Buying options Buying options

Authorized Marketplace Sellers:
3 new & used from $3.71

Security+ in Depth

Campbell, Paul; Calvert, Ben; Boswell, Steven
ISBN-10: 1592000649
ISBN-13: 9781592000647

In our Marketplace:
3 new & used from $3.71
"Security+ In Depth' gives you the coverage you need to fully understand the current risks and threats to your organization?s data. If you are just entering the IT field, you will appreciate the comprehensive coverage of the tools and techniques necessary to safeguard electronic data. This book also serves as a valuable tool for those seeking to pass the CompTIA Security+ certification exam. "Security+ In Depth" provides hands on, practical techniques for working in the field of security in the twenty-first century.Ben Calvert is an information security consultant with an Arizona-based networking firm. He holds an MBA from Thunderbird - the American Graduate School of International Management, and has earned CNP and CCSE certifications.Steven Boswll is an internetworking consultant based in Phoenix, Arizona. He has earned the CCNP certification and holds an MBA in International Management from Thunderbird - The American Graduate School of International Management. He has worked extensively with a wide variety of clients throughout the world, from Fortune 50 financial services firms to national and regional governments.Paul Campbell has over seven years of computer and data networking experience Ben Calvert is an information security consultant with an Arizona-based networking firm Steven Boswell is an internetworking consultant based in Phoenix, Arizona
Prefacep. xiv
Security Overviewp. 1
Understanding Network Securityp. 2
Security Threatsp. 3
Integrityp. 4
Confidentialityp. 4
Availabilityp. 4
Security Ramifications: Costs of Intrusionp. 5
Technology Weaknessesp. 5
Configuration Weaknessesp. 6
Policy Weaknessesp. 6
Human Errorp. 7
Goals of Network Securityp. 8
Eliminating Theftp. 8
Determining Authenticationp. 8
Identifying Assumptionsp. 8
Controlling Secretsp. 8
Creating a Secure Network Strategyp. 9
Human Factorsp. 9
Knowing Your Weaknessesp. 9
Limiting Accessp. 9
Achieving Security through Persistencep. 10
Remembering Physical Securityp. 10
Perimeter Securityp. 10
Firewallsp. 10
Web and File Serversp. 10
Access Controlp. 11
Change Managementp. 11
Encryptionp. 11
Intrusion Detection Systemsp. 12
Chapter Summaryp. 12
Key Termsp. 12
Review Questionsp. 13
Authenticationp. 17
Usernames and Passwordsp. 18
Strong Password Creation Techniquesp. 19
Techniques to Use Multiple Passwordsp. 20
Storing Passwordsp. 20
Kerberosp. 20
Kerberos Assumptionsp. 21
Kerberos Authentication Processp. 21
Using Kerberos in Very Large Network Systemsp. 24
Security Weaknesses of Kerberosp. 25
Challenge Handshake Authentication Protocolp. 25
The CHAP Challenge-and-Response Sequencep. 25
CHAP Security Issuesp. 26
Mutual Authenticationp. 27
Digital Certificatesp. 27
Electronic Encryption and Decryption Conceptsp. 27
How Much Trust Should One Place in a CA?p. 29
Security Tokensp. 30
Passive Tokensp. 30
Active Tokensp. 31
One-time Passwordsp. 31
Biometricsp. 32
How a Biometric Authentication System Worksp. 32
False Positives and False Negativesp. 33
