Security Patterns - Integrating Security and Systems Engineering
-
Author:
-
Subject:
-
Published by:John Wiley & Sons (UK)
-
Published:21/12/2005
-
Price:$94.99
- < Buy this book >
- Essential for designers building large-scale systems who want best practice solutions to typical security problems
- Real world case studies illustrate how to use the patterns in specific domains
For more information visit www.securitypatterns.org
Biography
- Markus Schumacher, SAP AG, Germany,
- Eduardo Fernandez-Buglioni, Florida Atlantic University, USA,
- Duane Hybertson, The MITRE Corp, USA,
- Frank Buschmann, Siemens AG, Germany,
- Peter Sommerlad, Hochschule für Technik Rapperswil, Germany
Table of Contents
Patterns at a Glance.
No Pattern is an Island.
Patterns Everywhere.
Humans are the Target.
Patterns Resolve Problems and Shape Environments.
Towards Pattern Languages.
Documenting Patterns.
A Brief Note on The History of Patterns.
The Pattern Community and its Culture.
Chapter 2: Security Foundations.
Overview.
Security Taxonomy.
General Security Resources.
Chapter 3: Security Patterns.
The History of Security Patterns.
Characteristics of Security Patterns.
Why Security Patterns?
Sources for Security Pattern Mining.
Chapter 4: Patterns Scope and Enterprise Security.
The Scope of Patterns in the Book.
Organization Factors.
Resulting Organization.
Mapping to the Taxonomy.
Organization in the Context of an Enterprise Framework.
Chapter 5: The Security Pattern Landscape.
Enterprise Security and Risk Management Patterns.
Identification & Authentication (I&A) Patterns.
Access Control Model Patterns.
System Access Control Architecture Patterns.
Operating System Access Control Patterns.
Accounting Patterns.
Firewall Architecture Patterns.
Secure Internet Applications Patterns.
Cryptographic Key Management Patterns.
Related Security Pattern Repositories Patterns.
Chapter 6: Enterprise Security and Risk Management.
Security Needs Identification for Enterprise Assets.
Asset Valuation.
Threat Assessment.
Vulnerability Assessment.
Risk Determination.
Enterprise Security Approaches.
Enterprise Security Services.
Enterprise Partner Communication.
Chapter 7: Identification and Authentication (I&A).
I&A Requirements.
Automated I&A Design Alternatives.
Password Design and Use.
Biometrics Design Alternatives.
Chapter 8: Access Control Models.
Authorization.
Role-Based Access Control.
Multilevel Security.
Reference Monitor.
Role Rights Definition.
Chapter 9: System Access Control Architecture.
Access Control Requirements.
Single Access Point.
Check Point.
Security Session.
Full Access with Errors.
Limited Access.
Chapter 10: Operating System Access Control.
Authenticator.
Controlled Process Creator.
Controlled Object Factory.
Controlled Object Monitor.
Controlled Virtual Address Space.
Execution Domain.
Controlled Execution Environment.
File Authorization.
Chapter 11: Accounting.
Security Accounting Requirements.
Audit Requirements.
Audit Trails and Logging Requirements.
Intrusion Detection Requirements.
Non-Repudiation Requirements.
Chapter 12: Firewall Architectures.
Packet Filter Firewall.
Proxy-Based Firewall.
Stateful Firewall.
Chapter 13: Secure Internet Applications.
Information Obscurity.
Secure Channels.
Known Partners.
Demilitarized Zone.
Protection Reverse Proxy.
Integration Reverse Proxy.
Front Door.
Chapter 14: Case Study: IP Telephony.
IP Telephony at a Glance.
The Fundamentals of IP Telephony.
Vulnerabilities of IP Telephony Components.
IP Telephony Use Cases.
Securing IP telephony with patterns.
Applying Individual Security Patterns.
Conclusion.
Chapter 15: Supplementary Concepts.
Security Principles and Security Patterns.
Enhancing Security Patterns with Misuse Cases.
Chapter 16: Closing Remarks.
References.
Index.
Data Center Physical Infrastructure: Optimising Business Value
To stay competitive in today’s rapidly changing business world, companies must update the way they view the value of their investment in data center physical infrastructure (DCPI). No longer are simply availability and upfront cost sufficient to make adequate business decisions. Agility, or business flexibility, and low total cost of ownership have become equally important to companies that will succeed in a changing global marketplace.
SoftDisc
SoftDisc is an image file tool that allows you to create, edit and manage your image files. It also lets you emulate a virtual CD ...
Process-Driven Master Data Management for Dummies
We wrote this book to introduce you to the subject of processdriven MDM. It’s a big topic, one that far outstrips the ability of a brief book to cover. However, our hope is that by reading this book you will gain a fundamental understanding of processdriven MDM, how it works, and what it takes to make it a success in your organisation.
- CCAvaya Engineer - ERS 8600 4.1NSW
- CCSAP PM ConsultantNSW
- FTQM Trainer and ConsultantNSW
- FTProduct Manager Strategist - Enterprise ApplicationsNSW
- FTSenior Network Engineer - Cisco / Nexus / UCS / - Routing / Switching / WirelessNSW
- CCOBIEE ConsultantWA
- FTSenior Citrix EngineerNSW
- FTSAP Basis ConsultantACT
- FTTechnical Services Engineer - ShoreTel/MitelVIC
- FTSenior Citrix EngineerNSW
- FTSenior Network Field Engineer - Cisco R&S / Wireless SolutionsNSW
- CCSystem Engineer - Exchange - CONTRACTSWA
- FTIT Account Manager - System Integrator - Career Progression - Start ImmediatelyNSW
- CCSystem Engineer - Lync and Exchange - CONTRACTSWA
- FTChange Management ProfessionalsNSW
- FTSenior Network Field Engineer - Cisco R&S / Wireless SolutionsNSW
- CCSAP FICO ConsultantNT
- FTSAP Basis ConsultantNSW
- CCPC Relocation Technicians - Multiple Roles availableSA
- FTIT Service Desk EngineerNSW
- FTiPhone App DeveloperNSW
- FTIT Service Desk EngineerNSW
- FTiPhone App DeveloperNSW
- FTiPhone App DeveloperNSW
- FTiPhone Developer DeveloperNSW








