Introduction xxix
CHAPTER 1: INTRODUCTION TO COMPUTER SECURITY 2
Introduction
How Seriously Should You Take Threats to Network Security?
Identifying Types of Threats
Assessing the Likelihood of an Attack on Your Network
Basic Security Terminology
Concepts and Approaches
How Do Legal Issues Impact Network Security?
Online Security Resources
Summary
CHAPTER 2: NETWORKS AND THE INTERNET 34
Introduction
Network Basics
How the Internet Works
History of the Internet
Basic Network Utilities
Other Network Devices
Advanced Network Communications Topics
Cloud Computing
Summary
CHAPTER 3: CYBER STALKING, FRAUD, AND ABUSE 74
Introduction
How Internet Fraud Works
Identity Theft
Cyber Stalking
Protecting Yourself Against Cybercrime
Summary
CHAPTER 4: DENIAL OF SERVICE ATTACKS 106
Introduction
DoS Attacks
Illustrating an Attack
Common Tools Used for DoS Attacks
DoS Weaknesses
Specific DoS Attacks
Real-World Examples of DoS Attacks
How to Defend Against DoS Attacks
Summary
CHAPTER 5: MALWARE 130
Introduction
Viruses
Trojan Horses
The Buffer-Overflow Attack
Spyware
Other Forms of Malware
Detecting and Eliminating Viruses and Spyware
Summary
CHAPTER 6: TECHNIQUES USED BY HACKERS 166
Introduction
Basic Terminology
The Reconnaissance Phase
Actual Attacks
Malware Creation
Penetration Testing
The Dark Web
Summary
CHAPTER 7: INDUSTRIAL ESPIONAGE IN CYBERSPACE 200
Introduction
What Is Industrial Espionage?
Information as an Asset
Real-World Examples of Industrial Espionage
How Does Espionage Occur?
Protecting Against Industrial Espionage
Trade Secrets
The Industrial Espionage Act
Spear Phishing
Summary
CHAPTER 8: ENCRYPTION 226
Introduction
Cryptography Basics
History of Encryption
Modern Cryptography Methods
Public Key (Asymmetric) Encryption
PGP
Legitimate Versus Fraudulent Encryption Methods
Digital Signatures
Hashing
MAC and HMAC
Steganography
Cryptanalysis
Cryptography Used on the Internet
Quantum Computing Cryptography
Summary
CHAPTER 9: COMPUTER SECURITY TECHNOLOGY 268
Introduction
Virus Scanners
Firewalls
Antispyware
IDSs
Digital Certificates
SSL/TLS
Virtual Private Networks
Wi-Fi Security
Summary
CHAPTER 10: SECURITY POLICIES 304
Introduction
What Is a Policy?
Important Standards
Defining User Policies
Defining System Administration Policies
Security Breaches
Defining Access Control
Development Policies
Standards, Guidelines, and Procedures
Disaster Recovery
Zero Trust
Important Laws
Summary
CHAPTER 11: NETWORK SCANNING AND VULNERABILITY SCANNING 336
Introduction
Basics of Assessing a System
Securing Computer Systems
Scanning Your Network
Testing and Scanning Standards
Getting Professional Help
Summary
CHAPTER 12: CYBER TERRORISM AND INFORMATION WARFARE 378
Introduction
Actual Cases of Cyber Terrorism
Weapons of Cyber Warfare
Economic Attacks
Military Operations Attacks
General Attacks
Supervisory Control and Data Acquisitions (SCADA)
Information Warfare
Actual Cases of Cyber Terrorism
Future Trends
Defense Against Cyber Terrorism
Terrorist Recruiting and Communication
TOR and the Dark Web
Summary
CHAPTER 13: CYBER DETECTIVE 408
Introduction
General Searches
Company Searches
Court Records and Criminal Checks
Usenet
Google
Maltego
Summary
CHAPTER 14: INTRODUCTION TO FORENSICS 426
Introduction
General Guidelines
Finding Evidence on a PC
Finding Evidence in System Logs
Getting Back Deleted Files
Operating System Utilities
The Windows Registry
Mobile Forensics: Cell Phone Concepts
The Need for Forensic Certification
Expert Witnesses
Additional Types of Forensics
Summary
CHAPTER 15: CYBERSECURITY ENGINEERING 466
Introduction
Defining Cybersecurity Engineering
Standards
SecML
Modeling
Summary
Glossary 494
Appendix A: Resources 500
Appendix B: Answers to the Multiple-Choice Questions 502