 |
Intrusion Detection with Snort View Larger Image | Jack Koziol Sams, Paperback, Published May 2003, 340 pages, ISBN 157870281X | List Price: $45.00 Our Price: $28.50 You Save: $16.50 (37% Off)
| | | Availability: Out-Of-Stock |
Be the First to Write a Review and tell the world about this title!People who purchase this book frequently purchase: - Hacking Exposed: Network Security Secrets & Solutions, 5th Edition; Joel Scambray, et al, $30.50, 39% Off!
- Managing Security with Snort and IDS Tools; Kerry Cox, et al, $24.50, 39% Off!
- Snort Cookbook; Angela Orebaugh, et al, $24.50, 39% Off!
Books on similar topics, in best-seller order:Books from the same publisher, in best-seller order:
Practical guidance on how to put Snort to work!
With over 100,000 installations, the Snort open-source network instrusion detection system is combined with other free tools to deliver IDS defense to medium - to small-sized companies, changing the tradition of intrusion detection being affordable only for large companies with large budgets.
Until now, Snort users had to rely on the official guide available on snort.org. That guide is aimed at relatively experience snort administrators and covers thousands of rules and known exploits.
The lack of usable information made using Snort a frustrating experience. The average Snort user needs to learn
how to actually get their systems up-and-running.
Snort Intrusion Detection provides readers with practical guidance on how to put Snort to work. Opening with a primer to intrusion detection and Snort, the book takes the reader through planning an installation to building the
server and sensor, tuning the system, implementing the system and analyzing traffic, writing rules, upgrading the system, and extending Snort.
ABOUT THE AUTHOR:
Jack Koziol has been working in computer security since 1998. As the
information security manager at a medical transcription company he
set up a number of Snort systems for partner hospitals.
He is currently the information security officer at a major bank in
Chicago, where he has architected a Snort-based intrusion detection
system for online banking and has also developed a security blueprint
for an online currecy exchange that is expected to have 100+ locations
by the end of 2003.
In addition to his work at the bank, Koziol also contributes to
Information Security magazine.
TABLE OF CONTENTS
- 1. Intrusion Detection Primer.
IDSs Come in Different Flavors. Methods of Detecting Intrusions.
Origin of Attacks. Orchestrating an Attack. The IDS Reality.
Summary.
- 2. Network Intrusion Detection with Snort.
Snort's Specifications. Detecting Suspicious Traffic via Signatures.
Detecting Suspicious Traffic via Heuristics. Gathering Intrusion
Data. Alerting via Output Plug-ins. Prioritizing Alerts. Distributed
Snort Architecture. Securing Snort. Shortcomings. Summary.
- 3. Dissecting Snort.
Feeding Snort Packets with Libpcap. Preprocessors. The Detection
Engine. Output Plugins. Summary.
- 4. Planning for the Snort Installation.
Defining an IDS Policy. Deciding What to Monitor. Designing Your
Snort Architecture. Planning for Maintenance. Incident Response
Plan. Responding to an Incident. Restoring to a Normal State.
Summary.
- 5. The Foundation-Hardware and Operating Systems.
Hardware Performance Metrics. Picking a Platform. The Monitoring
Segment. Distributing Traffic to Multiple Sensors. Summary.
- 6. Building the Server.
Installation Guide Notes. Red Hat Linux 7.3. Post-Installation
Tasks. Installing the Snort Server Components. Summary.
- 7. Building the Sensor.
Installation Guide Notes. Installing the Snort Sensor Components.
Installing Snort. Implementing Barnyard. Summary.
- 8. Building the Analyst's Console.
Windows. Linux. Testing the Console. Working with ACID.
Summary.
- 9. Additional Installation Methods.
The Hybrid Server/Sensor. Snort on OpenBSD. Snort on Windows.
Summary.
- 10. Tuning and Reducing False Positives.
Pre-Tuning Activities. Tuning the Network for Snort. Filtering Traffic
with Snort. Tuning the Preprocessors. Refining the Ruleset.
Organize Your Rules. Designing a Targeted Ruleset. Tuning
MySQL. Tuning ACID. Summary.
- 11. Real-Time Alerting.
An Overview of Real-Time Alerting with Snort. Prioritization of
Alerts. Alerting with the Hybrid. Alerting with Distributed Snort.
- 12. Basic Rule Writing.
Fundamental Rule Writing Concepts. Rule Syntax. Writing Rules.
Summary.
- 13. Upgrading and Maintaining Snort.
Choosing a Snort Management Application. IDS Policy Manager.
SnortCenter. Upgrading Snort. Summary.
- 14. Advanced Topics in Intrusion Prevention.
A Warning Concerning Intrusion Prevention. Planning an Intrusion
Prevention Strategy. Snort Inline Patch. SnortSam. Summary.
- Appendix A. Troubleshooting.
Snort Issues. ACID Issues. IDS Strategy.
- Appendix B. Rule Documentation.
- Index.
|
 |