Have one to sell? Sell yours here
or
Get a £0.25 Amazon.co.uk Gift Card
Security Engineering: A Guide to Building Dependable Distributed Systems (Wiley Computer Publishing)
 
 
Tell the Publisher!
I’d like to read this book on Kindle

Don't have a Kindle? Get your Kindle here, or download a FREE Kindle Reading App.

Security Engineering: A Guide to Building Dependable Distributed Systems (Wiley Computer Publishing) [Paperback]

Ross J. Anderson
4.9 out of 5 stars  See all reviews (8 customer reviews)

Available from these sellers.


‹  Return to Product Overview

Product Description

Amazon.co.uk Review

Gigantically comprehensive and carefully researched, Security Engineering makes it clear just how difficult it is to protect information systems from corruption, eavesdropping, unauthorised use and general malice. Better, Ross Anderson offers a lot of thoughts on how information can be made more secure (though probably not absolutely secure, at least not forever) with the help of both technologies and management strategies. His work makes fascinating reading, and will no doubt inspire considerable doubt--fear is probably a better choice of words--in anyone with information to gather, protect, or make decisions upon.

Be aware: this is absolutely not a book solely about computers, with yet another explanation of Alice and Bob and how they exchange public keys in order to exchange messages in secret. Anderson explores, for example, the ingenuous ways in which European truck drivers defeat their vehicles' speed-logging equipment. In another section, he shows how the end of the Cold War brought on a decline in defences against radio-frequency monitoring (radio frequencies can be used to determine, at a distance, what's going on in systems--bank teller machines, say) and how similar technology can be used to reverse-engineer the calculations that go on inside smart cards. In almost 600 pages of riveting detail, Anderson warns us not to be seduced by the latest defensive technologies, never to underestimate human ingenuity and always use common sense in defending valuables. It is a terrific read for security professionals and general readers alike. --David Wall

Topics covered: how some people go about protecting valuable things (particularly, but not exclusively, information) and how other people go about getting it anyway. Mostly, this takes the form of essays (about, for example, how the US Air Force keeps its nukes out of the wrong hands) and stories (one of which tells of an art thief who defeated the latest technology by hiding in a closet). Sections deal with technologies, policies, psychology and legal matters.

Review

"While many of the chapter topics may sound unexciting, Anderson has a wonderful writing style and at times reads almost like a Tom Clancy thriller with its details of military command and control systems and other similar topics. Anyone responsible for information security should read Security Engineering." (UnixReview.com, July 2001)

"an eminently readable yet comprehensive book" (Network News, 12 September 2001)

"...Anyone responsible for information security should read Security Engineering." (UnixReview.com, July 2001)

"an eminently readable yet comprehensive book" (Network News, 12 September 2001)

New Scientist, 16th June 2001

"Network administrators should be forced to have a copy of Ross Anderson's Security Engineering on their shelves. And anyone with the slightest interest in finding out just how vulnerable they are to one form of electronic infiltration or another must secure themselves a copy immediately. Read it from cover to cover or use it as a reference-it is encyclopaedic in its coverage of electronic security issues."

PC Pro, 1st September 2001

"This is the nearest thing that anyone involved in the building of secure systems in the 21st century will find to a bible volume."

UnixReview.com, July 2001

"...Anyone responsible for information security should read Security Engineering."

Product Description

The first quick reference guide to the do′s and don′ts of creating high quality security systems.
Ross Anderson, widely recognized as one of the world′s foremost authorities on security engineering, presents a comprehensive design tutorial that covers a wide range of applications. Designed for today′s programmers who need to build systems that withstand malice as well as error (but have no time to go do a PhD in security), this book illustrates basic concepts through many real–world system design successes and failures. Topics range from firewalls, through phone phreaking and copyright protection, to frauds against e–businesses. Anderson′s book shows how to use a wide range of tools, from cryptology through smartcards to applied psychology. As everything from burglar alarms through heart monitors to bus ticket dispensers starts talking IP, the techniques taught in this book will become vital to everyone who wants to build systems that are secure, dependable and manageable.

