DevOps環境でのサイバーセキュリティ<br>CyberSecurity in a DevOps Environment : From Requirements to Monitoring

個数:

DevOps環境でのサイバーセキュリティ
CyberSecurity in a DevOps Environment : From Requirements to Monitoring

  • 提携先の海外書籍取次会社に在庫がございます。通常3週間で発送いたします。
    重要ご説明事項
    1. 納期遅延や、ご入手不能となる場合が若干ございます。
    2. 複数冊ご注文の場合は、ご注文数量が揃ってからまとめて発送いたします。
    3. 美品のご指定は承りかねます。

    ●3Dセキュア導入とクレジットカードによるお支払いについて
  • 【入荷遅延について】
    世界情勢の影響により、海外からお取り寄せとなる洋書・洋古書の入荷が、表示している標準的な納期よりも遅延する場合がございます。
    おそれいりますが、あらかじめご了承くださいますようお願い申し上げます。
  • ◆画像の表紙や帯等は実物とは異なる場合があります。
  • ◆ウェブストアでの洋書販売価格は、弊社店舗等での販売価格とは異なります。
    また、洋書販売価格は、ご注文確定時点での日本円価格となります。
    ご注文確定後に、同じ洋書の販売価格が変動しても、それは反映されません。
  • 製本 Hardcover:ハードカバー版/ページ数 324 p.
  • 言語 ENG
  • 商品コード 9783031422119

Full Description

This book provides an overview of software security analysis in a DevOps cycle including requirements formalisation, verification and continuous monitoring.  It presents an overview of the latest techniques and tools that help engineers and developers verify the security requirements of large-scale industrial systems and explains novel methods that enable a faster feedback loop for verifying security-related activities, which rely on techniques such as automated testing, model checking, static analysis, runtime monitoring, and formal methods.

The book consists of three parts, each covering a different aspect of security engineering in the DevOps context. The first part, "Security Requirements", explains how to specify and analyse security issues in a formal way. The second part, "Prevention at Development Time", offers a practical and industrial perspective on how to design, develop and verify secure applications. The third part, "Protection at Operations", eventually introduces tools for continuous monitoring of security events and incidents. Overall, it covers several advanced topics related to security verification, such as optimizing security verification activities, automatically creating verifiable specifications from security requirements and vulnerabilities, and using these security specifications to verify security properties against design specifications and generate artifacts such as tests or monitors that can be used later in the DevOps process.

The book aims at computer engineers in general and does not require specific knowledge. In particular, it is intended for software architects, developers, testers, security professionals, and tool providers, who want to define, build, test, and verify secure applications, Web services, and industrial systems.

Contents

Part I: Security Requirements Engineering.- 1. A Taxonomy of Vulnerabilities, Attacks, and Security Solutions in Industrial PLCs.- 2. Natural Language Processing with Machine Learning for Security Requirements Analysis - Practical Approaches.- 3. Security Requirements Formalisation with RQCODE.- Part II: Prevention at Development Time.- 4. Vulnerability Detection and Response: Current Status and New Approaches.- 5. Metamorphic Testing for Verification and Fault Localization in Industrial Control Systems.- 6. Interactive Application Security Testing with Hybrid Fuzzing and Statistical Estimators.- Part III: Protection at Operations.- 7. CTAM: a tool for Continuous Threat Analysis and Management.- 8. EARLY - a tool for real-time security attack detection.- 9. A Stream-Based Approach to Intrusion Detection.- 10. Towards Anomaly Detection using Explainable AI. 

最近チェックした商品