{"product_id":"cyber-vigilance-and-digital-trust-cyber-security-in-the-era-of-cloud-computing-and-iot-hardback-9781786304483","title":"Cyber-Vigilance and Digital Trust; Cyber Security in the Era of Cloud Computing and IoT (Hardback) 9781786304483","description":"\u003cfont face=\"Georgia\"\u003e\r\n\u003cp\u003e\u003cfont size=\"6\"\u003eCyber-Vigilance and Digital Trust\u003c\/font\u003e\u003cbr\u003e\r\n\u003cfont size=\"5\"\u003eCyber Security in the Era of Cloud Computing and IoT\u003c\/font\u003e\u003c\/p\u003e\r\n\r\n\r\n\r\n\r\n\u003cp\u003e\u003cfont size=\"4\"\u003eWiem Tounsi (Edited by), W Tounsi (Author)\u003c\/font\u003e\u003c\/p\u003e\r\n\r\n\u003cp\u003e\u003cfont size=\"3\"\u003e9781786304483, Wiley\u003c\/font\u003e\u003c\/p\u003e\r\n\r\n\u003cp\u003e\u003cfont size=\"3\"\u003eHardback, published 10 May 2019\u003c\/font\u003e\u003c\/p\u003e\r\n\r\n\u003cp\u003e\u003cfont size=\"3\"\u003e256 pages\u003cbr\u003e23.6 x 16 x 2 cm, 0.544 kg\u003c\/font\u003e\u003c\/p\u003e\r\n\r\n\r\n\r\n\r\n\r\n\u003cp align=\"justify\"\u003e\u003cstrong\u003e\u003cfont size=\"3\"\u003eCyber threats are ever increasing. Adversaries are getting more sophisticated and cyber criminals are infiltrating companies in a variety of sectors. In today’s landscape, organizations need to acquire and develop effective security tools and mechanisms – not only to keep up with cyber criminals, but also to stay one step ahead.\u003cbr\u003e \u003cbr\u003e Cyber-Vigilance and Digital Trust develops cyber security disciplines that serve this double objective, dealing with cyber security threats in a unique way. Specifically, the book reviews recent advances in cyber threat intelligence, trust management and risk analysis, and gives a formal and technical approach based on a data tainting mechanism to avoid data leakage in Android systems\u003c\/font\u003e\u003c\/strong\u003e\u003c\/p\u003e\r\n\r\n\u003cp\u003e\u003cfont size=\"3\"\u003e\u003cp\u003e\u003cb\u003eIntroduction ix\u003c\/b\u003e\u003cbr\u003e \u003ci\u003eWiem TOUNSI\u003c\/i\u003e\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 1. What Is Cyber Threat Intelligence and How Is It Evolving? \u003c\/b\u003e\u003cb\u003e1\u003cbr\u003e \u003c\/b\u003e\u003ci\u003eWiem TOUNSI\u003c\/i\u003e\u003c\/p\u003e \u003cp\u003e1.1. Introduction 1\u003c\/p\u003e \u003cp\u003e1.2. Background 3\u003c\/p\u003e \u003cp\u003e1.2.1. New Generation Threats 3\u003c\/p\u003e \u003cp\u003e1.2.2. Analytical Frameworks 6\u003c\/p\u003e \u003cp\u003e1.3. Cyber Threat Intelligence 9\u003c\/p\u003e \u003cp\u003e1.3.1. Cyber Threat Intelligence Sources 9\u003c\/p\u003e \u003cp\u003e1.3.2. Cyber Threat Intelligence Sub-Domains 11\u003c\/p\u003e \u003cp\u003e1.3.3. Technical Threat Intelligence (TTI) 13\u003c\/p\u003e \u003cp\u003e1.4. Related