دسترسی نامحدود
برای کاربرانی که ثبت نام کرده اند
برای ارتباط با ما می توانید از طریق شماره موبایل زیر از طریق تماس و پیامک با ما در ارتباط باشید
در صورت عدم پاسخ گویی از طریق پیامک با پشتیبان در ارتباط باشید
برای کاربرانی که ثبت نام کرده اند
درصورت عدم همخوانی توضیحات با کتاب
از ساعت 7 صبح تا 10 شب
ویرایش:
نویسندگان: Tim Rains
سری:
ISBN (شابک) : 1800206011, 9781800206014
ناشر: Packt Publishing
سال نشر: 2020
تعداد صفحات: 429
زبان: English
فرمت فایل : PDF (درصورت درخواست کاربر به PDF، EPUB یا AZW3 تبدیل می شود)
حجم فایل: 4 مگابایت
در صورت تبدیل فایل کتاب Cybersecurity Threats, Malware Trends, and Strategies: Mitigate exploits, malware, phishing, and other social engineering attacks به فرمت های PDF، EPUB، AZW3، MOBI و یا DJVU می توانید به پشتیبان اطلاع دهید تا فایل مورد نظر را تبدیل نمایند.
توجه داشته باشید کتاب تهدیدات امنیت سایبری، روندها و استراتژیهای بدافزار: کاهش سوء استفاده، بدافزار، فیشینگ و سایر حملات مهندسی اجتماعی نسخه زبان اصلی می باشد و کتاب ترجمه شده به فارسی نمی باشد. وبسایت اینترنشنال لایبرری ارائه دهنده کتاب های زبان اصلی می باشد و هیچ گونه کتاب ترجمه شده یا نوشته شده به فارسی را ارائه نمی دهد.
پس از بررسی استراتژیهای متعدد امنیت سایبری، مشاور ارشد امنیت جهانی سابق مایکروسافت بینشهای منحصربهفردی را در مورد تحولات چشمانداز تهدید و نحوه برخورد شرکتها با چالشهای امنیت سایبری مدرن ارائه میدهد.
تهدیدات امنیت سایبری، روندهای بدافزار و استراتژی ها بینش های متعددی را در مورد تهدیدات به اشتراک می گذارد. هر دو سازمان های بخش دولتی و خصوصی با استراتژی های امنیت سایبری مواجه هستند که می تواند آنها را کاهش دهد.
این کتاب با بررسی روند بیست ساله در افشای آسیبپذیریها و بهرهبرداری، نزدیک به یک دهه تفاوتهای منطقهای در آلودگیهای بدافزار، عوامل اجتماعی-اقتصادی که زیربنای آنها و چگونگی تکامل بدافزارهای جهانی. این به شما دیدگاه های بیشتری در مورد محافظت از بدافزار برای سازمان شما می دهد. همچنین تهدیدات مبتنی بر اینترنت را که CISO ها باید از آنها آگاه باشند، بررسی می کند.
این کتاب ارزیابی استراتژیهای مختلف امنیت سایبری را ارائه میکند که در نهایت طی بیست سال گذشته شکست خوردهاند، همراه با یک یا دو مورد که واقعاً کارآمد بودهاند. این به مدیران و متخصصان امنیت و انطباق کمک می کند تا بفهمند که چگونه رایانش ابری برای آنها یک تغییر بازی است.
در پایان این کتاب، میدانید که چگونه اثربخشی استراتژی امنیت سایبری سازمان خود و کارآمدی فروشندگانی را که برای کمک به محافظت از سازمان و خود به کار میگیرید، اندازهگیری کنید.
این کتاب برای مدیریت ارشد در بخش تجاری و سازمانهای بخش عمومی، از جمله افسران ارشد امنیت اطلاعات (CISO) و سایر مدیران ارشد گروههای امنیت سایبری، افسران ارشد اطلاعات (CIO) است. ، افسران ارشد فناوری (CTO) و مدیران ارشد فناوری اطلاعات که می خواهند طیف وسیعی از امنیت سایبری، از شکار تهدید و مدیریت ریسک امنیتی گرفته تا تجزیه و تحلیل بدافزار را بررسی کنند. متخصصان حاکمیت، ریسک و انطباق نیز سود خواهند برد. کارشناسان امنیت سایبری که به دانش خود در مورد چشم انداز تهدید افتخار می کنند، از این کتاب به عنوان مرجع استفاده خواهند کرد.
