Bücher versandkostenfrei*100 Tage RückgaberechtAbholung in der Wunschfiliale
15% Rabatt11 auf ausgewählte eReader & tolino Zubehör mit dem Code TOLINO15
Jetzt entdecken
mehr erfahren
Produktbild: System Assurance | Nikolai Mansourov, Djenana Campara
Produktbild: System Assurance | Nikolai Mansourov, Djenana Campara

System Assurance

Beyond Detecting Vulnerabilities

(0 Bewertungen)15
655 Lesepunkte
Buch (kartoniert)
Buch (kartoniert)
65,49 €inkl. Mwst.
Zustellung: Sa, 30.08. - Di, 02.09.
Versand in 4 Tagen
Versandkostenfrei
Empfehlen

System Assurance teaches students how to use Object Management Group's (OMG) expertise and unique standards to obtain accurate knowledge about existing software and compose objective metrics for system assurance.

OMG's Assurance Ecosystem provides a common framework for discovering, integrating, analyzing, and distributing facts about existing enterprise software. Its foundation is the standard protocol for exchanging system facts, defined as the OMG Knowledge Discovery Metamodel (KDM). In addition, the Semantics of Business Vocabularies and Business Rules (SBVR) defines a standard protocol for exchanging security policy rules and assurance patterns. Using these standards together, students will learn how to leverage the knowledge of the cybersecurity community and bring automation to protect systems.

This book includes an overview of OMG Software Assurance Ecosystem protocols that integrate risk, architecture, and code analysis guided by the assurance argument. A case study illustrates the steps of the System Assurance Methodology using automated tools.

This book is recommended for technologists from a broad range of software companies and related industries; security analysts, computer systems analysts, computer software engineers-systems software, computer software engineers- applications, computer and information systems managers, network systems and data communication analysts.

Inhaltsverzeichnis

Contents

1. Why Hackers know more about our systems

1. 1 Operating in cyberspace involves risks

1. 2 Why Hackers are repeatadly successful

1. 2. 1 What are the challenges in defending cybersystems?

1. 2. 1. 1 Difficulties in understanding and assessing risks

1. 2. 1. 2 Understanding Development Trends

1. 2. 1. 3 Comprehending Systems' Complexity

1. 2. 1. 4 Understanding Assessment Practices and their Limitations

1. 2. 1. 5 Vulnerability Scanning Technologies and their Issues

1. 3 Where do We Go from Here

1. 3. 1 Systematic and repeatable defense at affordable cost

1. 3. 2 The OMG Software Assurance Ecosystem

1. 3. 3 Linguistic Modeling to manage the common vocabulary

1. 4 Who should read this book

2 Chapter: Confidence as a Product

2. 1 Are you confident that there is no black cat in the dark room?

2. 2 The Nature of Assurance

2. 2. 1 Engineering, Risk and Assurance

2. 2. 2 Assurance Case (AC)

2. 2. 2. 1 Contents of an Assurance Case

2. 2. 2. 2 Structure of the Assurance Argument

2. 3 Overview of the Assurance Process

2. 3. 1 Producing Confidence

2. 3. 1. 1 Economics of Confidence

3 Chapter: How to Build Confidence

3. 1 Assurance in the System Lifecycle

3. 2 Activities of System Assurance Process

3. 2. 1 Project Definition

3. 2. 2 Project Preparation

3. 2. 3 Assurance argument development

3. 2. 4 Architecture Security Analysis

3. 2. 4. 1 Discover System Facts

3. 2. 4. 2 Threat identification

3. 2. 4. 3 Safeguard Identification

3. 2. 4. 4 Vulnerability detection

3. 2. 4. 5 Security Posture Analysis

3. 2. 5 Evidence analysis

3. 2. 6 Assurance Case Delivery

4 Chapter: Knowledge of System as of Element in Cybersecurity argument

4. 1 What is system

4. 2 Boundaries of the system

4. 3 Resolution of the system description

4. 4 Conceptual commitment for system descriptions

4. 5 System architecture

4. 6 Example of an architecture framework

4. 7 Elements of System

4. 8 System Knowledge Involves Multiple Viewpoints

4. 9 Concept of operations (CONOP)

4. 10 Network Configuration

4. 11 System life cycle and assurance

4. 11. 1 System life cycle stages

4. 11. 2 Enabling Systems

4. 11. 3 Supply Chain

4. 11. 4 System life cycle processes

4. 11. 5 The implications to the common vocabulary and the integrated system model

