Intrusion Signatures and Analysis

Intrusion Signatures and Analysis

Intrusion Signatures and Analysis

more information about Intrusion Signatures and Analysis

Editorial Reviews
Amazon.com
Stephen Northcutt and his coauthors note in the superb Intrusion Signatures and Analysis that there's really no such thing as an attack that's never been seen before. The book documents scores of attacks on systems of all kinds, showing exactly what security administrators should look for in their logs and commenting on attackers' every significant command. This is largely a taxonomy of hacker strategies and the tools used to implement them. As such, it's an essential tool for people who want to take a scientific, targeted approach to defending information systems. It's also a great resource for security experts who want to earn their Certified Intrusion Analyst ratings from the Global Incident Analysis Center (GIAC)--it's organized, in part, around that objective.

The book typically introduces an attack strategy with a real-life trace--usually attributed to a real administrator--from TCPdump, Snort, or some sort of firewall (the trace's source is always indicated). The trace indicates what is happening (i.e., what weakness the attacker is trying to exploit) and the severity of the attack (using a standard metric that takes into account the value of the target, the attack's potential to do damage, and the defenses arrayed against the attack). The attack documentation concludes with recommendations on how defenses could have been made stronger. These pages are great opportunities to learn how to read traces and take steps to strengthen your systems' defenses.

The book admirably argues that security administrators should take some responsibility for the greater good of the Internet by, for example, using egress filtering to prevent people inside their networks from spoofing their source address (thus defending other networks from their own users' malice). The authors (and the community of white-hat security specialists that they represent) have done and continue to do a valuable service to all Internet users. Supplement this book with Northcutt's excellent Network Intrusion Detection, which takes a more general approach to log analysis and is less focused on specific attack signatures. --David Wall

Topics covered:



Book Description

Intrusion Signatures and Analysis opens with an introduction into the format of some of the more common sensors and then begins a tutorial into the unique format of the signatures and analyses used in the book. After a challenging four-chapter review, the reader finds page after page of signatures, in order by categories. Then the content digs right into reaction and responses covering how sometimes what you see isn¿t always what is happening. The book also covers how analysts can spend time chasing after false positives. Also included is a section on how attacks have shut down the networks and web sites of Yahoo, and E-bay and what those attacks looked like. Readers will also find review questions with answers throughout the book, to be sure they comprehend the traces and material that has been covered.

Intrusion Signatures and Analysis

Intrusion Signatures and Analysis,Mark Cooper,Stephen Northcutt,Matt Fearnow,Karen Frederick,Sams,0735710635,Access control,Computer Bks - Communications / Networking,Computer Books: General,Computer Data Security,Computer security,Computers,Internet - Security,Networking - General,Security - General,Computers / Internet / Security

Hot Books:

  1. Java Servlet & JSP Cookbook
  2. Java Web Services
  3. Jess in Action : Java Rule-Based Systems (In Action series)
  4. Learning Web Design : A Beginner's Guide to HTML, Graphics, and Beyond
  5. Machine Learning
  6. Maran Illustrated Weight Training (Maran Illustrated)
  7. MCAD Developing and Implementing Windows-based Applications with Microsoft Visual Basic .NET and Microsoft Visual Studio .NET Exam Cram 2 (Exam Cram 70-306)
  8. MDA Explained: The Model Driven Architecture--Practice and Promise
  9. Microsoft Access 2002 for Dummies
  10. Microsoft Excel 2003 Programming Inside Out

Hot Books

Hot Books

Recommended Books

  1. Fences : Authentic Details for Design and Restoration
  2. Dark Edge Volume 5
  3. Reality Fictions: The Films of Frederick Wiseman
  4. Personal Bankruptcy for Dummies
  5. On-the-Job Learning in the Software Industry : Corporate Culture and the Acquisition of Knowledge
  6. Self-paced Study Guide & Laboratory Exercises in Astronomy, 10th Edition
  7. Orbital symmetry and reaction mechanism: The OCAMS view
  8. Physicists of Ireland: Passion and Precision
  9. Murder, She Wrote: A Question of Murder
  10. Reincarnation: The Missing Link in Christianity
  11. Miller's: American Insider's Guide to the Twentieth-Century Furniture
  12. Making the Most of Small Spaces
  13. Personal Memoirs of P.H. Sheridan: General United States Army
  14. Mississippi Bird Watching: A Year-Round Guide
  15. Lonely Planet Road Trip Napa & Sonoma Wine Country