After scrutinizing numerous cybersecurity strategies, Microsoft's former Global Chief Security Advisor provides unique insights on the evolution of the threat landscape and how enterprises can address modern cybersecurity challenges.
Cybersecurity Threats, Malware Trends, and Strategies shares numerous insights about the threats that both public and private sector organizations face and the cybersecurity strategies that can mitigate them.
The book provides an unprecedented long-term view of the global threat landscape by examining the twenty-year trend in vulnerability disclosures and exploitation, nearly a decade of regional differences in malware infections, the socio-economic factors that underpin them, and how global malware has evolved. This will give you further perspectives into malware protection for your organization. It also examines internet-based threats that CISOs should be aware of.
The book will provide you with an evaluation of the various cybersecurity strategies that have ultimately failed over the past twenty years, along with one or two that have actually worked. It will help executives and security and compliance professionals understand how cloud computing is a game changer for them.
By the end of this book, you will know how to measure the effectiveness of your organization's cybersecurity strategy and the efficacy of the vendors you employ to help you protect your organization and yourself.
This book is for senior management at commercial sector and public sector organizations, including Chief Information Security Officers (CISOs) and other senior managers of cybersecurity groups, Chief Information Officers (CIOs), Chief Technology Officers (CTOs) and senior IT managers who want to explore the entire spectrum of cybersecurity, from threat hunting and security risk management to malware analysis. Governance, risk, and compliance professionals will also benefit. Cybersecurity experts that pride themselves on their knowledge of the threat landscape will come to use this book as a reference.
Cover Copyright Packt Page Contributors Table of Contents Preface Chapter 1: Ingredients for a Successful Cybersecurity Strategy What is a cybersecurity strategy? How organizations get initially compromised and the cybersecurity fundamentals Unpatched vulnerabilities Security misconfigurations Weak, leaked, and stolen credentials Social engineering Insider threats Focus on the cybersecurity fundamentals Understanding the difference between the attacker's motivations and tactics Other ingredients for a successful strategy Business objective alignment Cybersecurity vision, mission, and imperatives Senior executive and board support Understand the risk appetite Realistic view of current cybersecurity capabilities and technical talent Compliance program and control framework alignment An effective relationship between cybersecurity and IT Security culture Chapter summary References Chapter 2: Using Vulnerability Trends to Reduce Risk and Costs Introduction Vulnerability Management Primer Vulnerability Disclosure Data Sources Industry Vulnerability Disclosure Trends Reducing Risk and Costs – Measuring Vendor and Product Improvement Oracle Vulnerability Trends Apple Vulnerability Trends IBM Vulnerability Trends Google Vulnerability Trends Microsoft Vulnerability Trends Vendor Vulnerability Trend Summary Operating System Vulnerability Trends Microsoft Operating System Vulnerability Trends Windows XP Vulnerability Trends Windows 7 Vulnerability Trends Windows Server 2012 and 2016 Vulnerability Trends Windows 10 Vulnerability Trends Linux Kernel Vulnerability Trends Google Android Vulnerability Trends Apple macOS Vulnerability Trends Operating Systems Vulnerability Trend Summary Web Browser Vulnerability Trends Internet Explorer Vulnerability Trends Microsoft Edge Vulnerability Trends Google Chrome Vulnerability Trends Mozilla Firefox Vulnerability Trends Apple Safari Vulnerability Trends Web Browser Vulnerability Trend Summary Vulnerability Management Guidance Chapter summary References Chapter 3: The Evolution of the Threat Landscape – Malware Introduction Why is there so much malware on Windows compared to other platforms? Data sources The Malicious Software Removal Tool Real-time anti-malware tools Non-security data sources About malware How malware infections spread Trojans Potentially unwanted software Exploits and exploit kits Worms Ransomware Viruses Browser modifiers Measuring malware prevalence Global windows malware infection