Kyle Rankin

Linux Hardening in Hostile Networks

Server Security from TLS to Tor. Empfohlen von 18 bis 67 Jahre. 1. Auflage. Electronic book text. Sprachen: Englisch
eBook (epub), 272 Seiten
EAN 9780134173320
Veröffentlicht Juli 2017
Verlag/Hersteller Pearson ITP

Auch erhältlich als:

Buch (Softcover)
37,50
36,99 inkl. MwSt.
Teilen
Beschreibung

Protect Linux systems against modern threats with practical, real-world security techniques. Linux Hardening in Hostile Networks equips system administrators, DevOps engineers, security professionals, and IT teams with the knowledge to secure workstations, servers, networks, and critical services in increasingly hostile online environments. From fundamental hardening practices to advanced defensive strategies, this guide explains how to reduce attack surfaces, secure Internet-facing infrastructure, and respond effectively when incidents occur. Covering everything from authentication and workstation security to web servers, email, DNS, databases, Tor, and TLS, this edition breaks down complex security concepts into clear, actionable steps. Each chapter progresses from essential protections suitable for any Linux environment through to advanced techniques designed to defend against sophisticated attackers. Readers will learn not only how to implement security controls, but also when they are appropriate, what risks they mitigate, and their practical limitations. - Apply core security techniques including 2FA and strong passwords - Protect admin workstations via lock screens, disk encryption, BIOS passwords, and other methods - Use the security-focused Tails distribution as a quick path to a hardened workstation - Compartmentalise workstation tasks into VMs with varying levels of trust - Harden servers with SSH, use apparmor and sudo to limit the damage attackers can do, and set up remote syslog servers to track their actions - Establish secure VPNs with OpenVPN, and leverage SSH to tunnel traffic when VPNs can't be used - Configure a software load balancer to terminate SSL/TLS connections and initiate new ones downstream - Set up standalone Tor services and hidden Tor services and relays - Secure Apache and Nginx web servers, and take full advantage of HTTPS - Perform advanced web server hardening with HTTPS forward secrecy and ModSecurity web application firewalls - Strengthen email security with SMTP relay authentication, SMTPS, SPF records, DKIM, and DMARC - Harden DNS servers, deter their use in DDoS attacks, and fully implement DNSSEC - Systematically protect databases via network access control, TLS traffic encryption, and encrypted data storage - Respond to a compromised server, collect evidence, and prevent future attacks

Portrait

Kyle Rankin is the vice president of engineering operations for Final, Inc.; the author of DevOps Troubleshooting, The Official Ubuntu Server Book, Knoppix Hacks, Knoppix Pocket Reference, Linux Multimedia Hacks, and Ubuntu Hacks; and a contributor to a number of other books. Rankin is an award-winning columnist for Linux Journal and has written for PC Magazine, TechTarget websites, and other publications. He speaks frequently on Open Source software, including a keynote at SCALE 11x and numerous other talks at SCALE, O'Reilly Security Conference, OSCON, CactusCon, Linux World Expo, Penguicon, and a number of Linux Users' Groups. In his free time Kyle does much of what he does at work-plays with Linux and computers in general. He's also interested in brewing, BBQing, playing the banjo, 3D printing, and far too many other hobbies.

Inhaltsverzeichnis

- 1. Overall Security Concepts - 2. Workstation Security - 3. Server Security - 4. Network - 5. Web Servers - 6. Email - 7. DNS - 8. Database - 9. Incident Response (alt title Hacked Server Forensics) - Appendices: - A. Tor - B. SSL/TLS - C. PGP

Technik
Sie können dieses eBook zum Beispiel mit den folgenden Geräten lesen:
• tolino Reader 
Laden Sie das eBook direkt über den Reader-Shop auf dem tolino herunter oder übertragen Sie das eBook auf Ihren tolino mit einer kostenlosen Software wie beispielsweise Adobe Digital Editions. 
• Sony Reader & andere eBook Reader 
Laden Sie das eBook direkt über den Reader-Shop herunter oder übertragen Sie das eBook mit der kostenlosen Software Sony READER FOR PC/Mac oder Adobe Digital Editions auf ein Standard-Lesegeräte. 
• Tablets & Smartphones 
Möchten Sie dieses eBook auf Ihrem Smartphone oder Tablet lesen, finden Sie hier unsere kostenlose Lese-App für iPhone/iPad und Android Smartphone/Tablets. 
• PC & Mac 
Lesen Sie das eBook direkt nach dem Herunterladen mit einer kostenlosen Lesesoftware, beispielsweise Adobe Digital Editions, Sony READER FOR PC/Mac oder direkt über Ihre eBook-Bibliothek in Ihrem Konto unter „Meine eBooks“ -  „Sofort online lesen über Meine Bibliothek“.
 
Bitte beachten Sie, dass die Kindle-Geräte das Format nicht unterstützen und dieses eBook somit nicht auf Kindle-Geräten lesbar ist.
Hersteller
Libri GmbH
Friedensallee 273

DE - 22763 Hamburg

E-Mail: GPSR@libri.de

Website: www.libri.de