monitoring is a continued part of AWS security.No of pages: 40 - 50Sub - Topics: 1.\tIdentify and describe what it means to be proactive and reactive in security.2.\tIdentify and implement monitoring services into architecture 3.\tIdentify and understand the costs of the monitoring services4.\tIdentify how to make updates and patches to software - and who is responsible for what.\u003cbr\u003eChapter 5:  Is This the End?\u003cbr\u003eChapter Goal: Reinforce the need for lifelong learning.  Just as security is not a “one and done”, learning should be continuous as well.  No of pages: 10 - 20Sub - Topics: 1.\tIdentify resources available to continue learning from AWS (AWS Educate, AWS Academy, AWS Skillbuilder)2.\tIdentify resources available to continue learning from the publisher3.\tA final review of the Shared Responsibility Model.4.\tA final review of the Well-Architected Framework\u003cbr\u003e\u003cbr\u003e","brand":"APress","offers":[{"title":"Default Title","offer_id":48885834252631,"sku":"9781484296806","price":20.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9781484296806.jpg?v=1722537864"},{"product_id":"cybersecurity-cyberanalysis-warning-9781606926581","title":"Cybersecurity, Cyberanalysis \u0026 Warning","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003eCyber analysis and warning capabilities are critical to thwarting computer-based (cyber) threats and attacks. The Department of Homeland Security (DHS) established the United States Computer Emergency Readiness Team (US-CERT) to, among other things, co-ordinate the nation''s efforts to prepare for, prevent, and respond to cyber threats to systems and communications networks. The authors'' objectives were to (1) identify key attributes of cyber analysis and warning capabilities, (2) compare these attributes with US-CERT''s current capabilities to identify whether there are gaps, and (3) identify US-CERT''s challenges to developing and implementing key attributes and a successful national cyber analysis and warning capability. To address these objectives, the authors identified and analysed related documents, observed operations at numerous entities, and interviewed responsible officials and experts.","brand":"Nova Science Publishers Inc","offers":[{"title":"Default Title","offer_id":48886699000151,"sku":"9781606926581","price":999.99,"currency_code":"GBP","in_stock":false}]},{"product_id":"interperetable-ai-9781617297649","title":"Interperetable AI","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cp\u003eAI models can become so complex that even experts have difficulty understanding them—and forget about explaining the nuances of a cluster of novel algorithms to a business stakeholder! \u003cb\u003e\u003ci\u003eInterpretableAI \u003c\/i\u003e\u003c\/b\u003eis filled with cutting-edge techniques that will improve your understanding of how your AI models function.   \u003c\/p\u003e \u003cp\u003e\u003cb\u003e\u003ci\u003eInterpretableAI\u003c\/i\u003e\u003c\/b\u003e is a hands-on guide to interpretability techniques that open up the black box of AI. This practical guide simplifies cutting edge research into transparent and explainable AI, delivering practical methods you can easily implement with Python and opensource libraries. With examples from all major machine learning approaches, this book demonstrates why some approaches to AI are so opaque, teaches you toidentify the patterns your model has learned, and presents best practices for building fair and unbiased models.\u003c\/p\u003e \u003cp\u003eHow deep learning models produce their results is often a complete mystery, even to their creators. These AI\"black boxes\" can hide unknown issues—including data leakage, the replication of human bias, and difficulties complying with legal requirements such as the EU's \"right to explanation.\" State-of-the-art interpretability techniques have been developed to understand even the most complex deep learning models, allowing humans to follow an AI's methods and to better detect when it has made a mistake.