Books

  1. Intrusion Signatures and Analysis
    Intrusion Signatures and Analysis

  2. Designing CSS Web Pages
    Designing CSS Web Pages

  3. Introduction to EMC
    Introduction to EMC

  4. Valve and Transistor Audio Amplifiers
    Valve and Transistor Audio Amplifiers

  5. JNCIA: Juniper Networks Certified Internet Associate Study Guide
    JNCIA: Juniper Networks Certified Internet Associate Study Guide

  6. E-commerce for Dummies (For Dummies S.)
    E-commerce for Dummies (For Dummies S.)

  7. Network+ Certification for Dummies (For Dummies S.)
    Network+ Certification for Dummies (For Dummies S.)

  8. CCDA for Dummies (For Dummies S.)
    CCDA for Dummies (For Dummies S.)

  9. Web Services Enhancements: Understanding the WSE For.NET Enterprise Applications
    Web Services Enhancements: Understanding the WSE For.NET Enterprise Applications

  10. Wireless Devices End to End (End to End S.)
    Wireless Devices End to End (End to End S.)

  11. XML in Record Time
    XML in Record Time

  12. Cisco JumpStart
    Cisco JumpStart

  13. MCSA/MCSE Windows 2000 Network Management Study Guide
    MCSA/MCSE Windows 2000 Network Management Study Guide

  14. Mastering Cisco Routers
    Mastering Cisco Routers

  15. CCNA: Cisco Certified Network Associate Study Guide
    CCNA: Cisco Certified Network Associate Study Guide

  16. CCNA: Cisco Certified Network Associate Study Guide: Deluxe Edition
    CCNA: Cisco Certified Network Associate Study Guide: Deluxe Edition

  17. How Networks Work
    How Networks Work

  18. CCDA: Cisco Certified Design Associate Study Guide
    CCDA: Cisco Certified Design Associate Study Guide

  19. 10 Minute Guide to HTML
    10 Minute Guide to HTML

  20. Digital Communication
    Digital Communication

  21. Wireless Horizon: Strategy and Competition in the Worldwide Mobile Marketplace
    Wireless Horizon: Strategy and Competition in the Worldwide Mobile Marketplace

  22. Introduction to Communications Technologies for Non-engineers
    Introduction to Communications Technologies for Non-engineers

  23. Wireless Sensor Networks: Architectures and Protocols
    Wireless Sensor Networks: Architectures and Protocols

  24. High Power Audio Amplifier Construction (BP S.)
    High Power Audio Amplifier Construction (BP S.)

  25. Microstrip Antenna Design Handbook (Antennas & Propagation Library)
    Microstrip Antenna Design Handbook (Antennas & Propagation Library)

Intrusion Signatures and Analysis
Average customer rating: 4 out of 5 stars
  • When a good book is worth a thousand experiences!
  • A Great Title For Security Geeks to Learn Packet Forensics
  • Includes review questions with throughout the book
  • Analysis in practice
  • You want experience?
Intrusion Signatures and Analysis
Mark Cooper , Stephen Northcutt , Matt Fearnow , and Karen Frederick
Manufacturer: Sams
ProductGroup: Book
Binding: Paperback

EncryptionEncryption | Security & Encryption | Web Development | Computers & Internet | Subjects | Books
PrivacyPrivacy | Business & Culture | Computers & Internet | Subjects | Books
SecuritySecurity | Project Management | Business & Culture | Computers & Internet | Subjects | Books
Network SecurityNetwork Security | Networks, Protocols & APIs | Networking | Computers & Internet | Subjects | Books
GeneralGeneral | Networks, Protocols & APIs | Networking | Computers & Internet | Subjects | Books
GeneralGeneral | Computers & Internet | Subjects | Books
GeneralGeneral | Software | Computers & Internet | Subjects | Books
GeneralGeneral | E-commerce | Industries & Professions | Business & Investing | Subjects | Books
Look Inside Business BooksLook Inside Business Books | Trip | Specialty Stores | Books
Look Inside Computer BooksLook Inside Computer Books | Trip | Specialty Stores | Books
Qualifying Textbooks - Spring 2007Qualifying Textbooks - Spring 2007 | Stores | Books
GeneralGeneral | Software Books | Custom Stores | Stores | Software
Similar Items:
  1. Network Intrusion Detection (3rd Edition)
  2. Hack Attacks Revealed: A Complete Reference for UNIX, Windows, and Linux with Custom Security Toolkit, Second Edition
  3. Hacking Exposed
  4. Snort 2.1 Intrusion Detection, Second Edition
  5. The Tao of Network Security Monitoring: Beyond Intrusion Detection

