´ë·®±¸¸ÅȨ >
ÄÄÇ»ÅÍ/ÀÎÅͳÝ
>
IT Àü¹®¼­
>
³×Æ®¿öÅ©
>
º¸¾È/ÇØÅ·

Ŭ¶ó¿ìµå ȯ°æÀÇ À¥ ÇØÅ·°ú ½ÃÅ¥¾îÄÚµù ŽÁö/¼öÁ¤ ½Ç½À°¡À̵å : À¥ ¸ðÀÇÇØÅ· ¹× ½ÃÅ¥¾îÄÚµù ½ÇÀü½Ç½À¿ë
Á¤°¡ 34,000¿ø
ÆǸŰ¡ 30,600¿ø (10% , 3,400¿ø)
I-Æ÷ÀÎÆ® 1,700P Àû¸³(6%)
ÆǸŻóÅ ÆǸÅÁß
ºÐ·ù º¸¾È/ÇØÅ·
ÀúÀÚ ÃÖ°æö , ±èÂùÁß , ÀÌÀºÁø , ÃÖ°æö , ±èÂùÁß, ÀÌÀºÁø
ÃâÆÇ»ç/¹ßÇàÀÏ SECUBOOK / 2021.03.02
ÆäÀÌÁö ¼ö 320 page
ISBN 9788996427582
»óÇ°ÄÚµå 346966607
°¡¿ëÀç°í Àç°íºÎÁ·À¸·Î ÃâÆÇ»ç ¹ßÁÖ ¿¹Á¤ÀÔ´Ï´Ù.
 
ÁÖ¹®¼ö·® :
´ë·®±¸¸Å Àü¹® ÀÎÅÍÆÄÅ© ´ë·®ÁÖ¹® ½Ã½ºÅÛÀ» ÀÌ¿ëÇÏ½Ã¸é °ßÀû¿¡¼­ºÎÅÍ ÇàÁ¤¼­·ù±îÁö Æí¸®ÇÏ°Ô ¼­ºñ½º¸¦ ¹ÞÀ¸½Ç ¼ö ÀÖ½À´Ï´Ù.
µµ¼­¸¦ °ßÀûÇÔ¿¡ ´ãÀ¸½Ã°í ½Ç½Ã°£ °ßÀûÀ» ¹ÞÀ¸½Ã¸é ±â´Ù¸®½Ç ÇÊ¿ä¾øÀÌ ÇÒÀιÞÀ¸½Ç ¼ö ÀÖ´Â °¡°ÝÀ» È®ÀÎÇÏ½Ç ¼ö ÀÖ½À´Ï´Ù.
¸ÅÁÖ ¹ß¼ÛÇØ µå¸®´Â ÀÎÅÍÆÄÅ©ÀÇ ½Å°£¾È³» Á¤º¸¸¦ ¹Þ¾Æº¸½Ã¸é »óÇ°ÀÇ ¼±Á¤À» ´õ¿í Æí¸®ÇÏ°Ô ÇÏ½Ç ¼ö ÀÖ½À´Ï´Ù.

 ´ë·®±¸¸ÅȨ  > ÄÄÇ»ÅÍ/ÀÎÅÍ³Ý  > IT Àü¹®¼­  > ³×Æ®¿öÅ©  > º¸¾È/ÇØÅ·

Ŭ¶ó¿ìµå ȯ°æÀÇ À¥ ÇØÅ·°ú ½ÃÅ¥¾îÄÚµù ŽÁö/¼öÁ¤ ½Ç½À°¡À̵å 30,600¿ø (10%)
ÆÐŶ Æ÷·»½Ä 27,000¿ø (10%)
        
 

