Free The Tao of Network Security Monitoring: Beyond Intrusion Detection Ebook :: Security Ebook Category
Home | Categories | Links | My Amazon | StartLogic ixwebhosting

This page is optimized for Firefox.  Get Firefox
 



    The Tao of Network Security Monitoring: Beyond Intrusion Detection

     ISBN  0321246772
     Hits  454

     Category  Security

The Tao of Network Security Monitoring: Beyond Intrusion Detection eBook



Here is a really cool security book, that made me lose half a nigh sleep when I first got it. Richard Bejtlich "Tao of Network Security Monitoring" ("Tao of NSM") covers the process, tools and analysis techniques for monitoring your network using intrusion detection, session data, traffic statistical information and other data. Here are some of the book highlights.

The book starts from a really exciting and fun background on security, risk and the need to monitor networks and systems. Topics such as the classic "threat x vulnerability x value = risk" formula to threat modeling and limitation of attack prevention technologies are included. A nice thing on the process side is the "assess -> protect -> detect -> respond" loop, that defines a security process for an organization on a high level. Threat analysis material seems to have military origin, but is enlightening for other types of organizations as well.

NSM is introduced as being 'beyond IDS' with some coverage on why IDS deployments fail and what else is needed (NSM process and tools, that is).

A great and rarely appreciated idea expressed in the book is that the intruders are often smarter than defenders. It presents a stark contrast to all this "staying ahead of the hackers", which makes no sense in many cases as the attackers are in fact far ahead. NSM approach will indeed work against the advanced attackers, albeit a high resource cost to the defending organization. Such 'worst case' scenario preparations are extremely rare in other security books. Detecting such intruder is covered during their five phases of compromise (from reconnaissance to using/abusing the system).

Another gem is an idea of a "defensible network"; not 'secure' or 'protected', but defensible. 'Defensible network' can be watched, is configured to limit possible intruder actions, can be kept up to date and runs only the minimum necessary services, that assures that if bad things happen there, they can be handled effectively.

I also liked how the tools are covered in the book. It is not a tool manual rephrased, but rather the whole tool use context related to the rest of the NSM. While the paradigm 'products perform collection, people perform analysis' might be faulty as the products are getting smarter, having training analysts still is one of the best investments in security. On the process side, the book covers complete analyst training. People are indeed the critical component of NSM, since most of the decision-making relies on trained analysts and their investigation, classification and escalation of alerts.

A chapter on netflow and other types of session/connectivity data presents considerable interest to those monitoring networks. Example case studies show how such data helped identify intrusion action that did not directly product IDS alerts. Same applies to traffic visualization and statistical tools that enrich the IDS data and can sometimes provide early anomaly indications as well.

Of course, NSM event-driven analysis is centered on Sguil - a new GUI frontend to NIDS, session and other context data, facilitating easy and effective event classification and escalation (if needed).

Emergency NSM vs ongoing monitoring NSM procedures are also covered in the book. Even if the organization does not maintain an ongoing security monitoring program, it can still benefit from NSM that is deployed after a suspected intrusion.

Attacks against NSM processes and technologies also fill dedicated section. Such attacks include intruder tools as well as attacks against the human (such overwhelming the analysts) and process components of the NSM.

Overall, the book is a required reading for any security professional and those wishing to become one. It helps to broaden the horizons of seasoned professionals as well as educate the beginners in monitoring techniques. While value of NSM as an approach can be debated in modern organizations where tuned sensors and skilled analysts are an exception rather than the rule, the book is a superb security resource even for those who do not choose to implement NSM at the moment.



Download
Server Status
rapidshare_deLive

Other books on Security
Network Security Tools
Information Security Management Handbook, Fifth Edition
The International Handbook of Computer Security
Stealing the Network: How to Own a Continent
Linux Server Security
OS X for Hackers at Heart
A buffer overflow study: attack and defense
Codes and Ciphers- Julius Caesar, the Enigma, and the Internet
Computer Security Basics
Intrusion Prevention Fundamentals

View all books on Security

Previous & Next Book
OS X for Hackers at Heart
Intrusion Prevention Fundamentals

Random eBooks
 Probabilities in Physics

No Details (See Book Info)

 The Outlook Answer Book- Useful Tips, Tricks, and Hacks for Microsoft Outlook(R) 2003

From the Back Cover

Discover many useful customizations you can do with Outlook to improve efficiency both at home and on the job.

Get more out of Outlook! The Outlook Answer Book brings together hundreds of bite-size ti.. (read more)

 Perl Hacks- Tips & Tools for Programming, Debugging, and Surviving

With more than a million dedicated programmers, Perl has proven to be the best computing language for the latest trends in computing and business. While other languages have stagnated, Perl remains fresh, thanks to its community-based developmen.. (read more)

 Chemistry of Precious Metals

No Details (See Book Info)

 How to Value Your Business and Increase Its Potential

Business owners who understand the basic theories and realities of valuation gain valuable insights into how best to increase the intrinsic value of their businesses. How to Value Your Business and Increase Its Potential saves research ti.. (read more)




Load time: 0.04 sec

© 2007 ebook2.com, All Rights Reserved.

Sponsor: Find-Hosting.NET

Warning: Unknown: Your script possibly relies on a session side-effect which existed until PHP 4.2.3. Please be advised that the session extension does not consider global variables as a source of data, unless register_globals is enabled. You can disable this functionality and this warning by setting session.bug_compat_42 or session.bug_compat_warn to off, respectively. in Unknown on line 0