- عنوان کتاب: Windows System Security Foundations Hands-On Fundamentals for Identity, Access, and Process Control
- نویسنده: Mike O’Leary
- حوزه: امنیت ویندوز
- سال انتشار: 2026
- تعداد صفحه: 523
- زبان اصلی: انگلیسی
- نوع فایل: pdf
- حجم فایل: 5.18 مگابایت
متخصصان تازهکار اغلب برای پر کردن شکاف بین دانش آکادمیک و نظری از یک سو و مهارتهای عملی، کاربردی و عملی مورد نیاز هنگام نشستن پشت صفحه کلید، به کمک نیاز دارند. هدف این کتاب، کمک به خوانندگان در یادگیری عملیات سایبری و توسعه مهارتهای حل مسئله امنیتی است. این کتاب حاصل 20 سال تجربه تدریس عملی دورههای امنیت سایبری به دانشجویان کارشناسی و کارشناسی ارشد است که بسیاری از آنها الهامبخش و بازخورد ارائه دادهاند. تمرکز این کتاب بر امنیت سیستمها و سرورهای ویندوز است؛ پیکربندی و امنیت دامنههای Active Directory را در نظر نمیگیرد. از آنجا که سیستمهای ویندوز میتوانند و اغلب از Active Directory برای احراز هویت و مدیریت کاربر استفاده میکنند، این اجزای Active Directory در صورت نیاز مورد بحث قرار میگیرند. این کتاب با مقدمهای بر PowerShell آغاز میشود که معمولاً توسط مهاجمان و مدیران استفاده میشود. این کتاب ویژگیها و پیکربندی PowerShell مورد علاقه مهاجمان و مدافعان، مانند نحوه ثبت تاریخچه PowerShell، نحوه ایجاد اسکریپتهای مبهم PowerShell و نحوه مدیریت اعتبارنامهها توسط PowerShell را پوشش میدهد. این کتاب با کاربران و گروههای محلی و دامنه در سیستمهای ویندوز ادامه مییابد. وقتی کاربری وارد سیستم ویندوز میشود، فرآیند ورود به سیستم را طی میکند و یک (یا دو) توکن دسترسی به او اختصاص داده میشود؛ این موضوع توضیح داده شده است. به طور مشابه، وقتی کاربری میخواهد از اعتبارنامههای مدیریتی استفاده کند یا به عنوان کاربر دیگری عمل کند، از کنترل حساب کاربری (UAC) عبور میکند؛ این موضوع نیز توضیح داده شده است. ویندوز هشهای رمز عبور کاربران محلی را در پایگاه داده مدیر حسابهای امنیتی (SAM) ذخیره میکند، در حالی که هشهای رمز عبور کاربران دامنه در فروشگاه داده اکتیو دایرکتوری (ntds.dit) قرار دارند. کاربران ممتاز میتوانند به این هشها دسترسی داشته باشند و مهاجمان میتوانند هشها را با ابزارهایی مانند John the Ripper بشکنند. ویندوز بر اساس عضویت در گروههای کاربر، حقوق و امتیازاتی اعطا میکند. متن این گروههای مهم محلی و دامنه و همچنین حقوق و امتیازات فردی را بررسی میکند. سیستم فایل ویندوز پوشش داده شده است، از اصول اولیه شروع میشود و با میانبرها، پیوندها، اتصالات، پیوندهای نمادین، جریانهای داده جایگزین و علامت وب ادامه مییابد. کنترل دسترسی، از جمله تکنیکهای مشاهده و اصلاح لیستهای کنترل دسترسی اختیاری (DACL) شرح داده شده است. ساختار رجیستری و ابزارهایی برای بررسی آن ارائه شده است. فرآیندهای ویندوز، از جمله ابزارهایی برای مشاهده و مدیریت فرآیندهای ویندوز، بررسی میشوند. مفهوم یکپارچگی فرآیند شرح داده شده و با UAC مرتبط است و فرآیندهای کلیدی بوت ویندوز توضیح داده میشوند. سرویسهای ویندوز و ابزارهای مدیریت سرویسهای ویندوز شرح داده شدهاند. متن شامل بیش از ۲۰۰ تمرین با سطوح مختلف دشواری است که میتواند توسط یک مدرس که از کتاب به عنوان کتاب درسی استفاده میکند یا توسط یک خواننده باانگیزه که میخواهد مباحث مطرح شده در متن را تمرین کند، مورد استفاده قرار گیرد. خوانندگان باید با ویندوز در سطح کاربر عملیاتی عملی آشنا باشند و باید با دامنهها و کنترلکنندههای دامنه ویندوز آشنا باشند. این کتاب فرض میکند که خواننده اصول اولیه شبکههای کامپیوتری، از جمله IP، TCP و UDP را درک میکند. فرض بر این است که خوانندگان برنامهنویسان ماهری در زبانهای مختلف هستند؛ چندین زبان در سراسر متن استفاده شده است. من دریافتهام که دانشجویان علوم کامپیوتر دانشگاههای آمریکایی در سال سوم یا چهارم خود، بیشتر پیشزمینه مورد نیاز را به خوبی درک میکنند. خوانندگان باید برای آزمایش و تجربه و تکمیل تمرینهای مختلف به سیستمهای ویندوز دسترسی داشته باشند. یک راه برای ساخت یک آزمایشگاه آزمایش، مجازیسازی است. این به کاربران اجازه میدهد تا یک یا چند سیستم کامل، به نام مهمان، را درون سیستم دیگری به نام میزبان شبیهسازی کنند.