 
¸ñÂ÷
Part 01 ½ÃÅ¥¾îÄÚµù ŽÁö ¹× ÄÚµå¼öÁ¤ Section 01 ¼Ò½ºÄÚµå Ãë¾àÁ¡ Á¡°Ë±âÁØ 1. CWE/SANS Top 25 Section 02 Ŭ¶ó¿ìµå ±â¹ÝÀÇ ½ÃÅ¥¾îÄÚµù ȯ°æ ÀÌÇØ 1. CI/CD ÆÄÀÌÇÁ¶óÀÎ 2. µ¥ºê¼½¿É½º(DevSecOps) Section 03 Ŭ¶ó¿ìµå ±â¹ÝÀÇ ½ÃÅ¥¾îÄÚµù ȯ°æ ±¸¼º 1. ¼³Ä¡ ¹× ȯ°æ¼³Á¤ 2. CI/CD ÆÄÀÌÇÁ¶óÀÎ ±¸¼º Section 04 ¸ðÀÇ°ø°Ý ¹× ½ÃÅ¥¾îÄÚµù ½Ç½À 1. SQL Injection 2. Path traversal 3. CRLF Injection 4. JWT(Json web token) º¯Á¶ 5. Áß¿ä µ¥ÀÌÅÍ Æò¹®Àü¼Û Ãë¾àÁ¡ 6. XXE 7. Insecure Direct Object References º¯Á¶ 8. XSS 9. Inseure deserialization 10. Vulnerable Components 11. Ãë¾àÇÑ ¾Ïȣȭ ¾Ë°í¸®Áò 12. ¿À·ù ¸Þ½ÃÁö¸¦ ÅëÇÑ Á¤º¸ ³ëÃâ Part 02 À¥ Ãë¾àÁ¡ ŽÁö ¹× ¸ðÀÇÇØÅ· Section 01 À¥ Ãë¾àÁ¡ Á¡°Ë±âÁØ 1. A1-Injection 2. A2-Broken authentication 3. A3-Sensitive data exposure 4. A4-XML External entities 5. A5-Broken access control 6. A6-Security misconfiguration 7. A7-XSS 8. A8-Insecure deserialization 9. A9-Using components with known vulnerabilities 10. A10-Insufficient logging & monitoring

