 | |  |
| Computer Security | 
| Manufacturer: Wiley Category: EBooks
This item is no longer available
Avg. Customer Rating:   (13 reviews) Sales Rank: 29159
Format: Kindle Book Media: Kindle Edition Edition: 2 Number Of Items: 1 Pages: 386
Dewey Decimal Number: 005.8 ASIN: B000TYYSXM
Publication Date: January 18, 2006
|
| Similar Items:
|
| Editorial Reviews:
Product Description This is a brand new edition of the best-selling computer security book. Written for self-study and course use, this book will suit a variety of introductory and more advanced security programmes for students of computer science, engineering and related disciplines. Technical and project managers will also find that the broad coverage offers a great starting point for discovering underlying issues and provides a means of orientation in a world populated by a bewildering array of competing security systems. - Comprehensive reference covering fundamental principles of computer security
- Thinking about security within the initial design of a system is a theme that runs through the book
- A top-down approach.
- No active previous experience of security issues is necessary making this accessible to Software Developers and Managers whose responsibilities span any technical aspects of IT security
- Provides sections on Windows NT, CORBA and Java
|
| Customer Reviews: Read 8 more reviews...
  useless April 16, 2007 1 out of 2 found this review helpful
i used this book in a university course, i got very little out of it. it had handwavy explanations for almost every topic it discussed. when i tried to actually use the material, i found it useless because it skipped all the details. i had to spend hours on hours googling and wikiing to find information that the bok should have had.
  4th year BSA student's fourth security class text book (Bad) March 24, 2007 1 out of 2 found this review helpful
This is not an introductory book, or even a well though out or edited entry level graduate book. As I pointed out in the title of my review, I am a university student already familiar with security having had an introductory security course and two other technical security courses. I found this book to be overly complex and would not recommend it.
I am editing out most of my previous review. I misspoke and the author does make a case for users being a major threat to computer security. His book attempts to deepen the technical subject of security, unfortunately he does so by making it over complex, although in fairness I must say he does make roads into illuminating security being created at the kernal level. Otherwise I found little comparable value in it and having taken two additional graduate courses on security and can whole heartily endorse Charles and Shari Lawrence Pfleeger's Security in computing, for those with a little computer back ground this book will take you far.
Satya
  Excellent plain language overview... January 28, 2007 0 out of 1 found this review helpful
I am taking a Data and Network Security course at my University and they are using this book as the text. It is an excellent text and written very plainly in a clear and definitive manner. Consider it an excellent overview.
  Worst Textbook I've Ever Read February 24, 2005 8 out of 9 found this review helpful
Without doubt, this is the worst textbook I've ever had the misfortune to encounter. Even before the actual text starts, there's a discrepancy which bodes ill. Specifically, the back cover says:
"Written for SELF-STUDY and course use, this book will suit a variety of INTRODUCTORY and more advanced security programs for students of computer science, engineering and related disciplines."
However, the Preface states:
"This book grew out of my lecture notes for courses taught on a one-year POSTGRADUATE programme on information security."
The back cover is false and the Preface is much closer to what you can expect in the book: no person at a Computer Science/Computer Security introductory level will be able to get anything out of this book. The reader MUST already be fully knowledgeable about Unix, NT, Multics, and various computer security models and jargon. There's no way around that. If you don't meet those requirements, don't even think about picking up this book.
The biggest problem with the book is that it's written from the viewpoint of someone talking to a group of people who are already familiar with the subject: the author is merely pointing out things that those already-knowledgeable people should know. Instead of writing to teach people the topic, the author just synthesizes his own knowledge to focus on the subject. Also, he uses words not to explain and enlighten, but to confuse and obfuscate. For instance, his standard writing behavior is to use obscure technical terms well before he defines them. Plus, in general, as the book progresses, the exercises at the end of each chapter have less and less to do with anything discussed in the book and require such a level of expertise in huge swaths of areas that no one could possibly do them. Some specifics:
- The first five chapters are devoted to some of the theoretical underpinnings of the theory of computer security. Unfortunately, the author doesn't really explain these models. Instead, he assumes intimate knowledge of the models and talks about certain aspects of them. What's really jarring is that after solely talking about motherhood and apple pie (security wise) in nice, warm, fuzzy terms, he suddenly drops in "equations" from these models without explaining any of the terms or nomenclature (he follows this procedure throughout the book). Usually, after several pages you can find the definitions for what he's just said. But, unless you're familiar with what he's doing, none of this will make sense.