ASIN: 0735710635

Amazon.com

Stephen Northcutt and his coauthors note in the superb Intrusion Signatures and Analysis that there's really no such thing as an attack that's never been seen before. The book documents scores of attacks on systems of all kinds, showing exactly what security administrators should look for in their logs and commenting on attackers' every significant command. This is largely a taxonomy of hacker strategies and the tools used to implement them. As such, it's an essential tool for people who want to take a scientific, targeted approach to defending information systems. It's also a great resource for security experts who want to earn their Certified Intrusion Analyst ratings from the Global Incident Analysis Center (GIAC)--it's organized, in part, around that objective.

The book typically introduces an attack strategy with a real-life trace--usually attributed to a real administrator--from TCPdump, Snort, or some sort of firewall (the trace's source is always indicated). The trace indicates what is happening (i.e., what weakness the attacker is trying to exploit) and the severity of the attack (using a standard metric that takes into account the value of the target, the attack's potential to do damage, and the defenses arrayed against the attack). The attack documentation concludes with recommendations on how defenses could have been made stronger. These pages are great opportunities to learn how to read traces and take steps to strengthen your systems' defenses.

The book admirably argues that security administrators should take some responsibility for the greater good of the Internet by, for example, using egress filtering to prevent people inside their networks from spoofing their source address (thus defending other networks from their own users' malice). The authors (and the community of white-hat security specialists that they represent) have done and continue to do a valuable service to all Internet users. Supplement this book with Northcutt's excellent Network Intrusion Detection, which takes a more general approach to log analysis and is less focused on specific attack signatures. --David Wall

Topics covered:

Book Description

Intrusion Signatures and Analysis opens with an introduction into the format of some of the more common sensors and then begins a tutorial into the unique format of the signatures and analyses used in the book. After a challenging four-chapter review, the reader finds page after page of signatures, in order by categories. Then the content digs right into reaction and responses covering how sometimes what you see isn¿t always what is happening. The book also covers how analysts can spend time chasing after false positives. Also included is a section on how attacks have shut down the networks and web sites of Yahoo, and E-bay and what those attacks looked like. Readers will also find review questions with answers throughout the book, to be sure they comprehend the traces and material that has been covered.

Customer Reviews:

5 out of 5 stars When a good book is worth a thousand experiences!.......2002-02-24

This is the best book about Intrusion Signatures published yet.
I teach computer security at a local university, and with the only help of this book, I could take care of all the practical aspects of my last course. If you have already a good background on this field, and read and understand thoroughly the book, then you can afford any related security certification test.
Chapters 3 through 17, present several well documented cases, which, in turn, are discussed following the same standard:
- Presentation
- Source of Trace
- Detect Generated by
- Probability the Source Address Was spoofed
- Attack Description
- Attack Mechanism
- Correlations
- Evidence of Active Targeting
- Severity
- Defense Recommendations
- Questions

Chapter 1 introduces the reader to Analysis of Logs (including Snort, Tcpdump, and Syslog), IDS, and Firewalls. Even being a quick review, it is quite useful, though.
Chapter 2 explains the way the cases are studied.

The covered vulnerabilities and attacks include:
- Internet Security Threats
- Routers and Firewalls Attacks
- IP Spoofing
- Networks Mapping and Scanning
- Denial of Service
- Trojans
- Assorted Exploits
- Buffer Overflows
- IP Fragmentation
- False Positives
- Crafted Packets

At the bottom line, this is one of the 5 best computer security books I ever read. Even for non experts, the book can be a valuable tool to improve the understanding on this field.
Try it.