Work 14\u003c\/p\u003e \u003cp\u003e1.5. Technical Threat Intelligence Sharing Problems 16\u003c\/p\u003e \u003cp\u003e1.5.1. Benefits of CTI Sharing for Collective Learning 16\u003c\/p\u003e \u003cp\u003e1.5.2. Reasons for Not Sharing 17\u003c\/p\u003e \u003cp\u003e1.6. Technical Threat Intelligence Limitations 21\u003c\/p\u003e \u003cp\u003e1.6.1. Quantity Over Quality 21\u003c\/p\u003e \u003cp\u003e1.6.2. IOC-Specific Limitations 22\u003c\/p\u003e \u003cp\u003e1.7. Cyber Threat Intelligent Libraries or Platforms 25\u003c\/p\u003e \u003cp\u003e1.7.1. Benefits of CTI Libraries Based In the Cloud 26\u003c\/p\u003e \u003cp\u003e1.7.2. Reluctance to Use Cloud Services 26\u003c\/p\u003e \u003cp\u003e1.8. Discussion 27\u003c\/p\u003e \u003cp\u003e1.8.1. Sharing Faster Is Not Sufficient 27\u003c\/p\u003e \u003cp\u003e1.8.2. Reducing the Quantity of Threat Feeds 28\u003c\/p\u003e \u003cp\u003e1.8.3. Trust to Share Threat Data and to Save Reputation Concerns 30\u003c\/p\u003e \u003cp\u003e1.8.4. Standards for CTI Representation and Sharing 31\u003c\/p\u003e \u003cp\u003e1.8.5. Cloud-Based CTI Libraries for Collective Knowledge and Immunity 34\u003c\/p\u003e \u003cp\u003e1.9. Evaluation of Technical Threat Intelligence Tools 36\u003c\/p\u003e \u003cp\u003e1.9.1. Presentation of Selected Tools 37\u003c\/p\u003e \u003cp\u003e1.9.2. Comparative Discussion 38\u003c\/p\u003e \u003cp\u003e1.10. Conclusion and Future Work 39\u003c\/p\u003e \u003cp\u003e1.11. References 40\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 2. Trust Management Systems: A Retrospective Study on Digital Trust \u003c\/b\u003e\u003cb\u003e51\u003cbr\u003e \u003c\/b\u003e\u003ci\u003eReda YAICH\u003c\/i\u003e\u003c\/p\u003e \u003cp\u003e2.1. Introduction 51\u003c\/p\u003e \u003cp\u003e2.2. What Is Trust? 52\u003c\/p\u003e \u003cp\u003e2.3. Genesis of Trust Management Systems 54\u003c\/p\u003e \u003cp\u003e2.3.1. Access Control Model 54\u003c\/p\u003e \u003cp\u003e2.3.2. Identity-Based Access Control 55\u003c\/p\u003e \u003cp\u003e2.3.3. Lattice-Based Access Control 57\u003c\/p\u003e \u003cp\u003e2.3.4. Role-Based Access Control 58\u003c\/p\u003e \u003cp\u003e2.3.5. Organization-Based Access Control 59\u003c\/p\u003e \u003cp\u003e2.3.6. Attribute-Based Access Control 61\u003c\/p\u003e \u003cp\u003e2.4. Trust Management 62\u003c\/p\u003e \u003cp\u003e2.4.1. Definition 62\u003c\/p\u003e \u003cp\u003e2.4.2. Trust Management System 64\u003c\/p\u003e \u003cp\u003e2.4.3. Foundations 65\u003c\/p\u003e \u003cp\u003e2.4.4. Automated Trust Negotiation 70\u003c\/p\u003e \u003cp\u003e2.5. Classification of Trust Management Systems 72\u003c\/p\u003e \u003cp\u003e2.5.1. Authorization-Based TMSs 73\u003c\/p\u003e \u003cp\u003e2.5.2. Automated Trust Negotiation Systems 81\u003c\/p\u003e \u003cp\u003e2.6. Trust