Skip to content


Book

Securing the Virtual Environment: How to Defend the Enterprise Against Attack (Includes Bonus DVD)

A book by Davi Ottenheimer and Matthew Wallace
May 2012

John Wiley & Sons
ISBN: 978-1118155486
Hardcover US $49.99
Kindle US $32.99

Ordering

Order in hardcover: Book Depository | Powell's | Amazon | Barnes & Noble | Wiley

Order as an e-book: Amazon | Barnes & Noble | Wiley

Find the book in a library

Reviews and Responses

  • "Anyone who is serious about virtualization security should certainly make sure that Securing the Virtual Environment: How to Defend the Enterprise Against Attack is on their reading list, and that of every security administrator in their company." (Ben Rothke, InfoSec Mgr Wyndham Worldwide Corp, May 2012)
  • "Anyone who needs to understand virtualization security theory and attack strategy should pick up this book, without a doubt." (David Shackleford, principal consultant at Voodoo Security and author of "Virtualization Security: Protecting Virtualized Environments," June 2012)
  • "Definitely a recommended read for security professionals needing a substantial and solid introduction to what "security" actually involves in the cloud and other virtualized environments." (Richard Austin, HP Security Engineer, September 2012)

From the Back Cover

Your virtual environment might be a prime target for hackers and attackers who want to steal data or exploit your resources. This book arms you with the knowledge and tools to safeguard your virtual and cloud environments against external and internal threats. You'll gain insight into how to avoid denial of service, log and audit activity, protect virtual networks from eavesdroppers, and harden virtual servers. If your job involves protecting assets in virtual and cloud environments, this book will be invaluable to you.

  • Perform vulnerability assessments of your virtual environment to uncover security weaknesses
  • Learn how attacks in a virtual model differ from traditional computing models and how to best use technology and processes to defend yourself
  • Learn how attackers use and abuse APIs to manipulate and gain entry to virtual environments
  • Understand the risks of Software as a Service and how to get the protection you must have
  • Be ready for audits by ensuring that your virtual and cloud environments comply with standards and regulations such as PCI DSS and ISO 27001
  • Build your own low-budget virtualized test lab for hands-on evaluation of attacks and to practice prevention and response

On the DVD

Use the files on the DVD to follow along with the hands-on examples, or use them as the basis for your own code. Using the code and the book, you can

  • Conduct a "hypervisor escape", breaking out of a virtual machine into the host system
  • Load the included, ready-made penetration testing virtual machine—which is preloaded with tools such as nmap, ettercap, the Open VAS vulnerability scanner, and more—directly into your virtual environment
  • Test the security posture of your Xen or VMware environment using automated scripts that peek at virtual disks and copy or modify virtual machines
  • See the code used for hands-on exercises in the book that audit or attack virtual environments

0 Responses

Stay in touch with the conversation, subscribe to the RSS feed for comments on this post.



Some HTML is OK

or, reply to this post via trackback.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word