analysis Regional windows malware infection analysis The long-term view of the threat landscape in the Middle East and Northern Africa 10-year regional report card for the Middle East and Northern Africa The long-term view of the threat landscape in the European Union and Eastern Europe 10-year regional report card for the European Union 10-year regional report card for select Eastern European locations The long-term view of the threat landscape in select locations in Asia 10-year regional report card for Asia The long-term view of the threat landscape in select locations in the Americas 10-year regional report card for the Americas Regional Windows malware infection analysis conclusions What does this all mean for CISOs and enterprise security teams? Global malware evolution Global malware evolution conclusions The great debate – are anti-malware solutions really worthwhile? Threat intelligence best practices and tips Tip #1 – data sources Tip #2 – time periods Tip #3 – recognizing hype Tip #4 – predictions about the future Tip #5 – vendors' motives Chapter summary References Chapter 4: Internet-Based Threats Introduction A typical attack Phishing attacks Mitigating phishing Drive-by download attacks Mitigating drive-by download attacks Malware hosting sites Mitigating malware distribution Post compromise – botnets and DDoS attacks Chapter summary References Chapter 5: Cybersecurity Strategies Introduction Measuring the efficacy of cybersecurity strategies Cybersecurity strategies Protect and Recover Strategy Cybersecurity fundamentals scoring system score Protect and Recover Strategy summary Endpoint Protection Strategy Cybersecurity fundamentals scoring system score Endpoint Protection Strategy summary Physical control and security clearances as a security strategy Cybersecurity fundamentals scoring system score Physical Control and Security Clearances Strategy summary Compliance as a Security Strategy Cybersecurity fundamentals scoring system score Compliance as a Security Strategy summary Application-Centric Strategy Cybersecurity fundamentals scoring system score Application-Centric Strategy summary Identity-Centric Strategy Cybersecurity fundamentals scoring system score Identity-Centric Strategy summary Data-Centric Strategy Cybersecurity fundamentals scoring system score Data-Centric Strategy summary Attack-Centric Strategy Cybersecurity fundamentals scoring system score Attack-Centric Strategy summary Cybersecurity strategies summary DevOps and DevSecOps Zero Trust Chapter summary References Chapter 6: Strategy Implementation Introduction What is an Intrusion Kill Chain? Modernizing the kill chain Mapping the cybersecurity usual suspects Updating the matrix Getting started Maturity of current cybersecurity capabilities Who consumes the data? Cybersecurity license renewals Implementing this strategy Rationalizing the matrix – gaps, under-investments, and over-investments Planning your implementation Designing control sets Attack phase – Reconnaissance I Attack phase – Delivery Attack phase – Exploitation Attack phase – Installation Attack phase – Command and Control (C2) Attack phase – Reconnaissance II Attack phase – Actions on Objectives Conclusion Chapter summary References Chapter 7: Measuring Performance and Effectiveness Introduction Using vulnerability management data Assets under management versus total assets Known unpatched vulnerabilities Unpatched vulnerabilities by severity Vulnerabilities by product type Measuring performance and efficacy of an Attack-Centric Strategy Performing intrusion reconstructions Using intrusion reconstruction results Identifying lame controls Learning from failure Identifying helpful vendors Informing internal assessments Chapter summary References Chapter 8: The Cloud – A Modern Approach to Security and Compliance Introduction How is cloud computing different? Security and compliance game changers The power of APIs The advantages of automation Mitigating insider threat and social engineering Mitigating unpatched vulnerabilities Mitigating security misconfigurations Mitigating weak, leaked and stolen passwords Security and compliance game changers: Summary Using cybersecurity strategies in the cloud Using the protect and recover strategy in the cloud Compliance as a cybersecurity strategy in the cloud Using the attack-centric strategy in the cloud DevOps – A modern approach to security in the cloud Encryption and key management Conclusion Chapter summary References Other Books You May Enjoy Index