Wireless Operational Security
Rittinghouse, PhD, CISM, John; Ransome, PhD, CISM, CISSP, James F.
In stock
Regular price
34.750 KD
inc. VAT
Couldn't load pickup availability
Table of contents
- Cover
- Copyright Pageiv
- Contentsv
- List of Figures and Tablesxv
- Forewordxvii
- Prefacexix
- Acknowledgmentsxxv
- Section I: General Network Security1
- Chapter 1. Basic Concepts3
- 1.1 Threats to personal privacy4
- 1.2 Fraud and theft4
- 1.3 Internet fraud5
- 1.4 Employee sabotage7
- 1.5 Infrastructure attacks8
- 1.6 Malicious hackers8
- 1.7 Malicious coders9
- 1.8 Industrial espionage9
- 1.9 Social engineering12
- 1.10 Privacy standards and regulations16
- 1.11 Endnotes21
- Chapter 2. Managing Access23
- 2.1 Access control23
- 2.2 Password management38
- 2.3 Endnotes44
- Chapter 3. Setting Up Defenses47
- 3.1 Foundations of information assurance47
- 3.2 Defense-in-Depth strategy52
- 3.3 The Common Criteria Model56
- 3.4 Security architecture57
- 3.5 Operations security59
- 3.6 Host-based intrusion detection60
- 3.7 Network-based intrusion detection efforts66
- 3.8 Endnotes68
- Chapter 4. Incident Management69
- 4.1 Overview of RFC 2196 (Site Security Handbook)69
- 4.2 Incident handling process overview70
- 4.3 Endnotes84
- Chapter 5. Securing Web Applications85
- 5.1 Applications development security85
- 5.2 Endnotes93
- Chapter 6. Security and the Law95
- 6.1 The 1996 National Information Infrastructure Protection Act95
- 6.2 President’s Executive Order on critical infrastructure protection96
- 6.3 The USA Patriot Act of 200197
- 6.4 The Homeland Security Act of 2002101
- 6.5 Changes to existing laws101
- 6.6 Investigations112
- 6.7 Ethics113
- 6.8 Endnotes114
- Section II: Wireless Network Security115
- Chapter 7. Wireless Networking Basics117
- 7.1 Wireless local area networks117
- 7.2 Mobile security129
- 7.3 Encryption schemes in WLANs150
- 7.4 Endnotes156
- Chapter 8. WLAN Policy and Risk Management159
- 8.1 Purpose and goals of WLAN security policies159
- 8.2 Basic approach to WLAN security and policy development160
- 8.3 WLAN risk management177
- 8.4 Risks to wired networks from wireless networks181
- 8.5 Security issues for wireless public-access network use182
- 8.6 Sample WLAN security checklist183
- 8.7 Creating WLANs in public space187
- 8.8 Designs for scalable and secure WLAN solutions188
- 8.9 Endnotes190
- Chapter 9. WLAN Intrusion Process191
- 9.1 Pro.ling to select a target or gather information191
- 9.2 Social engineering192
- 9.3 Searching publicly available resources193
- 9.4 War-driving, -walking, -flying, and -chalking194
- 9.5 Exploitable WLAN configurations199
- 9.6 How intruders obtain network access to a WLAN199
- 9.7 Password gathering and cracking software205
- 9.8 Share enumerators209
- 9.9 Using antennas and WLAN equipment210
- 9.10 Denial-of-service attacks and tools210
- 9.11 Rogue devices as exploitation tools213
- 9.12 Other useful tools and techniques215
- 9.13 Use of malicious code or life insertion in WLANs217
- 9.14 Security vulnerabilities with public-access wireless networks220
- 9.15 Weaknesses in existing security solutions221
- 9.16 Endnotes222
- Chapter 10. WLAN Risk and Threat Mitigation223
- 10.1 Mitigating static WEP risks with TKIP223
- 10.2 Using dynamic WEP (802.1x and EAP) to address227
- 10.3 VPNs in a WLAN environment240
- 10.4 Enhancing WLAN security260
- 10.5 Other WLAN security issues270
- 10.6 Conclusion271
- 10.7 Endnotes272
- Chapter 11. Additional WLAN Security Solutions275
- 11.1 Intrusion detection systems275
- 11.2 Security advantages of thin clients in a wireless environment280
- 11.3 Using DHCP services for authentication280
- 11.4 Baselining282
- 11.5 Using Kerberos, RADIUS, and LDAP for WLAN authentication283