\u003c\/p\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTrade Review\u003c\/b\u003e\u003cbr\u003e\u003cp\u003e“I think this is a valuable book both for beginners as well for more experienced users.”\u003cb\u003eKim Falk Jørgensen\u003c\/b\u003e   \u003c\/p\u003e \u003cp\u003e“This book provides a great insight into the interpretability step of developing a structured learning robust AI systems.” \u003cb\u003eIzharHaq\u003c\/b\u003e   \u003c\/p\u003e \u003cp\u003e“Really great introduction to interpretability of ML models as well asgreat examples of how you can do it to your own models.” \u003cb\u003eJonathanWood\u003c\/b\u003e   \u003c\/p\u003e \u003cp\u003e“Techniques are consistently presented with excellent examples.” \u003cb\u003eJamesJ. Byleckie\u003c\/b\u003e   \u003c\/p\u003e \u003cp\u003e“A fine book towards making ML models less opaque.” \u003cb\u003eAlainCouniot\u003c\/b\u003e   \u003c\/p\u003e \u003cp\u003e“Read this to understand what the model actually says about the underlying data.” \u003cb\u003eShashank Polasa\u003c\/b\u003e   \u003c\/p\u003e \u003cp\u003e“Everybody working with ML models should be able to interpret (and check) results. This book will help you with that.” \u003cb\u003eKaiGellien    \u003c\/b\u003e\u003c\/p\u003e","brand":"Manning Publications","offers":[{"title":"Default Title","offer_id":48886900425047,"sku":"9781617297649","price":36.09,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9781617297649.jpg?v=1722542091"},{"product_id":"federal-cybersecurity-planning-human-capital-research-development-9781619427693","title":"Federal Cybersecurity Planning: Human Capital \u0026","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e","brand":"Nova Science Publishers Inc","offers":[{"title":"Default Title","offer_id":48886937026903,"sku":"9781619427693","price":52.69,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9781619427693.jpg?v=1722542251"},{"product_id":"the-target-store-data-breaches-examination-and-insight-9781633212695","title":"The Target Store Data Breaches: Examination and","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e","brand":"Nova Science Publishers Inc","offers":[{"title":"Default Title","offer_id":48887136977239,"sku":"9781633212695","price":131.19,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9781633212695.jpg?v=1722543178"},{"product_id":"audacity-to-spy-how-government-business-hackers-rob-us-of-privacy-9781935504795","title":"Audacity to Spy: How Government, Business \u0026","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003eEver get the feeling you are being watched? The thieves that steal identities are using cutting-edge, high-tech tools that can take one fact from a social media site, another from an online travel survey, a third from a purchase made via the internet and even access highly confidential medical records. Little by little they piece together your buying habits, your religious and school affiliations, the names of your family and pets, your political views, your driving habits, the places you have vacationed, and much, much more. This is not science fiction and this is not the future, this is what is happening to each and every one of us now - today. And although the vast majority of adults say they are concerned about providing personal information online, nearly 1\/3 say they have never used a privacy setting on their computer, never inquired about the charities to whom they donate their money, never worried about someone accessing their medical information and never thought twice about giving a financial institution their social security number over the internet. The Audacity to Spy, written by an attorney with an interest in privacy laws and legislation and her grandmother who is an experienced Information Analyst, reveals the ways in which your identity and personal data have been stolen by various sources. Yes, you should be concerned about the NSA and other government agencies having your phone logs and emails; but you should worry more about the insidious data brokers that are collecting information about you every time you log on to your laptop, use your cell phone, access an app, or use your GPS. Companies are collecting