Information Assurance: Dependability and Security in Networked Systems

Qian, Yi; Tipper, David; Krishnamurthy, Prashant; Joshi, James

In stock
Regular price 11.500 KD inc. VAT
License
Table of contents
  • Contentsxi
  • Prefacexxiii
  • Contributorsxxvii
  • Chapter 1. Information Assurance1
  • 1.1 Introduction1
  • 1.2 Information Assurance: Dependability and Security of Networked Information Systems3
  • 1.3 Book Organization7
  • 1.4 Conclusion14
  • References14
  • Part I: Foundational Background on Security and Dependability Techniques17
  • Chapter 2. Network Security19
  • 2.1 Introduction19
  • 2.2 Network Attacks and Security Issues19
  • 2.3 Protection and Prevention27
  • 2.4 Detection34
  • 2.5 Assessment and Response36
  • 2.6 Conclusion37
  • References37
  • Chapter 3. Security for Distributed Systems: Foundations of Access Control39
  • 3.1 Introduction39
  • 3.2 Identification and Authentication40
  • 3.3 Access Control46
  • 3.4 Access Control in Distributed Systems60
  • 3.5 Digital Identity Management72
  • 3.6 Conclusion76
  • References77
  • Chapter 4. Network Survivability81
  • 4.1 Introduction81
  • 4.2 Prevention Techniques83
  • 4.3 Survivable Network Design and Traffic Restoration Concepts84
  • 4.4 Transport Network Recovery Techniques91
  • 4.5 Survivable Network Design Techniques102
  • 4.6 Multilayer Issues105
  • 4.7 Conclusion and Future Research Areas107
  • References109
  • Chapter 5. System Survivability113
  • 5.1 Introduction and Background113
  • 5.2 Survivability and the Impact of Fault Models115
  • 5.3 Design for Survivability119
  • 5.4 Decentralized Storage126
  • 5.5 Survivability of Large Distributed Systems128
  • 5.6 Borrowing from Well-established Fields133
  • 5.7 Conlusion141
  • References142
  • Part II: Modeling the Interaction Between Dependability and Security147
  • Chapter 6. Taxonomy and Framework for Integrating Dependability and Security149
  • 6.1 Introduction149
  • 6.2 Basic Concepts and Related Work150
  • 6.3 Proposed Taxonomy and Framework154
  • 6.4 Dependability, Security, and their Attributes155
  • 6.5 The Means to Attain Dependability and Security164
  • 6.6 Conclusion168
  • References168
  • Chapter 7. Stochastic Modeling Techniques for Secure and Survivable Systems171
  • 7.1 Introduction171
  • 7.2 Analytical Modeling Techniques173
  • 7.3 Security Modeling179
  • 7.4 Survivability Modeling190
  • 7.5 Conclusion205
  • Acknowledgment205
  • References205
  • Chapter 8. Integrated Dependability and Security Evaluation Using Game Theory and Markov Models209
  • 8.1 Introduction209
  • 8.2 Stochastic Modeling213
  • 8.3 Predicting Attacker Behavior221
  • 8.4 Defining and Solving the Game225
  • 8.5 Tuning the Game Parameters230
  • 8.6 Case Study: DNS Service236
  • 8.7 Conclusion240
  • References243
  • Chapter 9. Scenario Graphs Applied to Network Security247
  • 9.1 Introduction247
  • 9.2 Algorithms for Generating Scenario Graphs248
  • 9.3 Attack Graphs are Scenario Graphs251
  • 9.4 Network Attack Graphs253
  • 9.5 Example Network257
  • 9.6 Attack Graph Analysis266
  • 9.7 Practical Experience269
  • 9.8 Related Work272
  • 9.9 Future Work and Conclusion274
  • Acknowledgments275
  • References276
  • Chapter 10. Vulnerability-Centric Alert Correlation279
  • 10.1 Introduction279
  • 10.2 Review of Alert Correlation and Related Techniques282
  • 10.3 Attack Graph284
  • 10.4 Alert Correlation, Hypothesis, Prediction, and Aggregation287
  • 10.5 Conclusion300
  • 10.6 Acknowledgments300
  • References301
  • Part III: Design and Architectural Issues for Secure and Dependable Systems305
  • Chapter 11. Monitoring and Detecting Attacks in All-Optical Networks307
  • 11.1 Introduction307
  • 11.2 Crosstalk Attack Features and Monitoring Techniques311
  • 11.3 Node, Attack, and Monitor Models315
  • 11.4 Necessary and Sufficient Conditions for Crosstalk Attack Detection320
  • 11.5 One-Crosstalk Attack Diagnosable Conditions325
