Blog Arşivi

Introduction to Security - Bölümler etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster
Introduction to Security - Bölümler etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster

30 Ekim 2011 Pazar

Bölüm - 10 : Trusted Computing and Multilevel Security

• Bell‐Lapadula security model
• other models
• reference monitors & trojan horse defence
• multilevel secure RBAC and databases
• trusted platform module
• common criteria
• assurance and evaluation

Bölüm - 9 : Firewalls and Intrusion Prevention Systems

• introduced need for & purpose of firewalls
• types of firewalls
– packet filter, stateful inspection, application and
circuit gateways
• firewall hosting, locations, topologies
• intrusion prevention systems

Bölüm - 8 : Denial of Service

• introduced denial of service (DoS) attacks
• classic flooding and SYN spoofing attacks
• ICMP, UDP, TCP SYN floods
• distributed denial of service (DDoS) attacks
• reflection and amplification attacks
• defenses against DoS attacks
• responding to DoS attacks

Bölüm - 7 : Malicious Software

• introduced types of malicous software
– incl backdoor, logic bomb, trojan horse, mobile
• virus types and countermeasures
• worm types and countermeasures
• bots
• rootkits

Bölüm - 6 : Intrusion Detection

• introduced intruders & intrusion detection
– hackers, criminals, insiders
• intrusion detection approaches
– host‐based (single and distributed)
– network
– distributed adaptive
– exchange format
• honeypots
• SNORT example

Bölüm - 5 : Database Security

• introduced databases and DBMS
• relational databases
• database access control issues
– SQL, role‐based
• inference
• statistical database security issues
• database encryption

Bölüm - 4 : Access Control

• introduced access control principles
– subjects, objects, access rights
• discretionary access controls
– access matrix, access control lists (ACLs),
capability tickets
– UNIX traditional and ACL mechanisms
• role‐based access control
• case study

Bölüm - 3 : User Authentication

introduced user authentication
– using passwords
– using tokens
– using biometrics
• remote user authentication issues
• example application and case study

Bölüm - 2 : Cryptographic Tools

• introduced cryptographic algorithms
• symmetric encryption algorithms for
confidentiality
• message authentication & hash functions
• public‐key encryption
• digital signatures and key management
• random numbers

25 Ekim 2011 Salı

Bölüm - 1 : Overview

 Konular:

• security concepts
• terminology
• functional requirements
• security architecture
• security trends
• security strategy