Early-career professionals often need help to bridge the gap between academic and theoretical knowledge on one hand and the practical, hands-on, actionable skills needed when sitting at the keyboard. The purpose of this book is to lend a helping hand to readers learning cyber operations and developing security problem-solving skills. This is the result of 20 years of experience teaching hands-on cybersecurity courses to undergraduate and graduate students, many of whom have provided inspiration and feedback. The focus of this book is on the security of Windows systems and servers; it does not consider the configuration and security of Active Directory domains. Because Windows systems can and often use Active Directory for authentication and user management, these components of Active Directory are discussed as needed. The book starts with an introduction to PowerShell, which is commonly used by attackers and administrators. It covers features and configuration of PowerShell of interest to attackers and defenders, like how PowerShell history is recorded, how to create obfuscated PowerShell scripts, and how PowerShell manages credentials. The book continues with local and domain users and groups on Windows systems. When a user logs onto a Windows system, they go through the logon process and are assigned one (or two) access tokens; this is explained. Similarly, when a user wants to use administrative credentials or act as another user, they pass through User Account Control (UAC); this is also explained. Windows stores password hashes for local users in the Security Accounts Manager (SAM) database, while password hashes for domain users are in the Active Directory Data Store (ntds.dit). Privileged users can access these hashes, and attackers can crack the hashes with tools like John the Ripper. Windows grants rights and privileges based on a user’s group memberships; the text reviews these important local and domain groups as well as the individual rights and privileges. The Windows file system is covered, beginning with the basics, continuing with shortcuts, links, junctions, symbolic links, alternate data streams, and the Mark of the Web. Access control is described, including the techniques to view and modify Discretionary Access Control Lists (DACLs). The structure of the registry and tools to examine it are provided. Windows processes are examined, including tools to view and manage Windows processes. The notion of process integrity is described and related to UAC, and the key Windows boot processes are explained. Windows services and the tools to manage Windows services are described. The text includes more than 200 exercises at various levels of difficulty that can be used by an instructor using the book as a textbook or by a motivated reader who wants to practice the topics covered in the text. Readers should be familiar with Windows at a practical operational user level and should be familiar with Windows domains and domain controllers. The book assumes that the reader understands the basics of computer networking, including IP, TCP, and UDP. Readers are assumed to be competent programmers in a variety of languages; several are used throughout the text. I have found that American university computer science students in their third or fourth years well understand most of the required background. Readers should have access to Windows systems for testing and experimentation and to complete the various exercises. One way to build a testing laboratory is with virtualization. This allows users to emulate one or more complete systems, called guests, inside another, called the host.
این کتاب را میتوانید از لینک زیر بصورت رایگان دانلود کنید:
Download: Windows System Security





نظرات کاربران