a variety of data about you, combining it with location information, and using it to both personalise their own services and to sell to other advertisers for behavioural marketing. Law enforcement agencies are tracking your car and insurance companies are installing devices to monitor your driving. Clerks are making copies of your credit cards. And if that wasn''t enough, the FBI has reported that hackers have been discovered embedding malicious software in two million computers, opening a virtual door for criminals to rifle through users'' valuable personal and financial information. More than warning you about the ways your data can be stolen, at the end of each chapter are suggestions for limiting the amount of personal data that is available to be seized and divulged. Can you completely cut off the flow of information about yourself? The answer is no, not completely - there is already too much data out there and increasingly sophisticated ways to obtain bits and pieces. But knowing how it is collected, and by whom, gives you the power to control sensitive information and determine how much of your life you wish to expose to those more than willing to exploit it.","brand":"Technics Publications LLC","offers":[{"title":"Default Title","offer_id":48888776819031,"sku":"9781935504795","price":999.99,"currency_code":"GBP","in_stock":false}]},{"product_id":"information-systems-security-in-small-and-medium-sized-enterprises-emerging-cybersecurity-threats-in-turbulent-times-9798886973907","title":"Information Systems Security in Small and","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e","brand":"Nova Science Publishers Inc","offers":[{"title":"Default Title","offer_id":48890364985687,"sku":"9798886973907","price":58.39,"currency_code":"GBP","in_stock":false}]},{"product_id":"network-defense-and-countermeasures-9780138200589","title":"Network Defense and Countermeasures","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cp\u003e\u003cstrong\u003eDr. Chuck Easttom \u003c\/strong\u003eis the author of 41 books, including several on computer security, forensics, and cryptography. He is also an inventor with 25 patents and the author of over 70 research papers. He holds a Doctor of Science in cybersecurity, a Ph.D. in nanotechnology, a Ph.D. in computer science, and three master's degrees (one in applied computer science, one in education, and one in systems engineering). He is a senior member of both the IEEE and the ACM. He is also a Distinguished Speaker of the ACM and a Distinguished Visitor of the IEEE. Dr. Easttom is currently an adjunct professor for Georgetown University and for Vanderbilt University.\u003c\/p\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e\u003cp\u003e\u003cstrong\u003e    Preface xxiii\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 1: Introduction to Network Security 2\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003e    Introduction\u003c\/strong\u003e\u003cstrong\u003e.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . \u003c\/strong\u003e\u003cstrong\u003e2\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e    The Basics of a Network.. . . . . . . . . . . . . . . . . . . . . . . . . 3\u003c\/p\u003e \u003cp\u003e    Basic Network Utilities.. . . . . . . . . . . . . . . . . . . . . . . . . 11\u003c\/p\u003e \u003cp\u003e    The OSI Model.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15\u003c\/p\u003e \u003cp\u003e    What Does This Mean for Security?. . . . . . . . . . . . . . . . . . . . 16\u003c\/p\u003e \u003cp\u003e    Assessing Likely Threats to the Network. . . . . . . . . . . . . . . . . . 16\u003c\/p\u003e \u003cp\u003e    Classifications of Threats.. . . . . . . . . . . . . . . . . . . . . . . . 20\u003c\/p\u003e \u003cp\u003e    Likely Attacks.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24\u003c\/p\u003e \u003cp\u003e    Threat Assessment.. . . . . . . . . . . . . . . . . . . . . . . . . . . 25\u003c\/p\u003e \u003cp\u003e    Understanding Security Terminology.. . . . . . . . . . . . . . . . . . . . 26\u003c\/p\u003e \u003cp\u003e    Choosing a Network Security Approach.. . . . . . . . . . . . . . . . . . 