Different Kinds of Biometricsp. 34
General Trends in Biometricsp. 38
Multi-Factor Authenticationp. 39
Chapter Summaryp. 39
Key Termsp. 40
Review Questionsp. 42
Attacks and Malicious Codep. 47
Denial-of-Service Attacksp. 48
SYN Floodp. 49
Smurfp. 52
IP Fragmentation Attacks: Ping of Deathp. 53
Distributed Denial-of-Service Attacksp. 55
Setting Up DDoS Attacksp. 55
Conducting DDoS Attacksp. 56
DDoS Countermeasuresp. 57
Spoofingp. 60
IP Address Spoofingp. 60
ARP Poisoningp. 62
Web Spoofingp. 62
DNS Spoofingp. 64
Man in the Middlep. 64
Replaysp. 66
TCP Session Hijackingp. 67
Social Engineeringp. 69
Dumpster Divingp. 70
Online Attacksp. 70
Social Engineering Countermeasuresp. 70
Attacks against Encrypted Datap. 71
Weak Keysp. 71
Mathematical Attacksp. 71
Birthday Attackp. 72
Password Guessingp. 72
Brute Forcep. 73
Dictionaryp. 74
Software Exploitationp. 74
Malicious Softwarep. 75
Backdoorp. 79
Logic Bombsp. 83
Wormsp. 83
Chapter Summaryp. 84
Key Termsp. 85
Review Questionsp. 87
Remote Accessp. 91
IEEE 802.1xp. 92
Telnetp. 93
Virtual Private Networksp. 94
VPN Optionsp. 95
VPN Drawbacksp. 96
Remote Authentication Dial-In User Servicep. 96
Authenticating with a RADIUS Serverp. 97
Terminal Access Controller Access Control Systemp. 99
Point-to-Point Tunneling Protocolp. 101
Layer
2. Tunneling Protocol
p. 102
Secure Shellp. 102
IP Security Protocolp. 103
ESP and Encryption Modelsp. 105
Telecommuting Vulnerabilitiesp. 106
Remote Solutionsp. 110
Chapter Summaryp. 110
Key Termsp. 111
Review Questionsp. 112
E-mailp. 117
Secure E-mail and Encryptionp. 118
Encryptionp. 119
Hash Functionsp. 120
Digital Signaturesp. 120
Digital Certificatesp. 121
Combining Encryption Methodsp. 122
How Secure E-mail Worksp. 123
Background on PGPp. 126
PGP Certificatesp. 126
S/MIMEp. 127
Background on S/MIMEp. 127
S/MIME Encryption Algorithmsp. 127
X.509 Certificatesp. 128
S/MIME Trust Model: Certificate Authoritiesp. 129
Differences between PGP and S/MIMEp. 129
E-mail Vulnerabilitiesp. 131
Spamp. 132
E-mail Spamp. 132
Hoaxes and Chain Lettersp. 133
Countermeasures for Hoaxesp. 135
Chapter Summaryp. 136
Key Termsp. 136
Review Questionsp. 138
Web Securityp. 143
SSL and TLSp. 144
HTTPSp. 146
Instant Messagingp. 147
IM Security Issuesp. 147
Vulnerabilities of Web Toolsp. 149
JavaScriptp. 149
ActiveXp. 150
Buffer Overflowsp. 151
Cookiesp. 152
Signed Appletsp. 153
CGIp. 154
SMTP Relayp. 156
Chapter Summaryp. 158
Key Termsp. 159
Review Questionsp. 160
Directory and File Transfer Servicesp. 165
Directory Servicesp. 166
LDAPp. 166
LDAP Operationsp. 168
LDAP Frameworkp. 169
LDAP Security Benefitsp. 170
LDAP Security Vulnerabilitiesp. 171
File Transfer Servicesp. 172
FTPp. 172
FTP Security Issuesp. 175
Secure File Transfersp. 178
File Sharingp. 179
Protecting Your File Sharesp. 181
Chapter Summaryp. 181
Key Termsp. 182
Review Questionsp. 183
Wireless and Instant Messagingp. 187
The Alphabet Soup of 802.11p. 188
802.11ap. 188
802.11bp. 189
802.11cp. 189
802.11dp. 189
802.11ep. 190
802.11fp. 190
802.11gp. 190
802.11hp. 190
802.11ip. 190
802.11jp. 191
WAP 1.x and WAP 2.0p. 192
How WAP 1.x Worksp. 193
The WAP 2.0 Stackp. 196
The Wireless Transport Layer Security Protocolp. 198
Wired Equivalent Privacyp. 200