- 11.6 Multifactor authentication301
- 11.7 802.11i and WiFi protected access302
- 11.8 Conclusion305
- 11.9 Endnotes305
- Chapter 12. WISDOM for WLAN Practitioners309
- 12.1 Risk assessments revisited309
- 12.2 Costs of securing WLANs310
- 12.3 WLAN threat and impact analysis312
- 12.4 WLAN security management considerations313
- 12.5 Applying WISDOM to WLAN security315
- 12.6 Conclusion355
- 12.7 Endnotes356
- Glossary357
- A Wireless Policy Essentials383
- A.1 Wireless position statement383
- A.2 ABC Inc. InfoSec Risk Assessment Policy387
- A.3 ABC Inc. InfoSec Audit Policy389
- A.4 ABC Inc. InfoSec Acceptable Use Policy391
- A.5 ABC Inc. InfoSec Network Policy397
- A.6 ABC Inc. InfoSec De-Militarized Zone (DMZ) Policy402
- A.7 ABC Inc. InfoSec Router Policy407
- A.8 ABC Inc. InfoSec Extranet Policy409
- A.9 ABC Inc. InfoSec Remote Access Policy413
- A.10 ABC Inc. InfoSec Dial-In Access Policy418
- A.11 ABC Inc. InfoSec VPN Communication Policy420
- A.12 ABC Inc. InfoSec Wireless Communication Policy423
- A.13 ABC Inc. InfoSec Server Policy425
- A.14 ABC Inc. InfoSec Password Policy429
- A.15 ABC Inc. InfoSec Application Password Policy434
- A.16 ABC Inc. InfoSec Anti-Virus Policy438
- A.17 ABC Inc. InfoSec Policy Exception Form440
- B Wireless-related Legislative Links441
- C Additional WLAN References443
- C.1 Other WLAN Interest Items445
- C.2 Security Risks and Legal Protections Recap446
- C.3 Endnotes451
- Index453
Book details
- Vendor Elsevier S & T
- SKU 9781555583170
- ISBN-13 9780080521190
- Author Rittinghouse, PhD, CISM, John; Ransome, PhD, CISM, CISSP, James F.
- Category Computers
- Subject General
Do you have questions about this book?
This comprehensive wireless network book addresses the operational and day-to-day security management requirements of 21st century companies. Wireless networks can easily be reconfigured, are very mobile, allow for potentially nonstop exposure, and require the level of security be scrutinized even more than for wired networks. This includes inherent security flaws in various wireless architectures that result in additional risks to otherwise secure converged wired networks. An even worse scenario is one where an insecure wireless network is connected to a weakly secured or insecure wired network and the wireless subnet is not separated from the wired subnet. There are approximately a dozen popular books that cover components of the architecture, design, theory, issues, challenges, and recommended policies for wireless security, none of which address them in a practical, operationally-oriented and comprehensive way. Wireless Operational Security bridges this gap.
*Presents a new "WISDOM" model for Wireless Security Infrastructures
*Acts as a critical guide to implementing "Converged Networks" wired/wireless with all necessary security considerations
*Rittinghouse's Cybersecurity Operations Handbook is the only security book recommended by the FCC
*Presents a new "WISDOM" model for Wireless Security Infrastructures
*Acts as a critical guide to implementing "Converged Networks" wired/wireless with all necessary security considerations
*Rittinghouse's Cybersecurity Operations Handbook is the only security book recommended by the FCC
Instant delivery by email
Your access email arrives within minutes of checkout, with a sign-in link for each book — no shipping, no waiting.
Read on any device
Books open in VitalSource Bookshelf on your phone, tablet, or computer, online or offline. Your library is always available at aafaq.vitalsource.com — just log in with the email you used at checkout.
Lost the email?
Resend it to yourself in seconds from My eBook orders, or email cs@aafaqeducation.com and we'll help.