30\u003c\/p\u003e \u003cp\u003e    Network Security and the Law.. . . . . . . . . . . . . . . . . . . . . . 32\u003c\/p\u003e \u003cp\u003e    Using Security Resources. . . . . . . . . . . . . . . . . . . . . . . . 34\u003c\/p\u003e \u003cp\u003e    Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35\u003c\/p\u003e \u003cp\u003e    Endnotes. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 2: Types of Attacks 42\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e    Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 42\u003c\/p\u003e \u003cp\u003e    Understanding Denial of Service Attacks.. . . . . . . . . . . . . . . . . . 43\u003c\/p\u003e \u003cp\u003e    Defending Against Buffer Overflow Attacks.. . . . . . . . . . . . . . . . . 63\u003c\/p\u003e \u003cp\u003e    Defending Against IP Spoofing. . . . . . . . . . . . . . . . . . . . . . 64\u003c\/p\u003e \u003cp\u003e    Defending Against Session Hijacking.. . . . . . . . . . . . . . . . . . . 66\u003c\/p\u003e \u003cp\u003e    Blocking Virus and Trojan Horse Attacks. . . . . . . . . . . . . . . . . . 66\u003c\/p\u003e \u003cp\u003e    Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 75\u003c\/p\u003e \u003cp\u003e    Endnotes. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 75\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 3: Fundamentals of Firewalls 82\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e    Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 82\u003c\/p\u003e \u003cp\u003e    What Is a Firewall?. . . . . . . . . . . . . . . . . . . . . . . . . . . 83\u003c\/p\u003e \u003cp\u003e    Implementing Firewalls.. . . . . . . . . . . . . . . . . . . . . . . . . 90\u003c\/p\u003e \u003cp\u003e    Firewall Deployment.. . . . . . . . . . . . . . . . . . . . . . . . . . 95\u003c\/p\u003e \u003cp\u003e    Selecting and Using a Firewall.. . . . . . . . . . . . . . . . . . . . . . 96\u003c\/p\u003e \u003cp\u003e    Using Proxy Servers.. . . . . . . . . . . . . . . . . . . . . . . . . . 97\u003c\/p\u003e \u003cp\u003e    Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 99\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 4: Firewall Practical Applications 106\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e    Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 106\u003c\/p\u003e \u003cp\u003e    Using Single Machine Firewalls.. . . . . . . . . . . . . . . . . . . . . 107\u003c\/p\u003e \u003cp\u003e    Windows 10 Firewall.. . . . . . . . . . . . . . . . . . . . . . . . . . 108\u003c\/p\u003e \u003cp\u003e    User Account Control.. . . . . . . . . . . . . . . . . . . . . . . . . 110\u003c\/p\u003e \u003cp\u003e    Linux Firewalls.. . . . . . . . . . . . . . . . . . . . . . . . . . . . 110\u003c\/p\u003e \u003cp\u003e    Using Small Office\/Home Office Firewalls.. . . . . . . . . . . . . . . . . 118\u003c\/p\u003e \u003cp\u003e    Using Medium-Sized Network Firewalls.. . . . . . . . . . . . . . . . . . 121\u003c\/p\u003e \u003cp\u003e    Using Enterprise Firewalls. . . . . . . . . . . . . . . . . . . . . . . . 124\u003c\/p\u003e \u003cp\u003e    Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 125\u003c\/p\u003e \u003cp\u003e    Endnotes. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 125\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 5: Intrusion-Detection Systems 132\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e    Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 132\u003c\/p\u003e \u003cp\u003e    Understanding IDS Concepts.. . . . . . . . . . . . . . . . . . . . . . 133\u003c\/p\u003e \u003cp\u003e    IDS Components and Processes.. . . . . . . . . . . . . . . . . . . . . 135\u003c\/p\u003e \u003cp\u003e    SIEM.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 136\u003c\/p\u003e \u003cp\u003e    Evasion Techniques.. . . . . . . . . . . . . . . . . . . . . . . . . . 137\u003c\/p\u003e \u003cp\u003e    Understanding and Implementing IDSs.. . . . . . . . . . . . . . . . . . 138\u003c\/p\u003e \u003cp\u003e    Understanding and Implementing Honeypots. . . . . . . . . . . . . . . . 