32 used & new from $0.01

Have one to sell? Sell yours here
 
 
Designing Secure Web-Based Applications for Microsoft Windows 2000 (DV-MPS Designing)
 
 
Tell the Publisher!
I’d like to read this book on Kindle

Don’t have a Kindle? Get your Kindle here.
 
  

Designing Secure Web-Based Applications for Microsoft Windows 2000 (DV-MPS Designing) (Paperback)

~ (Author)
4.6 out of 5 stars  See all reviews (15 customer reviews)


Available from these sellers.


10 new from $4.95 22 used from $0.01

Editorial Reviews

Amazon.com Review

"Web-based applications" is getting to be a redundant term, but that only highlights the fact that up-to-date programmers need to be familiar with the strategies and practices used to build modern networked software. Designing Secure Web-Based Applications for Microsoft Windows 2000 explains precisely what its title specifies: the mechanisms for allowing Windows programs to communicate over the network while maintaining security, plus their ways of fitting into complete product architectures. It's a complete engineering document with considerable information on identifying security threats, giving them relative weight, and deciding how to deal with them in the designs of your systems. The author has both done his homework and worked in the industry, and it's a pleasure to read his distilled knowledge.

Early sections are rather academic (which is not to say they're not worthwhile), while later sections deal with specific security strategies and the security features of particular products. The author isn't vague--he tells you how he thinks you should design your programs (storing hashes, instead of passwords, in a database to allow for intrusion into the database, for example) and what specifically you need to do (there's enough code here to give heft to what otherwise would be purely high-level advice). Although the author sticks to the Microsoft world, he isn't reluctant to point out security problems in Windows. This is a great volume for anyone designing Windows software that will share information over a network and need to use authentication, nonrepudiation, encryption, and other security techniques. --David Wall

Topics covered: Network security features of Windows 2000, Internet Explorer 5.0, SQL Server 7.0, SQL Server 2000, and COM+ 1.0, as well as the engineering tradeoffs involved in making software secure enough for safety, but open enough for reliability.

Product Description

Bullet-proof security is one of the strengths of Microsoft Windows 2000, but until now, no one has presented a complete picture of Windows 2000 Web server, component-level, and database security features and considerations. DESIGNING SECURE WEB-BASED APPLICATIONS FOR MICROSOFT WINDOWS 2000 offers an integrated, authoritative, pragmatic, end-to-end view of Windows 2000 security topics. The book starts by providing a solid foundation in Windows 2000 security theory and concepts, explaining the key software design considerations for various categories and levels of security, and showing how isolated security "islands" interact. It explains core security issues such as risk analysis, threats, authentication, authorization, and privacy, and then discusses ways to apply the appropriate security to an application to mitigate risk. It covers a range of security technologies such as NTLM authentication, Kerberos authentication, SSL/TLS, CryptoAPI, ACLs, Active Directory(tm), Certificates, Web security capabilities, and COM+ security. Finally, the author uses Web services, certificates, components, and database access to build a Web-based application (included on a companion CD) to show how Windows 2000 security features work in concert to protect applications and data.

Product Details

  • Paperback: 450 pages
  • Publisher: Microsoft Press (August 26, 2000)
  • Language: English
  • ISBN-10: 0735609950
  • ISBN-13: 978-0735609952
  • Product Dimensions: 9.2 x 7.4 x 1.4 inches
  • Shipping Weight: 2.3 pounds
  • Average Customer Review: 4.6 out of 5 stars  See all reviews (15 customer reviews)
  • Amazon.com Sales Rank: #1,519,032 in Books (See Bestsellers in Books)

More About the Author

Michael Howard
Discover books, learn about writers, read author blogs, and more.

Visit Amazon's Michael Howard Page

Look Inside This Book


Tag this product

 (What's this?)
Think of a tag as a keyword or label you consider is strongly related to this product.
Tags will help all customers organize and find favorite items.
Your tags: Add your first tag
 

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

 

Customer Reviews

15 Reviews
5 star:
 (13)
4 star:    (0)
3 star:
 (1)
2 star:    (0)
1 star:
 (1)
 
 
 
 
 