5 out of 5 stars A Great Title For Security Geeks to Learn Packet Forensics.......2001-07-11

I read this book out of general interest and a need to dig deeper into the technical aspects of security, and intrusion detection in particular. For that, this title is perfect!

It's great to learn intrusion detection, packet analysis, forensics, attack methodologies, attack recognition, and similar topics. And oh, by the way, if you have any interest at all in certification, Intrusion Signatures and Analysis is the study guide for one of the hottest new certs there is: SANS GIAC Intrusion Detection In Depth.

5 out of 5 stars Includes review questions with throughout the book.......2001-05-20

A must-have for the serious network security professional, Intrusion Signatures And Analysis opens with an introduction into the format of some of the more common sensors and then begins a tutorial into the unique format of the signatures and analyses used in the book. Readers will find page after page of signatures, in order by categories as well as a case study section on how attacks have shut down the networks and web sites of Yahoo, and E-bay and what those attacks looked like. As an added feature, the collaborative authors Stephen Northcutt; Mark Cooper; Matt Fearnow; and Karen Frederick included review questions with throughout the book to help readers be sure they comprehend the traces and material that has been covered. Intrusion Signatures And Analysis is a recommended resource for the SANS Institute GIAC certification program. 448 pp.

4 out of 5 stars Analysis in practice.......2001-04-06

This is the second release from some of the key SANS GIAC folk and is a fine addition as it extends on the data from "Network Intrusion Detection : An Analysts Handbook", to give intrusion detection practitioners some interesting detects from the GIAC graduates.

Included in these detects are some of the more unique pieces of analysis that have been performed at GIAC, with detailed write-ups of the analysis process and the logic applied in defining the conditions in which the events occured.

Once again, this is easy and interesting reading which will appeal to intrusion analyists of all levels. Further, this book gives neophytes a real sense of what can be monitered and how important intrusion detection is in security layering.

5 out of 5 stars You want experience?.......2001-02-07

The real-world signatures in this book, along with the analysis, make this a wonderful reference book. There is, of course, no substitute for experience. However, this book provides an excellent baseline of experience for any Intrusion Analyst! From that baseline one should be able to better analyze future attacks; there is, after all, only so much an attacker can do.

This book was made possible by contributors to GIAC (Global Incident Analysis Center); professionals out "in the trenches" dealing with attacks of all shape and size on a daily basis. These traces were not generated in a lab; they're the same traces you will see on your network if you're looking for them.

I've already used this book as a reference guide and it sits on my shelf next to "TCP/IP Illustrated V1" by Dr. Richard Stevens and "Intrusion Detection: An Analysts Handbook V2" by Stephen Northcutt and Judy Novak- I use all on a regular basis.

Whether you are just starting out in the IDS realm or whether you're an established Analyst sitting on an enterprise of sensors this book is for you.

-- Brent Deterding Enterprise Manager of Network Security - Solutia Inc.

Intrusion Signatures and Analysis: Custom Edition
Average customer rating: Not rated
    Intrusion Signatures and Analysis: Custom Edition
    Mark Cooper
    Manufacturer: Pearson Custom Pub
    ProductGroup: Book
    Binding: Paperback

    SecuritySecurity | Project Management | Business & Culture | Computers & Internet | Subjects | Books
    GeneralGeneral | Computers & Internet | Subjects | Books
    ASIN: 0536182426

    Books:

    1. Comptia Network+exam Self Study Guide
    2. Code Hacking: A Developer's Guide to Network Security
    3. Total SNMP: Exploring the Simple Network Management Protocol
    4. Solid Modeling Using Solidworks 2004, a DVD Solution
    5. Java Network Programming [2nd Edition]
    6. IP Telephony Demystified (McGraw-Hill Telecom S.)
    7. Intrusion Detection with SNORT: Advanced IDS Techniques Using SNORT, Apache, MySQL, PHP and ACID (Bruce Perens' Open Source S.)
    8. Client/Server Survival Guide (Third Ed)
    9. Intrusion Signatures and Analysis
    10. A Guide to the TCP/IP Protocol Suite (Telecommunications Library)

    Books