Gigantically comprehensive and carefully researched, Security Engineering makes it clear just how difficult it is to protect information systems from corruption, eavesdropping, unauthorized use, and general malice. Better, Ross Anderson offers a lot of thoughts on how information can be made more secure (though probably not absolutely secure, at least not forever) with the help of both technologies and management strategies. His work makes fascinating reading and will no doubt inspire considerable doubt--fear is probably a better choice of words--in anyone with information to gather, protect, or make decisions about.

Be aware: This is absolutely not a book solely about computers, with yet another explanation of Alice and Bob and how they exchange public keys in order to exchange messages in secret. Anderson explores, for example, the ingenious ways in which European truck drivers defeat their vehicles' speed-logging equipment. In another section, he shows how the end of the cold war brought on a decline in defenses against radio-frequency monitoring (radio frequencies can be used to determine, at a distance, what's going on in systems--bank teller machines, say), and how similar technology can be used to reverse-engineer the calculations that go on inside smart cards. In almost 600 pages of riveting detail, Anderson warns us not to be seduced by the latest defensive technologies, never to underestimate human ingenuity, and always use common sense in defending valuables. A terrific read for security professionals and general readers alike. --David Wall

Topics covered: How some people go about protecting valuable things (particularly, but not exclusively, information) and how other people go about getting it anyway. Mostly, this takes the form of essays (about, for example, how the U.S. Air Force keeps its nukes out of the wrong hands) and stories (one of which tells of an art thief who defeated the latest technology by hiding in a closet). Sections deal with technologies, policies, psychology, and legal matters.      

Share
Related Documents
  1. [Free] Watcher : testing tool and passive vulnerability scanner (1710)
  2. [Free] skipfish : web application security reconnaissance tool. (1824)
  3. Software Security Assurance (1731)
  4. [Ebook] Internet Security: A Jumpstart for Systems Administrators and IT Managers (2914)
  5. [PodCast] Security Testing (104M) (761)
  6. [Ebook] Practical Unix & Internet Security, 3rd Edition (3063)
  7. [Paid] Web Site Security Audit - WSSA : Website and Web Server Security Auditing (1421)
  8. [Ebook] Exploiting Software How to Break Code (2690)
  9. Security Focus : Newsletter Archive (1340)
  10. [Free] SiteDigger : vulnerabilities, errors, configuration issues, proprietary information, and interesting security testing tool (4281)
  11. What is a Security stress testing? (1213)
  12. [Video] seNetsparker - A free web app security testing tool (681)
  13. Security Testing for Web Application (1840)
  14. Secure Software Advisory for security testing (828)
  15. [Webinar] Are You Ready for DO-178C and Emerging Security-Critical Standards? (1007)
  16. Creating a Web security testing policy (1638)
  17. Building web application security into your development process (1371)
  18. Security Strategies Alert (764)
  19. Web Security Testing Blog (984)
  20. [Ebook] Practical Applications for Security Testing (4135)