- For icing, in these first five chapters, the author uses virtually NO examples (which, for the most part, continues throughout the book). He'll mention Multics and some consultant data base as sources, but he never gives concrete examples of what he's "explaining." Even worse, with no examples in the text, the author asks the reader to provide examples of what he's talking about in the exercises. In general, the exercises assume far more knowledge than the author has provided in the text.
- In chapter 6, "Unix Security," he moves into "examples" of where these models are used. Similarly to earlier chapters, he writes as though his readers are intimately familiar with the subject (Unix, in this case) and that he's merely pointing out some interesting things. The chapter is filled with Unix commands with no structure to his delivery or explanation of where those commands come from. Plus, when you get to the exercises at the end of the chapter, they're mostly of the type that require you to SIGN ON TO YOUR UNIX SYSTEM AND DO THINGS! There's nothing in the preface of this book stating the requirement for being on (and intimately familiar with) a Unix system. Yet, there you are, unable to understand the chapter, and unable to do the exercises.
- Chapter 7, "Windows NT Security," is almost as bad. For someone with no familiarity with the inner workings of NT, most of the chapter will be meaningless. It's not quite as bad as Chapter 6 since NT uses a GUI for what he discusses and Unix uses the command line, but it's still frustrating. Unlike Chapter 6 and Unix, the exercises don't assume access to an NT machine, although most of them can't be done with only the information presented in the chapter.
- Chapter 8, "How Things Go Wrong," is actually somewhat interesting. It suffers from the same assumption that the reader is intimately familiar with the technical jargon of various systems and protocols. But, it actually involves examples. Of course, the exercises at the end of the chapter are undoable since they don't relate to anything taught in the chapter and are at a highly technically adept level.
I'm running out of space, so I won't write about the remaining seven chapters except to say that they suffer from the same things related above. I'd also like to include some advice to Florida State University (FSU): this book is the text for an elective (CIS 4360: "Introduction to Computer Security") in their Computer Science degree. According to the course write-up, its sole prerequisite is CGS 3408, which is a C programming course. FSU seriously needs to re-examine their use of this book. There's no chance that undergraduate students with only a C programming course under their belts (and C is used nowhere in the book) will get anything out of this book other than hemorrhoids. Find another book.
I rate this book 1 star out of 5. Avoid.
  Simply unreadable December 19, 2004 2 out of 3 found this review helpful
I can't believe that the original price of this book is $60! I got this book for $24 when amazon had a 70% discount on it. And I still regret paying that much for this book. Even if the discount on this book was 90%, it still won't be worth it! The explanations in this book are very complicated. (I probably shouldn't call them "explanations" - "complications" would make alot more sense!) You would read the paragraph over and over again to just get a hint on what Mr. Gollmann wants to say. If Mr. Gollmann's intention was to sound vague and ambiguous as much as possible, he succeeded! The book doesn't draw clear boundaries between the different terms - for example, you won't get a clear idea about the relation and interaction between "security policy", "security mechanism", "security system", "security model", "reference model", "access operations", "access permissions", ... etc. It's as if Mr. Gollmann's objective was actually to confuse the reader rather than guide the reader towards clear understanding. Many ideas could have been presented in a much simpler way, but the author chose otherwise! Plus the book doesn't include enough examples to clear the fog. Mr. Gollman just slams the reader with dry unreadable material. At the end of day, you are left confused, having many unanswered questions, feeling that you got very little out of the much you've read, and wishing you never bought this book!
|
|
| Powered by: Dknc, inc. and Amazon.com |  | 
For your safety and security, orders are processed through amazon.com
|
|
 |
|