How WEP Worksp. 201
WEP's Weaknessesp. 201
Conducting a Wireless Site Surveyp. 203
Conducting a Needs Assessment of the Network Usersp. 203
Obtaining a Copy of the Site's Blueprintsp. 204
Doing a Walk-Through of the Sitep. 204
Identifying Possible Access Point Locationsp. 204
Verifying Access Point Locationsp. 205
Documenting Your Findingsp. 205
Instant Messagingp. 206
A Definition of IMp. 206
Lack of Default Encryption Enables Packet Sniffingp. 206
Social Engineering Overcomes Even Encryptionp. 207
Technical Issues Surrounding IMp. 207
Legal Issues Surrounding IMp. 207
Blocking IMp. 208
Cellular Phone SMSp. 208
Chapter Summaryp. 208
Key Termsp. 208
Review Questionsp. 211
Devicesp. 215
Firewallsp. 216
Drafting a Security Policyp. 216
Designing the Firewall to Implement the Policyp. 218
What do Firewalls Protect Against?p. 218
How Do Firewalls Work?p. 218
Routersp. 221
How a Router Moves Informationp. 221
Beyond the Firewallp. 222
The OSI Stackp. 225
Limitations of Packet-Filtering Routersp. 226
Switchesp. 226
Switch Securityp. 227
Wirelessp. 229
Modemsp. 229
DSL Versus Cable Modem Securityp. 230
Dynamic Versus Static IP Addressingp. 230
Remote Access Servicesp. 231
Security Problems with RASp. 231
Telecom/Private Branch Exchangep. 231
Virtual Private Networksp. 232
Intrusion Detection Systemsp. 234
Computer-based IDSp. 234
Network-based IDSp. 234
Anomaly-based Detectionp. 235
Signature-based Detectionp. 236
Network Monitoring and Diagnosticsp. 236
Workstations and Serversp. 236
Personal Firewall Software Packagesp. 237
Antivirus Software Packagesp. 237
Mobile Devicesp. 238
Chapter Summaryp. 238
Key Termsp. 239
Review Questionsp. 241
Media and Mediump. 245
Transmission Mediap. 246
Coaxial Cablep. 246
Twisted Pair Copper Cablep. 247
Fiber-Optic Cablep. 248
Unguided Transmissionp. 249
Securing Transmission Mediap. 250
Storage Mediap. 252
Magnetic Storage Mediap. 252
Optical Storage Mediap. 254
Solid-State Storage Mediap. 255
Catastrophic Lossp. 257
Encryptionp. 257
Storing and Destruction of Mediap. 257
Chapter Summaryp. 258
Key Termsp. 258
Review Questionsp. 259
Network Security Topologiesp. 263
Perimeter Security Topologiesp. 264
Three-tiered Architecturep. 264
Creating and Developing Your Security Designp. 267
DMZp. 269
Intranetp. 271
Extranetp. 272
Network Address Translationp. 273
Tunnelingp. 275
Virtual Local Area Networksp. 276
Security Features of VLANsp. 279
Vulnerabilities of VLAN Trunksp. 280
Chapter Summaryp. 281
Key Termsp. 282
Review Questionsp. 282
Intrusion Detectionp. 287
The Value of Intrusion Detectionp. 288
Negatives and Positivesp. 288
Network-based and Host-based IDSp. 290
Network-based IDSp. 291
Host-based IDSp. 296
Active Detection and Passive Detectionp. 300
Anomaly-based and Signature-based IDSp. 302
Intrusion Detection Productsp. 304
Honeypotsp. 305
Honeypot Deployment Optionsp. 307
Honeypot Designp. 307
Honeypots, Ethics, and the Lawp. 308
Incident Responsep. 308
IDS Monitoringp. 308
Information Security Incident Response Teamp. 309
Chapter Summaryp. 310
Key Termsp. 310
Review Questionsp. 312
Security Baselinesp. 315
OS/NOS Hardeningp. 316
File Systemp. 317
Creating Needed User Groupsp. 319
Configuring Access Controlsp. 319
