Computer security is more than a collection of protective tools: it is also the study of what a system should protect, whom it should trust, and how its rules work in practice. In Computer Security: Art and Science, Matt Bishop develops that perspective across the field, linking rigorous foundations to the policies and mechanisms used to secure real systems.
This second edition ranges from access-control models and confidentiality policies to cryptography, authentication, system design, and the analysis of attacks. Its detailed treatment suits readers who want to understand not just which security mechanisms exist, but the reasoning behind them.
Start with the principles behind security
The opening sections establish core concepts such as security goals, assumptions, trust, policy, and mechanism. From there, the book examines formal foundations, including access-control matrices and protection models. These ideas give readers a framework for reasoning about permissions, privilege, and the properties a system can—or cannot—guarantee.
Connect policy to system behavior
Security policies shape how information is protected and how users and systems may act. Bishop explores policy models for confidentiality, integrity, and availability, along with hybrid approaches and questions of policy composition. The emphasis on both rules and their implementation helps make clear why a carefully stated policy still needs mechanisms that enforce it accurately.
Explore the tools and techniques
Later sections address cryptography and key management, ciphers, authentication, identity, and access-control mechanisms. The book also considers system design and practical security concerns such as malware, vulnerabilities, auditing, and intrusion detection. Together, these subjects show how security depends on interacting choices rather than on any single technology.
For readers ready for depth
The scope and formal material make this a substantial text for advanced undergraduate and graduate study, and a detailed reference for IT professionals. Readers looking for a quick checklist may find its theoretical approach more extensive than they need; those seeking a structured account of computer-security concepts and their practical implications will find much to examine.
With its blend of models, policy, and implementation, this edition offers a serious foundation for understanding how computer security is reasoned about—and how those ideas are applied.
User Reviews
Only logged in customers who have purchased this product may leave a review.
Original price was: $91.99.$45.99Current price is: $45.99.


There are no reviews yet.