Security Engineering: A Guide to Building Dependable Distributed Systems, 3rd Edition
- 29h 45m
- Ross Anderson
- Sybex
- 2020
Now that there’s software in everything, how can you make anything secure? Understand how to engineer dependable systems with this newly updated classic
In Security Engineering: A Guide to Building Dependable Distributed Systems, Third Edition Cambridge University professor Ross Anderson updates his classic textbook and teaches readers how to design, implement, and test systems to withstand both error and attack.
This book became a best-seller in 2001 and helped establish the discipline of security engineering. By the second edition in 2008, underground dark markets had let the bad guys specialize and scale up; attacks were increasingly on users rather than on technology. The book repeated its success by showing how security engineers can focus on usability.
Now the third edition brings it up to date for 2020. As people now go online from phones more than laptops, most servers are in the cloud, online advertising drives the Internet and social networks have taken over much human interaction, many patterns of crime and abuse are the same, but the methods have evolved. Ross Anderson explores what security engineering means in 2020, including:
- How the basic elements of cryptography, protocols, and access control translate to the new world of phones, cloud services, social media and the Internet of Things
- Who the attackers are – from nation states and business competitors through criminal gangs to stalkers and playground bullies
- What they do – from phishing and carding through SIM swapping and software exploits to DDoS and fake news
- Security psychology, from privacy through ease-of-use to deception
- The economics of security and dependability – why companies build vulnerable systems and governments look the other way
- How dozens of industries went online – well or badly
- How to manage security and safety engineering in a world of agile development – from reliability engineering to DevSecOps
The third edition of Security Engineering ends with a grand challenge: sustainable security. As we build ever more software and connectivity into safety-critical durable goods like cars and medical devices, how do we design systems we can maintain and defend for decades? Or will everything in the world need monthly software upgrades, and become unsafe once they stop?
About the Author
ROSS ANDERSON is Professor of Security Engineering at Cambridge University in England. He is widely recognized as one of the world's foremost authorities on security. In 2015 he won the Lovelace Medal, Britain's top award in computing. He is a Fellow of the Royal Society and the Royal Academy of Engineering. He is one of the pioneers of the economics of information security, peer-to-peer systems, API analysis and hardware security. Over the past 40 years, he has also worked or consulted for most of the tech majors.
In this Book
-
Preface to the Third Edition
-
Preface to the Second Edition
-
Preface to the First Edition
-
For my daughter, and other lawyers…
-
Foreword
-
What Is Security Engineering?
-
Who Is the Opponent?
-
Psychology and Usability
-
Protocols
-
Cryptography
-
Access Control
-
Distributed Systems
-
Economics
-
Multilevel Security
-
Boundaries
-
Inference Control
-
Banking and Bookkeeping
-
Locks and Alarms
-
Monitoring and Metering
-
Nuclear Command and Control
-
Security Printing and Seals
-
Biometrics
-
Tamper Resistance
-
Side Channels
-
Advanced Cryptographic Engineering
-
Network Attack and Defence
-
Phones
-
Electronic and Information Warfare
-
Copyright and DRM
-
New Directions?
-
Surveillance or Privacy?
-
Secure Systems Development
-
Assurance and Sustainability
-
Beyond “Computer Says No”
-
Bibliography