141\u003c\/p\u003e \u003cp\u003e    Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 146\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 6: Encryption Fundamentals 152\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e    Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 152\u003c\/p\u003e \u003cp\u003e    The History of Encryption.. . . . . . . . . . . . . . . . . . . . . . . . 153\u003c\/p\u003e \u003cp\u003e    Learning About Modern Encryption Methods.. . . . . . . . . . . . . . . . 160\u003c\/p\u003e \u003cp\u003e    Identifying Good Encryption.. . . . . . . . . . . . . . . . . . . . . . . 173\u003c\/p\u003e \u003cp\u003e    Understanding Digital Signatures and Certificates.. . . . . . . . . . . . . . 174\u003c\/p\u003e \u003cp\u003e    MAC and HMAC.. . . . . . . . . . . . . . . . . . . . . . 179\u003c\/p\u003e \u003cp\u003e    Understanding and Using Decryption.. . . . . . . . . . . . . . . . . . . 179\u003c\/p\u003e \u003cp\u003e    Cracking Passwords.. . . . . . . . . . . . . . . . . . . . . . . . . . 180\u003c\/p\u003e \u003cp\u003e    Steganography. . . . . . . . . . . . . . . . . . . . . . . . . . . . 184\u003c\/p\u003e \u003cp\u003e    Steganalysis.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 185\u003c\/p\u003e \u003cp\u003e    Quantum Computing and Quantum Cryptography. . . . . . . . . . . . . . 186\u003c\/p\u003e \u003cp\u003e    Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 187\u003c\/p\u003e \u003cp\u003e    Endnote.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 187\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 7: Virtual Private Networks 194\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e    Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 194\u003c\/p\u003e \u003cp\u003e    Basic VPN Technology.. . . . . . . . . . . . . . . . . . . . . . . . . 195\u003c\/p\u003e \u003cp\u003e    Using VPN Protocols for VPN Encryption.. . . . . . . . . . . . . . . . . 197\u003c\/p\u003e \u003cp\u003e    IPsec.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 206\u003c\/p\u003e \u003cp\u003e    SSL\/TLS.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 207\u003c\/p\u003e \u003cp\u003e    Other VPN Protocols.. . . . . . . . . . . . . . . . . . . . . . . . . . 209\u003c\/p\u003e \u003cp\u003e    Implementing VPN Solutions.. . . . . . . . . . . . . . . . . . . . . . 210\u003c\/p\u003e \u003cp\u003e    Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 215\u003c\/p\u003e \u003cp\u003e    Endnotes. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 215\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 8: Operating System Hardening 222\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e    Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 222\u003c\/p\u003e \u003cp\u003e    Configuring Windows Properly.. . . . . . . . . . . . . . . . . . . . . . 223\u003c\/p\u003e \u003cp\u003e    Configuring Linux Properly.. . . . . . . . . . . . . . . . . . . . . . . 244\u003c\/p\u003e \u003cp\u003e    Patching the Operating System.. . . . . . . . . . . . . . . . . . . . . 245\u003c\/p\u003e \u003cp\u003e    Configuring Browsers.. . . . . . . . . . . . . . . . . . . . . . . . . 246\u003c\/p\u003e \u003cp\u003e    Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 253\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 9: Defending Against Virus Attacks 260\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e    Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 260\u003c\/p\u003e \u003cp\u003e    Understanding Virus Attacks.. . . . . . . . . . . . . . . . . . . . . . 261\u003c\/p\u003e \u003cp\u003e    Virus Scanners.. . . . . . . . . . . . . . . . . . . . . . . . . . . . 270\u003c\/p\u003e \u003cp\u003e    Virus Scanning Techniques. . . . . . . . . . . . . . . . . . 272\u003c\/p\u003e \u003cp\u003e    When Antivirus Causes a Problem. . . . . . . . . . . . . . . 274\u003c\/p\u003e \u003cp\u003e    Commercial Antivirus Software.. . . . . . . . . . . . . . . . 274\u003c\/p\u003e \u003cp\u003e    Antivirus Policies and Procedures.. . . . . . . . . . . . . . . . . . . . 