Installing and Configuring File Encryption Capabilitiesp. 320
Updatesp. 320
Network Hardeningp. 321
Firmware Updatesp. 322
Configurationp. 322
Access Control Listsp. 324
Enabling and Disabling of Services and Protocolsp. 326
Application Hardeningp. 328
Web Serversp. 328
E-mail Serversp. 330
FTP Serversp. 332
DNS Serversp. 334
NNTP Serversp. 337
File and Print Serversp. 338
DHCP Serversp. 339
Data Repositoriesp. 341
Directory Servicesp. 341
Chapter Summaryp. 345
Key Termsp. 346
Review Questionsp. 349
Cryptographyp. 353
Algorithmsp. 354
Hashingp. 354
Symmetric versus Asymmetric Algorithmsp. 354
Symmetric Algorithmsp. 355
Asymmetric Algorithmsp. 356
Common Encryption Algorithmsp. 356
Concepts of Using Cryptographyp. 358
Digital Signaturesp. 359
Certificatesp. 360
PKI Certificatesp. 360
Trust Modelsp. 362
Key and Certificate Life Cycle Managementp. 363
Setup and Initializationp. 364
Certificate Expirationp. 366
Certificate Revocation and Suspensionp. 367
Key Historyp. 367
Key Archivep. 367
Chapter Summaryp. 368
Key Termsp. 369
Review Questionsp. 370
Physical Securityp. 373
Physical Controlsp. 374
Location and Environmentp. 374
Constructionp. 374
Physical Barriersp. 375
Physical Surveillancep. 378
Technical Controlsp. 379
Personnel Access Controlsp. 379
Technical Surveillancep. 382
Ventilationp. 382
Power Supplyp. 382
Fire Detection and Suppressionp. 383
Shieldingp. xxx
Natural Disastersp. 385
Chapter Summaryp. 385
Key Termsp. 385
Review Questionsp. 386
Disaster Recovery and Business Continuityp. 391
Business Continuityp. 392
Disaster Recovery Planning Processp. 392
Data Backupsp. 393
Disaster Recovery Planp. 395
Policies and Proceduresp. 397
Security Policyp. 397
Human Resources Policyp. 400
Incident Response Policyp. 402
Privilege Managementp. 404
Chapter Summaryp. 406
Key Termsp. 406
Review Questionsp. 406
Computer Forensics and Advanced Topicsp. 411
Computer Forensicsp. 412
Digital Evidencep. 412
Principles of Digital Evidencep. 412
The Forensic Processp. 413
Risk Managementp. 417
Asset Identificationp. 417
Risk Assessmentp. 417
Threat Identificationp. 418
Vulnerabilitiesp. 418
Education and Trainingp. 418
Communicationp. 418
User Awarenessp. 419
Auditingp. 419
Documentationp. 421
Standards and Guidelinesp. 421
Systems Architecturep. 421
Change Documentationp. 421
Logs and Inventoriesp. 422
Classification and Notificationp. 422
Retention and Storagep. 422
Destructionp. 423
Chapter Summaryp. 423
Key Termsp. 423
Review Questionsp. 424
Answers to Chapter Review Questionsp. 391
Glossaryp. 441
Indexp. 459
Table of Contents provided by Ingram. All Rights Reserved.

Edition: 2003
Publisher: Course Technology
Binding: Trade Paper
Pages: 496
Size: 7.25" wide x 8.75" long x 1.00" tall
Weight: 1.85 lbs.
Language: English

100% Money Back Guarantee: Wrong item? No problem! Our hassle-free returns policy has you covered. We'll also process your order within 24 hours. Learn more about our shipping policy.


About TextbooksRus.com

TextbooksRus.com is dedicated to providing customers with the lowest prices on textbooks, trade books and professional books. In addition to low prices, TextbooksRus.com offers a buyback system that is unparalleled by competitors.
© 2002-2010, TextbooksRus.com