From the Publisher

Security engineering is about building systems to remain dependable in the face of malice, error or mischance. It requires cross-disciplinary expertise, ranging from cryptography and computer security to a knowledge of applied psychology, management and the law. Although there are good books on many of these disciplines, this book is the first to bring them together into a comprehensive guide to building complete systems. Written for the working programmer or engineer who needs to learn the subject quickly but has no time to do a PhD in it, the book brings the subject to life with detailed descriptions of automatic teller machines, burglar alarms, copyright protection mechanisms, de-identified medical record databases, electronic warfare systems, and other critical applications. It also covers a lot of technology for which there isn't any good introductory text, such as biometrics, tamper-resistant electronics and the tricks used in phone fraud.

Over the next few years, the Internet will grow to include all sorts of things besides PCs. By 2003, there will be more mobile phones connected than computers, and within a few years we'll see many of the world's fridges, heart monitors, bus ticket dispensers and burglar alarms talking IP. Things will be further complicated by the spread of peer-to-peer models of networking. Securing real applications in this sort of environment is one of the biggest engineering challenges of the next ten years. This book will help you to meet the challenge.

From the Author

This is the book I wish had been around in the early 1980s when I started earning my living doing security engineering. Then, there were plenty books and research papers on theory, but little on the actual practice. Nowadays, the situation is still much the same. And just as bridge builders learn more from the one bridge that falls down than from the hundreds that don't, so security engineers can learn much more from studying how real systems have been built - and, especially, how they have failed. The real problems have to do with system-level concepts; they lie in understanding what your application's protection requirements really are, and how you can combine the available mechanisms intelligently to meet them.

This book distills the system know-how I've learnt in years as a banker, in more years as a security consultant, and in still more years as an academic. Putting it together has been fun. It's also been a valuable research exercise: there's no better way of finding out what you don't know than trying to write down what you do. With luck, this book will serve as a snapshot of what we know - and of what we don't - at the beginning of the twenty-first century.

I hope you have as much fun reading it as I had writing it!

From the Back Cover

"If you′re even thinking of doing any security engineering, you need to read this book. It′s the first, and only, end–to–end modern security design and engineering book ever written."–Bruce Schneier

"Many people are anxious about Internet security for PCs and servers," says leading expert Ross Anderson, "as if that′s all there is when in reality security problems have just begun. By 2003, there may be more mobile phones on the Net than PCs, and they will be quickly followed by network–connected devices from refrigerators to burglar alarms to heart monitors. How will we manage the risks?"

Dense with anecdotes and war stories, readable, up–to–date and full of pointers to recent research, this book will be invaluable to you if you have to design systems to be resilient in the face of malice as well as error. Anderson provides the tools and techniques you′ll need, discusses what′s gone wrong in the past, and shows you how to get your design right the first time around.

You don′t need to be a security expert to understand Anderson′s truly accessible discussion of:
∗ Security engineering basics, from protocols, cryptography, and access controls to the nuts and bolts of distributed systems
∗ The lowdown on biometrics, tamper resistance, security seals, copyright marking, and many other protection technologies–for many of them, this is the first detailed information in an accessible textbook
∗ What sort of attacks are done on a wide range of systems–from banking and medical records through burglar alarms and smart cards to mobile phones and e–commerce–and how to stop them
∗ Management and policy issues–how computer security interacts with the law and with corporate culture

About the Author

ROSS ANDERSON teaches and directs research in computer security at Cambridge University, England. Widely recognized as one of the world′s foremost authorities on security engineering, he has published extensive studies on how real security systems fail–on bank card fraud, phone phreaking, pay–TV hacking, ways to cheat metering systems and breaches of medical privacy.
‹  Return to Product Overview