Search
 Advanced SearchView Cart   Checkout   
 Location:  Home » Books » Web Security Field GuideJanuary 9, 2009  
Bestsellers
Computer Organization and Design, Fourth Edition, Fourth Edition: The Hardware/Software Interface (The Morgan Kaufmann Series in Computer Architecture and Design)
Computer Networking: A Top-Down Approach (4th Edition)
The iPhone Developer's Cookbook: Building Applications with the iPhone SDK (Developer's Library)
CISSP Certification All-in-One Exam Guide, 4th Ed.
Network+ Guide to Networks, Fourth Edition (Networking)
A Beginner's Guide to Day Trading Online (2nd edition)
CCNA Official Exam Certification Library (CCNA Exam 640-802) (Exam Certification Guide)
CCNA: Cisco Certified Network Associate Study Guide: Exam 640-802
JavaScript: The Definitive Guide
MCITP Self-Paced Training Kit (Exams 70-640, 70-642, 70-643, 70-647): Windows Server 2008 Enterprise Administrator Core Requirements
Browse
Books
Computers
Electronics
New Releases
Computer Organization and Design, Fourth Edition, Fourth Edition: The Hardware/Software Interface (The Morgan Kaufmann Series in Computer Architecture and Design)
The iPhone Developer's Cookbook: Building Applications with the iPhone SDK (Developer's Library)
Social Media Marketing: An Hour a Day
The iPhone Book: How to Do the Most Important, Useful & Fun Stuff with Your iPhone, 2nd Edition
Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning
Professional Android Application Development (Wrox Programmer to Programmer)
iPhone in Action: Introduction to Web and SDK Development
Security+ Guide to Network Security Fundamentals
iPhone Developer's Cookbook, The
CCNA Voice Official Exam Certification Guide (640-460 IIUC)
Web Security Field Guide
Web Security Field Guide
Author: Steve Kalman
Publisher: Cisco Press
Category: Book

List Price: $50.00
Buy New: $6.49
You Save: $43.51 (87%)
Buy New/Used from $0.99

Avg. Customer Rating: 5.0 out of 5 stars(1 reviews)
Sales Rank: 1970813

Media: Paperback
Edition: 1st
Number Of Items: 1
Pages: 608
Shipping Weight (lbs): 2.2
Dimensions (in): 9.1 x 7.3 x 1.3

ISBN: 1587050927
Dewey Decimal Number: 005.8
UPC: 619472050927
EAN: 9781587050923
ASIN: 1587050927

Publication Date: November 8, 2002
Availability: Usually ships in 1-2 business days

Editorial Reviews:

Product Description

Hands-on techniques for securing Windows(r) servers, browsers, and network communications

  • Create effective security policies and establish rules for operating in and maintaining a security- conscious environment
  • Learn how to harden Windows multi-user platforms, including NT, 2000, and XP
  • Understand secure installation options for Windows web servers and how to enhance security on existing web and FTP server installations
  • Improve security at the end user's workstation, including web browsers, desktops, and laptops
  • Evaluate the pros and cons of installing a certificate server and becoming your own Certification Authority
  • Learn the Cisco PIX Firewall and Cisco IOS Firewall architecture and how to apply Cisco standard and extended access lists
  • Discover ways to test the current state of security and keep it up to date
  • Learn to engage end users as part of the overall network security solution

While the Internet has transformed and improved the way we do business, this vast network and its associated technologies have opened the door to an increasing number of security threats. The challenge for successful, public web sites is to encourage access to the site while eliminating undesirable or malicious traffic and to provide sufficient levels of security without constraining performance or scalability. The more reliant organizations become on the Internet to perform daily jobs or conduct transactions, the greater the impact a breach of network security has. Just as Cisco Systems has been an innovator in using the Internet to conduct business, so too is it a market leader in the development and sale of products and technologies that protect data traveling across the Internet. Yet a network security solution is only as strong as its weakest link. Network attacks can occur at any point, including the network connection, the firewall, the web server, or the client. Hardening the defenses at all these points is key to creating an effective, all-encompassing network security solution.

Web Security Field Guide provides you with hands-on, proven solutions to help patch the most common vulnerabilities of Windows(r) web servers and browsers within the context of an end-to-end network security architecture. Avoiding conceptual discussions of underlying technologies, the book spends little time discussing how each application works. Using plain language and lots of step-by-step examples, the book instead focuses on helping you secure your web servers and prevent the majority of network attacks. Divided into five parts, the book opens with an overview of essential background information and helps you establish working network security rules and policies. Parts II through IV teach you the techniques for hardening the operating system, the web server, and the browser. Part V of the book addresses overall network security, focusing on preventing and controlling access. Topics such as becoming a Certification Authority, Cisco PIX(r) Firewall, Cisco IOS(r) Firewall, access lists, ongoing security maintenance, and testing are all examined in-depth, providing an overall network security plan that can drastically reduce the risk to your business systems and data.

Full of diagrams, screen captures, and step-by-step instructions for performing simple tasks that can radically improve the security of your Internet business solutions, Web Security Field Guide is a practical tool that can help ensure the integrity and security of your business-critical applications.




Customer Reviews:

5 out of 5 stars Great Practical book with Tried and True Advice   November 26, 2002
  6 out of 7 found this review helpful

To really understand Web security, you need to know how TCP/IP networks function, thoroughly understand the concept of network layering, and then fully grasp or as Heinlein would say "groc" the important details such as port numbers, etc., found in the IP and TCP headers.

Kalman shows his understanding of these areas by starting off with a concise discussion of these valuable items. This form the basis for the later Chapters.

To achieve computer security, you need a security policy. Kalman moves to this indespensible area next, covering the basics of this easy to understand, but difficult to implement, concept.

Achieving Web Security means securing your WEB browsers, hardening your operating systems on your Web Servers, hardening your WEB servers, securing the dataflow between browser and server, and finally, taking care of the entire Web environment.

Most writers seem to think that Web security is only about items such as hardening a WEB server, using something like the Microsoft LockDown tool for IIS. This book goes much farther; it follows the tried and true perscription noted above to generated a more secure Web environment.

First off, for the Microsoft sites, a good discussion of the IEAK took for the Internet Explorer is found. Using this tool, you can completely customize your IE Web Browser. This will eliminate a number of hacks that many have faced in recent years. Very few books discuss IEAK.

Of course, the issues involved in securing or hardening a web server are presented in good detail. Following that is a good
presentation of the fundamentals of securing Microsoft servers, using the Microsoft Security Configuration toolkit follows. Many who use Microsoft do not use this valuable toolset. Kalman has done a good job explaining this valuable toolset so that a wider audience can benefit from using its many features.

It also handles the tricky matters with the Certificate Server scenarios as well.

I also like the coverage of Cisco ACL's and the PIX firewall. Most whom I have met have experienced great difficulty in setting up properly functioning ACLs for their Cisco border routers. And of course, properly setting up a PIX is as, if not more challenging than setting up router security. Kalman shows his breadth in the field by including these seldomly included topics in his Field Guide.

After all this, Kalman pursues the day to day management issues that must be dealt with by those responsible for securing their environments.

Every chapter has excellent material. It is not a book filled with fluff, but rather an excellent compendium of time proven techniques to provide better security.

Securing a web environment is a challenging, time-consuming task, that must be done day after day. Kalman has written the exact kind of "Field Guide" to help novices and even experienced security personnel in many ways.

If you are looking for a great guide that is both thorough and easy to read with many graphics, this book is for you.

I think so much of this book that I own a copy of it.

Powered by: Dknc, inc. and Amazon.com


For your safety and security, orders are processed through amazon.com