Management In Cloud Infrastructures 90\u003c\/p\u003e \u003cp\u003e2.6.1. Credentials-Based Trust Models 90\u003c\/p\u003e \u003cp\u003e2.6.2. SLA-Based Trust Models 90\u003c\/p\u003e \u003cp\u003e2.6.3. Feedback-Based Trust Models 91\u003c\/p\u003e \u003cp\u003e2.6.4. Prediction-Based Trust Models 92\u003c\/p\u003e \u003cp\u003e2.7. Conclusion 93\u003c\/p\u003e \u003cp\u003e2.8. References 94\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 3. Risk Analysis Linked to Network Attacks \u003c\/b\u003e\u003cb\u003e105\u003cbr\u003e \u003c\/b\u003e\u003ci\u003eKamel KAROUI\u003c\/i\u003e\u003c\/p\u003e \u003cp\u003e3.1. Introduction 105\u003c\/p\u003e \u003cp\u003e3.2. Risk Theory 107\u003c\/p\u003e \u003cp\u003e3.2.1. Risk Analysis Terminology 107\u003c\/p\u003e \u003cp\u003e3.2.2. Presentation of the Main Risk Methods 109\u003c\/p\u003e \u003cp\u003e3.2.3. Comparison of the Main Methods 116\u003c\/p\u003e \u003cp\u003e3.3. Analysis of IS Risk In the Context of IT Networks 120\u003c\/p\u003e \u003cp\u003e3.3.1. Setting the Context 120\u003c\/p\u003e \u003cp\u003e3.3.2. Risk Assessment 127\u003c\/p\u003e \u003cp\u003e3.3.3. Risk Treatment 133\u003c\/p\u003e \u003cp\u003e3.3.4. Acceptance of Risks 136\u003c\/p\u003e \u003cp\u003e3.3.5. Risk Communication 137\u003c\/p\u003e \u003cp\u003e3.3.6. Risk Monitoring 138\u003c\/p\u003e \u003cp\u003e3.4. Conclusion 138\u003c\/p\u003e \u003cp\u003e3.5. References 138\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 4. Analytical Overview on Secure Information Flow In Android Systems: Protecting Private Data Used By Smartphone Applications \u003c\/b\u003e\u003cb\u003e141\u003cbr\u003e \u003c\/b\u003e\u003ci\u003eMariem GRAA\u003c\/i\u003e\u003c\/p\u003e \u003cp\u003e4.1. Introduction 142\u003c\/p\u003e \u003cp\u003e4.2. Information Flow 143\u003c\/p\u003e \u003cp\u003e4.2.1. Explicit Flows 143\u003c\/p\u003e \u003cp\u003e4.2.2. Implicit Flows 143\u003c\/p\u003e \u003cp\u003e4.2.3. Covert Channels 144\u003c\/p\u003e \u003cp\u003e4.3. Data Tainting 145\u003c\/p\u003e \u003cp\u003e4.3.1. Interpreter Approach 145\u003c\/p\u003e \u003cp\u003e4.3.2. Architecture-Based Approach 146\u003c\/p\u003e \u003cp\u003e4.3.3. Static Taint Analysis 146\u003c\/p\u003e \u003cp\u003e4.3.4. Dynamic Taint Analysis 147\u003c\/p\u003e \u003cp\u003e4.4. Protecting Private Data In Android Systems 149\u003c\/p\u003e \u003cp\u003e4.4.1. Access Control Approach 149\u003c\/p\u003e \u003cp\u003e4.4.2. Preventing Private Data Leakage Approach 153\u003c\/p\u003e \u003cp\u003e4.4.3. Native Libraries Approaches 157\u003c\/p\u003e \u003cp\u003e4.5. Detecting Control Flow 160\u003c\/p\u003e \u003cp\u003e4.5.1. Technical Control Flow Approaches 160\u003c\/p\u003e \u003cp\u003e4.5.2. Formal Control Flow Approaches 162\u003c\/p\u003e \u003cp\u003e4.6. Handling