Information Security Magazine, February 2004
The breadth and quality of its information coverage should earn this book a place on your shelf.
Product Description
Teaches end-to-end network security concepts and techniques. Includes comprehensive information on how to design a comprehensive security defense model. Plus, discloses how to develop and deploy computer, personnel, and physical security policies, how to design and manage authentication and authorization methods, and much more.
Book Info
Reference provides the information necessary to plan, implement, and maintain a secure network. Shows how to protect confidential information such as customer lists, credit card numbers, stockholder names, and addresses. Includes a security dictionary and contributions from topical experts.
From the Back Cover
The Most Authoritative Volume Available on Network Security
Includes a Security Dictionary and contributions from topical experts!
The solution to today's computer system security ills will only be solved when organizations obtain and implement a network security program. This comprehensive resource provides all the information necessary to formulate strategies to reach that goal. Learn to plan, implement, and maintain a secure network, and protect confidential information such as customer lists, credit card numbers, and stockholder names, and addresses. Prevent the attack or theft of specialized information such as trade secrets, formulas, production details, and other intellectual property. Network Security: The Complete Reference provides critical strategies, concepts, techniques, and solutions to keep your network system secure.
Learn what it takes to build a solid security architecture
Manage and control all access points to your digital data
Anticipate incidents using risk analysis, threat definition, and vulnerability assessment
Secure confidentiality, integrity, privacy, and availability
Understand how HIPAA, Gramm-Leach-Bliley and other security legislation affects you
Learn about a California law that requires compliance from all organizations, no matter what state they reside in
Technical Experts:
Dr. Nick Efford & Steve Wright, Windows .NET Security
Ken Pfeil, Physical Security
Ben Rothke, Operating System Security
Roger A. Grimes, Intrusion Detection
Anil Desai & Rob Kraft, Database Security
Ole Drews Jensen, Router & Device Security
Dr. Andrew A. Vladimirov & Stephen Prendergast, Wireless Security
Michael Howard, Secure Software
Thaddeus Fortenberry & Eric Maiwald, VPN Security
Michael O'Dea, Windows Security
Brian Buege, Michael Judd & Jim Keogh, J2EE Security
Bernard Chapple, Disaster Recovery
Glen Carty & Steve Thomas, Novell Security
Christian Genetski & Curtis Karnow, Legal Issues
Curtis W. Rose, Incident Response & Computer Forensics
Thomas Knox & Robert Clugston, Linux/UNIX Security
Barak Weicheselbaum, Application Security
About the Author
Roberta Bragg (CISSP, MCSE: Security; Security+, ETI Client Server, Certified Technical Trainer, IBM Certified Trainer, DB2-UDB, Citrix Certified Administrator) has been a Security Advisor columnist for Microsoft Certified Professional Magazine for five years, is a Security Expert for SearchWin2000.com, and writes for the “SecurityWatch” newsletter, which has more than 55,000 subscribers. Roberta designed, planned, produced, and participated in the first Windows Security Summit, held in Seattle, Washington, in 2002. In September and October of 2002, Roberta was an instructor for four sessions of SANS Gold Standard Windows 2000 Training. Roberta has participated in numerous security audits and is a security evangelist traveling all over the world consulting, assessing, and training on network and Windows security. Roberta has served as adjunct faculty at Seattle Pacific University and at Johnson County Community College teaching courses on Windows 2000 Security Design and Network Security Design. Mark Rhodes-Ousley (CISSP) has been a practicing security professional for more than ten years. Mark has advised, designed, and installed security technologies and policies for dozens of companies, including Fortune 500 companies, large, medium-sized, and many small companies. All this experience with companies in different stages of growth leads to a unique perspective on how to manage security for a growing company—where to begin, what to do when moving forward, and how to plan for future growth. Mark holds certifications from the International Information Systems Security Certification Consortium, known as (ISC)2, Cisco Systems, Security Dynamics, Raptor Systems, Hewlett Packard, and Digital Equipment Corporation, along with a Bachelor degree in Applied Mathematics and Electrical Engineering from the University of California, San Diego (UCSD). Keith Strassberg (CPA, CISSP) is an independent security consultant with more than seven years of experience in information security. Most recently, he worked as a senior security engineer for a mid-sized technology consulting company. Keith’s professional experiences cover all facets of information security, including, but not limited to, designing and deploying secure infrastructures, implementing firewalls and intrusion detection systems, performing computer forensic investigations, developing policies and procedures, and performing vulnerability testing.
Product Details
Paperback: 896 pages
Publisher: McGraw-Hill Osborne Media; 1 edition (November 17, 2003)
Language: English
ISBN-10: 0072226978
ISBN-13: 978-0072226973
Product Dimensions: 9 x 7.4 x 2 inches
Shipping Weight: 3.3 pounds (View shipping rates and policies)
Friday, June 27, 2008
Network Security: The Complete Reference
Monday, May 5, 2008
Tips for Network Security
Network in nowadays give us possibilities communicate and do more other things possible and much faster. But not everything is so nice how we thing in first moment. There are a lot of threats which grow up every day in networking!
Here are 10 information security awareness tips for network security, which helps to do network and communication via this network safer, and also give to you confidence that everything is O.K.
1.Use strong password.
Passwords are the simplest form of security. By leaving passwords blank or simple (i.e., password or admin), unauthorized users are practically invited to view sensitive data. Passwords are more secure when they contain letters,numbers and special characters in a combination of upper-case and lower-case characters, and they should be changed periodically.
2.Educate users.
Users need to know exactly what kinds of threats they can expect using e-mail, making faceless downloads and open unknown attachments. Uneducated computer users are often those who fall victim to viruses, spyware, and phishing attacks, all of which are designed to corrupt systems or leak personal information to a third party without the user's consent. The best way hot to make this education is to do special information security awareness training which provides some companies, for example, InfoSecurityLab.