ÀúÀÚ
ÃÖ°æö
ÇöÀç º¸¾ÈÃʺ¸½ºÅ͵ð(http://cafe.naver.com/sec)¿¡¼­ ¿î¿µÀÚ·Î È°µ¿ÁßÀ̸ç, ÁÖ¿ä°ü½ÉºÐ¾ß´Â Ãë¾àÁ¡ºÐ¼®ÅøÀÇ ÆÐÅÏ°ú ŽÁö±Ù°Å¿¡ ´ëÇÑ Á¶»çÀ̸ç, °ü·Ã ¿¬±¸¸¦ ÇмúÁö µî¿¡ ¹ßÇ¥ÇÏ¿´´Ù. °ü·ÃÀú¼­·Î´Â (À¥ ÇØÅ·°ú ¹æ¾î), (À¥ ¸ðÀÇÇØÅ· ¹× ½ÃÅ¥¾îÄÚµù Áø´Ü°¡À̵å), (½Ã½ºÅÛ ÇØÅ·ÀÇ ¿ø¸®¿Í ÀÌÇØ), (³×Æ®¿öÅ© ÆÐŶ Æ÷·»½Ä) ¹× (¾Èµå·ÎÀÌµå ¾Û Ãë¾àÁ¡ ºÐ¼®)ÀÌ ÀÖ´Ù.
   IT ¿£Áö´Ï¾î·Î »ç´Â ¹ý 1 | ÃÖ°æö | ºñÆҺϽº
   ½±°Ô ¹è¿ì´Â ¾Èµå·ÎÀÌµå ¾Û Ãë¾àÁ¡ Áø´Ü | ÃÖ°æö | SECU BOOK
±èÂùÁß
¾ÆÁÖ´ëÇб³ ¼®»çÁ¹¾÷(Á¤º¸º¸¾È Àü°ø) ÈÄ º¸¾ÈÀü¹®¾÷ü¿¡¼­ º¸¾È°üÁ¦, ¸ðÀÇÇØÅ· µîÀ» °æÇè ÇÏ¿´À¸¸ç ÇöÀç´Â SI¿Í °ü·ÃµÈ ¾÷¹«¸¦ ÁøÇàÇϸ鼭 ´Ù¾çÇÑ Áö½ÄÀ» ³ÐÇô°¡°í ÀÖ´Â ÁßÀÌ´Ù.
ÇöÀç Ŭ¶ó¿ìµå, ¸ðÀÇÇØÅ·, AIµî¿¡ °ü½ÉÀ» °¡Áö°í ÀÖÀ¸¸ç, ´Ù¾çÇÑ °æÇèÀ» ÅëÇØ ÀÚ½ÅÀÇ °¡Ä¡¸¦ ³ÐÇô°¡·Á°í »ý°¢ÇÏ°íÀÖ´Ù.
º¸¾È Ãʺ¸½ºÅ͵ð(https://cafe.naver.com/sec) ºÎ¸Þ´ÏÀú¸¦ ¸Ã°íÀÖ´Ù.
   ÆÐŶ Æ÷·»½Ä | ±èÂùÁß | SECU BOOK
ÀÌÀºÁø
1993³â °øÀåÀÚµ¿È­ °³¹ßÀÚ·Î ½ÃÀÛÇØ 2000³â ½ã¸¶ÀÌÅ©·Î½Ã½ºÅÛÁî Instructor·Î Àο¬À» ¸Î¾î J2EE ±â¹Ý ±â¼ú·ÎÀÇ º¯È­´Â Áö±Ý±îÁö IT ¾÷°è¿¡¼­ ÀÏÇÏ´Â ±â¹ÝÀÌ µÈµíÇÏ´Ù.
2015³â Æ®¸®´ÏƼ ¼ÒÇÁÆ®¿¡¼­ ¼ÒÇÁÆ®¿þ¾î º¸¾È Áø´Ü ÄÁ¼³Æà ¾÷¹«´Â °³ÀÎÀûÀÎ ±â¼úº¯È­ÀÇ °è±â°¡ µÇ¾ú°í °ü·Ã ¾÷¹«¿Í °­ÀǸ¦ Çϸ鼭 ¼ÒÇÁÆ®¿þ¾î º¸¾ÈÀº ¼ÒÇÁÆ®¿þ¾î °ü·ÃµÈ ¾ÆÅ°ÅØ, ¼³°èÀÚ, °³¹ßÀÚ, Å×½ºÅÍ, ¿î¿µÀÚ °¢ °¢ÀÌ Ãë¾àÁ¡À» ÀÌÇØÇÏ°í º¸¾ÈÀ» À§ÇÑ ¿ªÇÒÀ» ´ã´çÇÏ´Â °ÍÀÌ °¡Àå È¿À²ÀûÀ̶ó´Â »ý°¢Àº È®½ÇÇØÁø´Ù. Áö±ÝÀº Ŭ¶ó¿ìµå ±â¹ÝÀÇ MSA(Micro Service Architecture) °³¹ß¿¡ °ü½ÉÀ» °¡Áö°í °ü·ÃµÈ ¼ÒÇÁÆ®¿þ¾î º¸¾ÈÀ» °í¹ÎÇÏ°í ÀÖ´Ù.