Average Customer Review
4.6 out of 5 stars (15 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
18 of 18 people found the following review helpful:
5.0 out of 5 stars This is NOT a rehash of Microsoft whitepapers or help files., September 7, 2000
By Jason Fossen (Dallas, Tx) - See all my reviews
This is the best IIS security book I've found yet, and I do Microsoft network security consulting for a living. Most IIS books simply rehash the IIS help files or Resource Kit-- this doesn't. Moreover, IIS 5.0 on Windows 2000 is substantially different than IIS 4.0 on NT, but nobody else I've read tackles the new heavy features like Kerberos authentication, digital certificate mapping to Active Directory, IPsec packet filtering for HTTP, distributed applications with COM+/DCOM, WMI, ADSI, etc.. The CD-ROM is also very useful; for example, it includes a Perl script which will search IIS logs for common attack signatures for intrusion detection. This book is written for security administrators and web-application developers. It has saved me MANY hours of trying to track down IIS 5.0 security internals that might not be documented anywhere else.
Help other customers find the most helpful reviews  
Was this review helpful to you? Yes No


 
10 of 10 people found the following review helpful:
5.0 out of 5 stars Excellent broad coverage, an easy read., November 25, 2000
By "bruce1055" (Moutain View, CA USA) - See all my reviews
The book covers a great deal of ground very quickly. Importantly, the material is easy to read and useful. While the focus is on Windows 2000-based technology, much of the book (most notably, threat modelling, and practical authentication, authorization, privacy and non-repudiation) can be applied to other non-MS technologies.

The really cool thing I like the most about the book is it is practical, rather then theoretical.

The book gave me ammunition to convince management that they need to spend time/money/resources to insure a secure system, and then the book showed me how to choose appropriate technologies to solve security problems.

Help other customers find the most helpful reviews  
Was this review helpful to you? Yes No


 
8 of 8 people found the following review helpful:
5.0 out of 5 stars Worth every Penny, November 5, 2000
By Aaron (Berlin, Germany) - See all my reviews
A great source of wisdom if you build or deploy web-sites. Well written, greath depth and most of all - easy to read. There is lots of new information previously unpublished.

It explains how to design, build, and deploy secure systems without resorting to scare-tactics.

Help other customers find the most helpful reviews  
Was this review helpful to you? Yes No

Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews

5.0 out of 5 stars Best book I read on the subject
enjoyable and very informative
Published on February 23, 2003 by Jakubovitz Itzhak

5.0 out of 5 stars Very beneficial.
I had no background in networking and Windows security. This book allowed me to understand how to employ security in Windows distributed applications. Read more
Published on June 20, 2002

5.0 out of 5 stars The most complete web application security on the market
This book covers all issues pertaining to building and securing web applications. From the browser all the way to the database server. Read more
Published on May 8, 2001 by mike332

5.0 out of 5 stars Exceptional
Incredible security coverage of IIS, Windows 2000, COM+, IE and SQL Server. The best IIS security book out there. But it focuses on other topics, not just IIS.
Published on April 26, 2001 by Pete

1.0 out of 5 stars Worse than nothing
Probably the worse book I've read on IIS security. This is what the books says on setting File security on your web: "use the wizard". Read more
Published on April 23, 2001

3.0 out of 5 stars Great if you're new to MS Security but not enough for others
I was dissapointed with this book because it did not go to the depth a developer would need to make the most of the Windows 2000/NT security technologies. Read more
Published on November 22, 2000

5.0 out of 5 stars It Answered Many Questions!
I have always thought that n-tier security was next to impossible. This books proves it isn't. The book discusses the pros and cons of various ways of building secure n-tier... Read more
Published on October 31, 2000

5.0 out of 5 stars Superb!
The best book I've read regarding web security. Covers a lot of ground, quickly and logically. I didn't realise there was so much to learn. Read more
Published on October 31, 2000

5.0 out of 5 stars Superb!
Simply put - I learned more about security from this book than any other book I have previously read. Read more
Published on October 23, 2000 by harryw@earthlink.net

5.0 out of 5 stars EXCELLENT-Highly Recommended
I've read many books about computer and network security, and this blows away all of them. It's easy to read, extremeley pragmatic and, as far as I know, it is the ONLY BOOK that... Read more
Published on October 11, 2000 by MarkR

Only search this product's reviews



Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 

Search Customer Discussions
Search all Amazon discussions
   


Listmania!


Create a Listmania! list

So You'd Like to...


Create a guide

Product Information from the Amapedia Community

Beta (What's this?)


Look for Similar Items by Category


Look for Similar Items by Subject

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.



Your Recent History

 (What's this?)

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.