3.Make backup copies.
Indulence is one of the biggest security threats. It's considerably more difficult to completely re-create a crippled system than it is to take the time to create proper backups. Create backups often, and do not immediately overwrite them with the next set of backups. In addition, make copies and keep them off-site in case of emergency.
4.Use protection software.
Without protection software information is like a hedgehog on the motorway-everyone can get this information and "smash" it! Ideally, network protection software should include virus protection, multiple spyware scanners, and a program that runs in the background to prevent malicious software from ever being installed.
5.Do regullary updates
Every day there are created new computer viruses and malicious softwares, so, what good are all those virus and spyware scanners if they're not updated? It\'s crucial to update what are called the "virus/spyware definitions" every week. This keeps the scanners up-to-date to detect the latest malicious software.
6.Install security patches
Security holes may exist in every operating system. There is no software which is perfect. Once an imperfection or hole is found, it's usually exploited within a very short period of time. Therefore, it is imperative to install security patches as soon as possible because otherwise you let these holes open for worms, trojan horses and other viruses.
7.Don't be creduloud
Ads on the Internet have become devious and deceptive. They now appear as "urgent system messages" and warnings designed to scare users into clicking. As a rule of thumb, if a popup window contains an ad claiming to end popups, chances are it's a scam of some sort.
8.Use encryption
Encryption is a way of coding the information in a file or e-mail message so that if it is intercepted by a third party as it travels over a network it cannot be read. Encryption is especially important when dealing with banking and credit cards. Storing and transferring unencrypted data is the equivalent of posting that data for everyone to see. If you\'re not comfortable implementing encryption technology, ask IT specialist assist you.
9.Trust proffesional service
Don't try to do all yourself, you can't be professional in every area. Setting up a network, applying proper security measures, and downloading and installing software can be tricky. Large companies have IT departments. Small business owners should also ask for advice or even hire help.
10.Proper instruction.
Security measures are most effective if everyone is aware of how the system operates. Better are inform all employies how security system work and what to do if something goes wrong! These tips is not so difficult make in life, but they can really increase your network and information security. Do networking safe or not - it's up to you!
The Basics of Network Security
A network is two or more computers linked together in order to share data. From a security standpoint, the problem with networks is that unauthorized individuals might also be able to access that data. Network security is a term that encompasses your overall system for keeping your network as impenetrable as possible, be it hardware, software, or company policies.
Whether your network consists of two computers or two hundred computers, there are certain basic security measures you should have in place. Most of these measures aren’t complicated or expensive, and they don’t require any particular expertise in networking or computer security.
One of the most basic steps for securing your network is to have anti-virus software in place. Anti-virus software periodically sweeps your computer looking for known viruses. You can also choose to run a anti-virus test at any time. Once run, the software generates a report that lists the viruses detected. You are then able to select which, if any, of the viruses detected you want quarantined and removed. It’s more important that you keep your software up to date because new viruses are created and released every day.
Next, make sure you have a firewall in place. A firewall is like a gatekeeper. It’s a hardware/software combination that allows you to decide what goes in and out of your network. You determine the “trust level” to which your firewall is set. The trust level dictates which network connections will be automatically allowed and which will require specific permission. Firewalls come with a “default” setting which is unlikely to be stringent enough to meet your security needs. For optimum security, you should always manually set the trust settings to a higher degree of scrutiny.
Firewalls and anti-virus software are essential for another very important reason: they help protect your system from adware and spyware. Adware and spyware range from annoying to very dangerous. Adware slows down your system, and generates irritating pop-up ads that interfere with your work. Spyware is much more serious. It tracks your computer usage habits, and basically opens up a door to your network that allows hackers to penetrate your system without your knowing it.
Another simple measure is to regularly download patches for your software. Computer programs are tested for vulnerabilities and possible exploits before they are distributed to the public. However, it’s impossible to detect every single vulnerability in advance. As new exploits are discovered, companies “patch” their programs and software to prevent the exploitation of that vulnerability. Without these patches, the software and programs on your computer remain vulnerable.
Network security also depends on common sense. Weak passwords can cause big problems, but are easily avoided. Never use easy-to-guess passwords like your last name, phone number, or birth date. Always use a combination of letters and numbers. Your best bet is to avoid real words altogether and use a string of numbers and letters that stand for a saying or phrase you can easily remember.
Another common sense security measure is to delete suspicious-looking email. More importantly, never open or download an attachment from an email address you don’t recognize. Doing so could be inviting a virus right into your computer. When in doubt, follow this simple rule: delete without opening.
If your business, you should also put in place security policies to govern the behavior of authorized users. Even authorized users can pose a serious security risk, sometimes without realizing it. For instance, “I love to dance, I love to sing” could be “1L2D1L2S,” with the number 1 replacing the letter I.
Here are a few elements of a solid network security policy:
• Require your employees to change their passwords every 3 months.
• Do not allow employees to post their passwords on their desk or cubicle
• Immediately terminate a departing employee’s access to your network.
• Operate on the computer network equivalent to the “need to know” basis. Only allow an employee access to the programs and data that are essential to his or her job.
• Put all of your security guidelines down in writing, and post them where all of your employees can see them.
You want your network security policy to be tight, but not completely rigid. That is, if a given security measure is proving to be unworkable or a serious inconvenience, be willing to adjust. You can often achieve the same result through different means.
Last, but certainly not least, review your network security on a regular basis. A network that’s secure today may not be secure a few months down the road. Hackers are smart and are constantly developing ways to bypass security measures. Be smarter than the hackers by staying on the cutting edge of network security technology.