Explicit and Control Flows In Java and Native Android Appsʼ Code 164\u003c\/p\u003e \u003cp\u003e4.6.1. Formal Specification of the Under-Tainting Problem 164\u003c\/p\u003e \u003cp\u003e4.6.2. Formal Under-Tainting Solution 166\u003c\/p\u003e \u003cp\u003e4.6.3. System Design 175\u003c\/p\u003e \u003cp\u003e4.6.4. Handling Explicit and Control Flows In Java Android Appsʼ Code 176\u003c\/p\u003e \u003cp\u003e4.6.5. Handling Explicit and Control Flows In Native Android Appsʼ Code 180\u003c\/p\u003e \u003cp\u003e4.6.6. Evaluation 184\u003c\/p\u003e \u003cp\u003e4.6.7. Discussion 187\u003c\/p\u003e \u003cp\u003e4.7. Protection Against Code Obfuscation Attacks Based on Control Dependencies In Android Systems 188\u003c\/p\u003e \u003cp\u003e4.7.1. Code Obfuscation Definition 188\u003c\/p\u003e \u003cp\u003e4.7.2. Types of Program Obfuscations 189\u003c\/p\u003e \u003cp\u003e4.7.3. Obfuscation Techniques 189\u003c\/p\u003e \u003cp\u003e4.7.4. Code Obfuscation In Android System 190\u003c\/p\u003e \u003cp\u003e4.7.5. Attack Model 191\u003c\/p\u003e \u003cp\u003e4.7.6. Code Obfuscation Attacks 192\u003c\/p\u003e \u003cp\u003e4.7.7. Detection of Code Obfuscation Attacks 194\u003c\/p\u003e \u003cp\u003e4.7.8. Obfuscation Code Attack Tests 195\u003c\/p\u003e \u003cp\u003e4.8. Detection of Side Channel Attacks Based on Data Tainting In Android Systems 198\u003c\/p\u003e \u003cp\u003e4.8.1. Target Threat Model 199\u003c\/p\u003e \u003cp\u003e4.8.2. Side Channel Attacks 200\u003c\/p\u003e \u003cp\u003e4.8.3. Propagation Rules for Detecting Side Channel Attacks 203\u003c\/p\u003e \u003cp\u003e4.8.4. Implementation 205\u003c\/p\u003e \u003cp\u003e4.8.5. Evaluation 207\u003c\/p\u003e \u003cp\u003e4.9. Tracking Information Flow In Android Systems Approaches Comparison: Summary 210\u003c\/p\u003e \u003cp\u003e4.10. Conclusion and Highlights 215\u003c\/p\u003e \u003cp\u003e4.11. References 216\u003c\/p\u003e \u003cp\u003eList of Authors 227\u003c\/p\u003e \u003cp\u003eIndex 229\u003c\/p\u003e\u003c\/font\u003e\u003c\/p\u003e\r\n\r\n\u003cp\u003e\u003cfont size=\"3\"\u003eSubject Areas: Computer science [\u003ca title=\"See our other books on Computer science\" href=\"https:\/\/freshlyprintedbooks.co.uk\/search?q=%22Computer%20science%20%5BUY%5D%22\"\u003eUY\u003c\/a\u003e]\u003c\/font\u003e\u003c\/p\u003e\r\n\r\n\r\n\u003c\/font\u003e","brand":"Wiley-ISTE","offers":[{"title":"Brand New","offer_id":52446735532312,"sku":"9781786304483","price":105.96,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0730\/2037\/5320\/files\/9781786304483.jpg?v=1785112475","url":"https:\/\/freshlyprintedbooks.co.uk\/products\/cyber-vigilance-and-digital-trust-cyber-security-in-the-era-of-cloud-computing-and-iot-hardback-9781786304483","provider":"Freshly Printed Books","version":"1.0","type":"link"}