Applied Information Security A Hands-on Approach

This book explores fundamental principles for securing IT systems and illustrates them with hands-on experiments that may be carried out by the reader using accompanying software. The experiments highlight key information security problems that arise in m

  • PDF / 1,639,296 Bytes
  • 209 Pages / 439.37 x 666.142 pts Page_size
  • 159 Downloads / 737 Views

DOWNLOAD

REPORT


David Basin r Patrick Schaller r Michael Schläpfer

Applied Information Security A Hands-on Approach

Prof. Dr. David Basin ETH Zurich Zurich Switzerland [email protected]

Michael Schläpfer ETH Zurich Zurich Switzerland [email protected]

Dr. Patrick Schaller ETH Zurich Zurich Switzerland [email protected]

ISBN 978-3-642-24473-5 e-ISBN 978-3-642-24474-2 DOI 10.1007/978-3-642-24474-2 Springer Heidelberg Dordrecht London New York Library of Congress Control Number: 2011941698 ACM Classification (1998): K.6.5, K.4.4, D.4.6, E.3 © Springer-Verlag Berlin Heidelberg 2011 This work is subject to copyright. All rights are reserved, whether the whole or part of the material is concerned, specifically the rights of translation, reprinting, reuse of illustrations, recitation, broadcasting, reproduction on microfilm or in any other way, and storage in data banks. Duplication of this publication or parts thereof is permitted only under the provisions of the German Copyright Law of September 9, 1965, in its current version, and permission for use must always be obtained from Springer. Violations are liable to prosecution under the German Copyright Law. The use of general descriptive names, registered names, trademarks, etc. in this publication does not imply, even in the absence of a specific statement, that such names are exempt from the relevant protective laws and regulations and therefore free for general use. Cover design: deblik, Berlin Printed on acid-free paper Springer is part of Springer Science+Business Media (www.springer.com)

To our families for their support and to the members of the Institute of Information Security Group at ETH Zurich for their input and feedback.

Preface

Over the past decades, information security has emerged from being a specialist topic studied primarily by military cryptographers to being a general subject area relevant for every professional who wishes to better understand, develop, or use modern information and communication systems. Most courses on information security emphasize theory and basic concepts: cryptography, algorithms, protocols, models and selected applications. This is essential in providing the reader with a basic understanding of the subject. But information security is ultimately about getting your hands dirty and putting these ideas to work. That is where this book comes in. Our goal in writing this book is to provide a hands-on experimental counterpart to the more theoretically-oriented textbooks available. We approach information security from the perspective of a laboratory where students carry out experiments, much like they do in other courses such as physics or chemistry. Our aim is to help students better understand the theory they have learned by putting it directly to use and seeing first-hand the practical consequences and the subtleties involved. Just like with other lab courses, this book is not intended to be a replacement for a theory course and associated textbooks; it is complementary and has the aim of building on and extending the