283\u003c\/p\u003e \u003cp\u003e    Additional Methods for Defending Your System.. . . . . . . . . . . . . . . 284\u003c\/p\u003e \u003cp\u003e    What to Do If Your System Is Infected by a Virus.. . . . . . . . . . . . . . 285\u003c\/p\u003e \u003cp\u003e    Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 288\u003c\/p\u003e \u003cp\u003e    Endnotes. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 288\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 10: Defending Against Trojan Horses and Phishing 296\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e    Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 296\u003c\/p\u003e \u003cp\u003e    Trojan Horses.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 297\u003c\/p\u003e \u003cp\u003e    Phishing.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 307\u003c\/p\u003e \u003cp\u003e    Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 313\u003c\/p\u003e \u003cp\u003e    Endnotes. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 313\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 11: Security Policies 318\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e    Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 318\u003c\/p\u003e \u003cp\u003e    ISO 27002. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 319\u003c\/p\u003e \u003cp\u003e    Important Standards.. . . . . . . . . . . . . . . . . . . . . . . . . . 322\u003c\/p\u003e \u003cp\u003e    Defining User Policies.. . . . . . . . . . . . . . . . . . . . . . . . . 324\u003c\/p\u003e \u003cp\u003e    Defining System Administration Policies.. . . . . . . . . . . . . . . . . . 331\u003c\/p\u003e \u003cp\u003e    Defining Access Control.. . . . . . . . . . . . . . . . . . . . . . . . 336\u003c\/p\u003e \u003cp\u003e    Defining Developmental Policies.. . . . . . . . . . . . . . . . . . . . . 337\u003c\/p\u003e \u003cp\u003e    Disaster Recovery.. . . . . . . . . . . . . . . . . . . . . . . . . . . 338\u003c\/p\u003e \u003cp\u003e    Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 339\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 12: Assessing System Security 346\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e    Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 346\u003c\/p\u003e \u003cp\u003e    Risk Assessment Concepts.. . . . . . . . . . . . . . . . . . . . . . . 347\u003c\/p\u003e \u003cp\u003e    Evaluating the Security Risk.. . . . . . . . . . . . . . . . . . . . . . . 348\u003c\/p\u003e \u003cp\u003e    Conducting the Initial Assessment. . . . . . . . . . . . . . . . . . . . 351\u003c\/p\u003e \u003cp\u003e    Probing the Network.. . . . . . . . . . . . . . . . . . . . . . . . . . 357\u003c\/p\u003e \u003cp\u003e    Vulnerabilities.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 381\u003c\/p\u003e \u003cp\u003e    McCumber Cube.. . . . . . . . . . . . . . . . . . . . . . . . . . . 384\u003c\/p\u003e \u003cp\u003e    Security Documentation.. . . . . . . . . . . . . . . . . . . . . . . . 385\u003c\/p\u003e \u003cp\u003e    Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 388\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 13: Security Standards 394\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e    Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 394\u003c\/p\u003e \u003cp\u003e    COBIT.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 394\u003c\/p\u003e \u003cp\u003e    ISO Standards.. . . . . . . . . . . . . . . . . . . . . . . . . . . . 396\u003c\/p\u003e \u003cp\u003e    NIST Standards.. . . . . . . . . . . . . . . . . . . . . . . . . . . . 397\u003c\/p\u003e \u003cp\u003e    U.S. DoD Standards.. . . . . . . . . . . . . . . . . . . . . . . . . . 403\u003c\/p\u003e \u003cp\u003e    Using the Common Criteria.. . . . . . . . . . . . . . . . . . . . . . . 405\u003c\/p\u003e \u003cp\u003e    Using Security Models.. . . . . . . . . . . . . . . . . . . . . . . . . 407\u003c\/p\u003e \u003cp\u003e    U.S. Federal Regulations, Guidelines, and Standards.. . . . . . . . . . . . 410\u003c\/p\u003e \u003cp\u003e    Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 413\u003c\/p\u003e \u003cp\u003e    Endnotes. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 414\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 14: Physical Security and Disaster Recovery 422\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e    Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 422\u003c\/p\u003e \u003cp\u003e    Physical Security.. . . . . . . . . . . . . . . . . . . . . . . . . . . 422\u003c\/p\u003e \u003cp\u003e    Disaster Recovery.. . . . . . . . . . . . . . . . . . . . . . . . . . . 428\u003c\/p\u003e \u003cp\u003e    Ensuring Fault Tolerance.. . . . . . . . . . . . . . . . . . . . . . . . 432\u003c\/p\u003e \u003cp\u003e    Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 435\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 15: Techniques Used by Attackers 438\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e    Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 438\u003c\/p\u003e \u003cp\u003e    Preparing to Hack.. . . . . . . . . . . . . . . . . . . . . . . . . . . 439\u003c\/p\u003e \u003cp\u003e    The Attack Phase. . . . . . . . . . . . . . . . . . . . . . . . . . . 453\u003c\/p\u003e \u003cp\u003e    Session Hijacking. . . . . . . . . . . . . . . . . . . . . . . . . . . 457\u003c\/p\u003e \u003cp\u003e    Wi-Fi Hacking. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 459\u003c\/p\u003e \u003cp\u003e    Bluetooth Hacking.. . . . . . . . . . . . . . . . . . . . . . . . . . . 459\u003c\/p\u003e \u003cp\u003e    Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 462\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 16: Introduction to Forensics 466\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e    Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 466\u003c\/p\u003e \u003cp\u003e    General Forensics Guidelines.. . . . . . . . . . . . . . . . . . . . . . 467\u003c\/p\u003e \u003cp\u003e    FBI Forensics Guidelines. . . . . . . . . . . . . . . . . . . . . . . . 470\u003c\/p\u003e \u003cp\u003e    Imaging a Drive.. . . . . . . . . . . . . . . . . . . . . . . . . . . . 471\u003c\/p\u003e \u003cp\u003e    Finding Evidence on the PC.. . . . . . . . . . . . . . . . . . . . . . . 474\u003c\/p\u003e \u003cp\u003e    Gathering Evidence from a Cell Phone.. . . . . . . . . . . . . . . . . . 485\u003c\/p\u003e \u003cp\u003e    Forensic Tools to Use.. . . . . . . . . . . . . . . . . . . . . . . . . 491\u003c\/p\u003e \u003cp\u003e    AccessData Forensic Toolkit.. . . . . . . . . . . . . . . . . 491\u003c\/p\u003e \u003cp\u003e    EnCase.. . . . . . . . . . . . . . . . . . . . . . . . . . 492\u003c\/p\u003e \u003cp\u003e    The Sleuth Kit. . . . . . . . . . . . . . . . . . . . . . . 492\u003c\/p\u003e \u003cp\u003e    OSForensics. . . . . . . . . . . . . . . . . . . . . . . . 492\u003c\/p\u003e \u003cp\u003e    Forensic Science.. . . . . . . . . . . . . . . . . . . . . . . . . . . 493\u003c\/p\u003e \u003cp\u003e    To Certify or Not to Certify?.. . . . . . . . . . . . . . . . . . . . . . . 493\u003c\/p\u003e \u003cp\u003e    Expert Witnesses.. . . . . . . . . . . . . . . . . . . . . . . . . . . 494\u003c\/p\u003e \u003cp\u003e    Additional Types of Forensics.. . . . . . . . . . . . . . . . . . . . . . 495\u003c\/p\u003e \u003cp\u003e    Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 499\u003c\/p\u003e \u003cp\u003e    Endnote.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 499\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eChapter 17: Cyber Warfare and Terrorism 504\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e    Introduction.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 504\u003c\/p\u003e \u003cp\u003e    Defending Against Computer-Based Espionage. . . . . . . . . . . . . . . 505\u003c\/p\u003e \u003cp\u003e    Defending Against Computer-Based Terrorism. . . . . . . . . . . . . . . 508\u003c\/p\u003e \u003cp\u003e    Choosing Defense Strategies.. . . . . . . . . . . . . . . . . . . . . . 514\u003c\/p\u003e \u003cp\u003e    Summary.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 524\u003c\/p\u003e \u003cp\u003e    Endnotes. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 524\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eAppendix A: Answers 530\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e\u003cstrong\u003eGlossary 542\u003c\/strong\u003e\u003c\/p\u003e \u003cp\u003e \u003c\/p\u003e \u003cp\u003e9780138200589, 9\/1\/2023\u003c\/p\u003e","brand":"Pearson Education (US)","offers":[{"title":"Default Title","offer_id":49083359035735,"sku":"9780138200589","price":64.79,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9780138200589.jpg?v=1725548665"},{"product_id":"blockchain-hype-or-innovation-9783030615581","title":"Blockchain: Hype or Innovation","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003e\u003cp\u003eThis book focuses on the innovation of blockchain technology and the advantages it offers. It provides a clear and comprehensive overview of blockchain technology and its possibilities, and thereby helps readers to form an opinion and draw their own conclusions about its potential exploitations.\u003c\/p\u003e\u003cp\u003eThe book begins with a chapter on the topic of decentralized networks, which familiarizes readers with their challenges by using the example of an online trading platform. Hereinafter, it is then detailed what blockchain technology is, where it comes from, and how it works. The necessary underlying technologies are explained, and various individual approaches as well as their composition are presented. Using well-known examples such as Bitcoin and Ethereum as an illustration, the book looks at the architecture of blockchain technology and focuses on the challenges such as security and scalability. The options available when introducing blockchain technology are also outlined, and best-practice examples are presented to get a better idea of what areas benefit from this technology.\u003cbr\u003e\u003c\/p\u003e\u003cp\u003eNumerous examples and detailed explanations will accompany the readers throughout the book. By the time they have reached the end, they will be able to decide for themselves what is truly innovative about blockchain technology and what is nothing more than hype.\u003cbr\u003e\u003c\/p\u003e\u003cbr\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e​1. Introduction.- 2. What Is Hidden Behind the Term “Blockchain”?.- 3. Technical Basics for a Better Understanding of Blockchain Technology.- 4. Where Does the Hype End, and Where Does the Innovation of Blockchain Technology Begin?.- 5. The Right Use Leads to Success.- 6. Projects and Application Areas of Blockchain Technology.- 7. Summary.","brand":"Springer Nature Switzerland AG","offers":[{"title":"Default Title","offer_id":49084750823767,"sku":"9783030615581","price":21.84,"currency_code":"GBP","in_stock":true}]},{"product_id":"silicon-valley-cybersecurity-conference-second-conference-svcc-2021-san-jose-ca-usa-december-2-3-2021-revised-selected-papers-9783030960568","title":"Silicon Valley Cybersecurity Conference: Second","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003eThis book constitutes selected and revised papers from the Second Silicon Valley Cybersecurity Conference, held in San Jose, USA, in December 2021. Due to the COVID-19 pandemic the conference was held in a virtual format. \u003cbr\u003eThe 9 full papers and one shoprt paper presented in this volume were thoroughly reviewed and selected from 15 submissions. They present most recent research on dependability, reliability, and security to address cyber-attacks, vulnerabilities, faults, and errors in networks and systems. \u003cbr\u003eChapters 1, 4, 5, 6, and 8-10 are published open access under a CC BY license (Creative Commons Attribution 4.0 International License).\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003eMachine Learning for Security.- Encryption.- Miscellaneous Security.","brand":"Springer Nature Switzerland AG","offers":[{"title":"Default Title","offer_id":49084752298327,"sku":"9783030960568","price":21.53,"currency_code":"GBP","in_stock":true}]}],"url":"https:\/\/bookcurl.com\/collections\/network-security.oembed?page=6","provider":"Book Curl","version":"1.0","type":"link"}