ÀúÀÚ¿ÍÀÇ Àο¬À¸·Î º¸¾È¿¡ ´ëÇÑ ºÎÁ·ÇÑ ºÎºÐÀ» ä¿ì°í °³¹ß¿¡ ´ëÇÑ ³ëÇϿ츦 °øÀ¯ÇÒ ¼ö ÀÖ¾úÀ¸¸ç, ±â¼ú º¯È­ÀÇ È帧¿¡ ¸ÂÃç ²÷ÀÓ¾øÀÌ °í¹ÎÇÏ°í °øºÎÇÏ°í ÃâÆÇÀ» ÅëÇØ °øÀ¯ÇÏ´Â ÀúÀÚ¿Í ÇÔ²² ÀÏÇÒ ¼ö ÀÖ´Â ±âȸ°¡ ÁÖ¾îÁ® °¨»çÇÏ´Ù.
ÀÌ Ã¥Àº ¼ÒÇÁÆ®¿þ¾î ¾ÆÅ°ÅØ, ¼³°èÀÚ, °³¹ßÀÚ, Å×½ºÅÍ, ¿î¿µÀÚ¿¡°Ô Ãë¾àÁ¡À» ÀÌÇØÇϴµ¥ Å« µµ¿òÀÌ µÉ °ÍÀ̶ó »ý°¢Çϸç, ¼ÒÇÁÆ®¿þ¾î º¸¾È ´ã´çÇÏ´Â º¸¾È ´ã´çÀڵ鿡°Ô´Â º¸¾È ¾àÁ¡¿¡ ´ëÇÑ ÄÚµå ¼³¸í°ú ´ëÀÀ¹æ¾ÈÀÌ µµ¿òÀÌ µÉ °ÍÀ̶ó »ý°¢ÇÑ´Ù.
ÃÖ°æö
ÃÖ°æöÀº ¼þ½Ç´ëÇб³¸¦ Á¹¾÷ÇÏ°í µ¿ ´ëÇпø¿¡¼­ ¼®»çÇÐÀ§¸¦ ÃëµæÇÏ¿´À¸¸ç, ¾Æ½Ã¾Æ³ªÇ×°ø, Æ柽ÃÅ¥¸®Æ¼, STG½ÃÅ¥¸®Æ¼¸¦ °ÅÃÄ ÇöÀç Æ®¸®´ÏƼ¼ÒÇÁÆ®¿¡¼­ º¸¾È¼Ö·ç¼Ç °³¹ß°ú ±âȹÀ» ÇÏ°í ÀÖ´Ù. ÁÖ¿ä °ü½ÉºÐ¾ß·Î´Â Ãë¾àÁ¡ ºÐ¼® ÅøÀÇ ÆÐÅÏ°ú ŽÁö±Ù°Å¿¡ ´ëÇÑ Á¶»ç ¹× °³¹ßÀ̸ç, °ü·ÃµÈ ¿¬±¸¸¦ LNCS µîÀÇ ÇмúÁö¿¡ ³í¹®À¸·Î ¹ßÇ¥ÇÏ¿´´Ù. Àú¼­·Î´Â £¼À¥ º¸¾È£¾, £¼AutoInspect£¾, £¼À¥ ÇØÅ·°ú ¹æ¾î£¾, £¼½Ã½ºÅÛÇØÅ·ÀÇ ¿ø¸®¿Í ÀÌÇØ£¾µîÀÌ ÀÖ´Ù.
   ½±°Ô ¹è¿ì´Â ¾Èµå·ÎÀÌµå ¾Û Ãë¾àÁ¡ Áø´Ü | ÃÖ°æö | SECU BOOK
   ÆÐŶ Æ÷·»½Ä | ÃÖ°æö | SECU BOOK
±èÂùÁß, ÀÌÀºÁø
 
µµ¼­¸¦ ±¸ÀÔÇϽŠ°í°´ ¿©·¯ºÐµéÀÇ ¼­ÆòÀÔ´Ï´Ù.
ÀÚÀ¯·Î¿î ÀÇ°ß ±³È¯ÀÌ °¡´ÉÇÕ´Ï´Ù¸¸, ¼­ÆòÀÇ ¼º°Ý¿¡ ¸ÂÁö ¾Ê´Â ±ÛÀº »èÁ¦µÉ ¼ö ÀÖ½À´Ï´Ù.

µî·ÏµÈ ¼­ÆòÁß ºÐ¾ß¿Í »ó°ü¾øÀÌ ¸ÅÁÖ ¸ñ¿äÀÏ 5ÆíÀÇ ¿ì¼öÀÛÀ» ¼±Á¤ÇÏ¿©, S-Money 3¸¸¿øÀ» Àû¸³Çص帳´Ï´Ù.
ÃÑ 0°³ÀÇ ¼­ÆòÀÌ ÀÖ½À´Ï´Ù.