5 Chapter: Knowledge of Risk as an Element of Cybersecurity argument

5. 1 Introduction

5. 2 Basic cybersecurity elements

5. 3 Common vocabulary for risk analysis

5. 3. 1 Defining diScernable vocabulary for Assets

5. 3. 2 Threats and hazards

5. 3. 3 Defining dicernable vocabulary for Injury and Impact

5. 3. 4 Defining dicernable vocabulary for threats

5. 3. 5 Threat scenarios and attacks

5. 3. 6 Defining dicernable vocabulary for vulnerabilities

5. 3. 7 Defining dicernable vocabulary for safeguards

5. 3. 8 Risk

5. 4 Systematic Threat Identification

5. 5 Assurance Strategies

5. 5. 1 Injury Argument

5. 5. 2 Entry point argument

5. 5. 3 Threat argument

5. 5. 4 Vulnerability argument

5. 5. 5 Security requirement argument

5. 5. 6 Assurance of the threat identification

6 Chapter: Knowledge of Vulnerabilities as an Element of Cybersecurity Argument

6. 1 Vulnerability as part of system knowledege

6. 1. 1 What is Vulnerability

6. 1. 2 Vulnerability as Unit of Knowledge: The History of Vulnerability

6. 1. 3 Vulnerabilities and the Phases of the System Life Cycle

6. 1. 4 Enumeration of Vulnerabilities as a Knowledge Product

6. 1. 5 Vulnerability Databases

6. 1. 5. 1 US-CERT

6. 1. 5. 2 Open Source Vulnerability Database (OSVDB)

6. 1. 6 Vulnerability Life Cycle

6. 2 NIST Security Content Automation

Produktdetails

Erscheinungsdatum
21. Januar 2011
Sprache
englisch
Untertitel
Beyond Detecting Vulnerabilities. Sprache: Englisch.
Reihe
The MK/OMG Press
Autor/Autorin
Nikolai Mansourov, Djenana Campara
Verlag/Hersteller
Produktart
kartoniert
Gewicht
772 g
Größe (L/B/H)
17/191/235 mm
ISBN
9780123814142

Portrait

Nikolai Mansourov

Nikolai Mansourov is recognized worldwide for his work in the areas of automatic code generation and using formal specifications in both forward and reverse engineering. Prior to joining KDM Analytics, Dr. Mansourov was the Chief Scientist and Chief Architect at Klocwork Inc, where he significantly helped build the company's credibility. Dr. Mansourov also was a department head at the Institute for System Programming, Russian Academy of Sciences, where he was responsible for numerous groundbreaking research projects in advanced software development for industry leaders Nortel Networks and Telelogic. Dr. Mansourov has published over 50 research papers and is a frequent speaker as well as member of program committees at various international research forums. He is a founding member of the World-Wide Institute of Software Architects WWISA. His impact on the industry continues through his participation on several standards bodies, including the ITU-T and Object Management Group. Dr. Mansourov is one of the first OMG-certified UML Advanced Professionals and a member of the UML2 standardization team. Dr. Mansourov is the Editor of the OMG Knowledge Discovery Metamodel (KDM) specification and the Chair of the OMG Revision Task Force for KDM.

Djenana Campara has 20+ years of experience and leadership in the software engineering field. Ms. Campara is a member of the Board of Directors of the Object Management Group (OMG). Djenana Campara chairs the OMG Architecture-Driven Modernization Task Force and Software Assurance Special Interests Group, and serves as a board member on the Canadian Consortium of Software Engineering Research (CSER). Previously, Djenana was CTO of Klocwork and chairwoman of Klocwork's Board of Directors. Djenana founded the company in 2001 as a successful Nortel Networks spin off. She has served as Klocwork's chief executive officer, securing the company's first round of funding as well as closing its first customers.

She has been awarded four US patents for her groundbreaking static analysis techniques implemented in Klocwork's products. She has published a number of papers on software transformations, has been quoted in publications, including The Economist and Secure Computing, and has participated in Fortune Magazine's "Brainstorm 2003," an international conference of the world's most creative leaders.


Pressestimmen

"The Object Management Group (OMG) Software Assurance Ecosystem described in this book is a significant step towards collaborative cyber security automation; it offers a standards-based solution for building security and resilience in computer systems." --Joe Jarzombek, Director for Software Assurance, Global Cyber Security Management, National Cyber Security Division, Department of Homeland Security

"System Assurance is a very complex and difficult subject. This book successfully demonstrates and describes in detail how to combine different existing tools together in order to systematically develop System Assurance documentation and justification in a practical manner for a specific domain. The book provides very useful practical guidance that can be used by technical and management practitioners for the specific domain described, and by example for others for different domains." --John P. Hopkinson, Security Strategist, Kwictech

Bewertungen

0 Bewertungen

Es wurden noch keine Bewertungen abgegeben. Schreiben Sie die erste Bewertung zu "System Assurance" und helfen Sie damit anderen bei der Kaufentscheidung.

Nikolai Mansourov, Djenana Campara: System Assurance bei hugendubel.de. Online bestellen oder in der Filiale abholen.