  • 11.6 k-Crosstalk Attacks in the Network329
  • 11.7 Sparse Monitoring and Routing Algorithms336
  • 11.8 Sparse Monitoring, Test Connection, and Routing for More than One Original Attack Flow342
  • 11.9 Conclusion345
  • References345
  • Chapter 12. Robustness Evaluation of Operating Systems349
  • 12.1 Introduction349
  • 12.2 Evaluation Goals352
  • 12.3 Target System353
  • 12.4 Error Model and Workload Selection355
  • 12.5 Robustness Metrics361
  • 12.6 Presentation and Interpretation of Results366
  • 12.7 Conclusion370
  • References370
  • Further Reading375
  • Chapter 13. Intrusion Response Systems: A Survey377
  • 13.1 Introduction377
  • 13.2 Static Decision-Making Systems381
  • 13.3 Dynamic Decision-Making Systems387
  • 13.4 Intrusion Tolerance Through Diverse Replicas397
  • 13.5 Responses to Specific Kinds of Attacks403
  • 13.6 Benchmarking Intrusion Response Systems407
  • 13.7 Thoughts on Evolution of IRS Technology410
  • 13.8 Conclusion412
  • References412
  • Chapter 14. Secure and Resilient Routing: Building Blocks for Resilient Network Architectures417
  • 14.1 Introduction417
  • 14.2 Traffic Engineering Perspective and its Relation to Network Robustness419
  • 14.3 Components of a Resilient Network Architecture423
  • 14.4 Threats and Counter Measures in Link-State Routing424
  • 14.5 Resilient Architecture: Virtualization and Routing435
  • 14.6 Conclusion446
  • Acknowledgments446
  • References446
  • 14.A Secure Group Communication449
  • 14.A.1 Using One-Way Function Chain to Build Key Chain449
  • 14.A.2 Key Distribution451
  • 14.A.3 Key Agreement Protocol454
  • 14.A.4 Assessment456
  • Chapter 15. Security and Survivability of Wireless Systems459
  • 15.1 Introduction459
  • 15.2 Background460
  • 15.3 Current Security Approaches in Wireless Networks463
  • 15.4 Current Survivability Approaches in Wireless Networks465
  • 15.5 Framework for Wireless Network Survivability and Security467
  • 15.6 Interaction Between Survivability and Security in Wireless Networks470
  • 15.7 Conclusion484
  • References485
  • Chapter 16. Integrated Fault and Security Management489
  • 16.1 Introduction489
  • 16.2 Active Integrated Fault Identification Framework490
  • 16.3 Fault and Security Management on High-Speed Networks506
  • 16.4 Conclusion520
  • References520
  • Index523
Book details
  • Vendor Elsevier S & T
  • SKU 9780123735669R90
  • ISBN-13 9780080555881
  • Author Qian, Yi; Tipper, David; Krishnamurthy, Prashant; Joshi, James
  • Category Computers
  • Subject General

Do you have questions about this book?

Ask an expert!

In today’s fast paced, infocentric environment, professionals increasingly rely on networked information technology to do business. Unfortunately, with the advent of such technology came new and complex problems that continue to threaten the availability, integrity, and confidentiality of our electronic information. It is therefore absolutely imperative to take measures to protect and defend information systems by ensuring their security and non-repudiation. Information Assurance skillfully addresses this issue by detailing the sufficient capacity networked systems need to operate while under attack, and itemizing failsafe design features such as alarms, restoration protocols, and management configurations to detect problems and automatically diagnose and respond. Moreover, this volume is unique in providing comprehensive coverage of both state-of-the-art survivability and security techniques, and the manner in which these two components interact to build robust Information Assurance (IA).

KEY FEATURES
* The first and (so far) only book to combine coverage of both security AND survivability in a networked information technology setting
* Leading industry and academic researchers provide state-of-the-art survivability and security techniques and explain how these components interact in providing information assurance
* Additional focus on security and survivability issues in wireless networks