Poised Solutions Library

Poised Solutions Tech Library

the tao of network
security monitoring book review

Poised Solutions

The Tao of Network Security Monitoring Book Review

IT Security

IT Library

The Tao of Network Security Monitoring

The Tao of Network Security Monitoring

Amazon UKAmazon USA
The Tao of Network Security Monitoring
Author:
Richard Bejtlich
Publisher:
Addison-Wesley
Published:
2005
Pages:
798

The Tao of Network Security Monitoring


The Tao of Network Security Monitoring Chapters

The Tao of Network Security Monitoring Chapters
  1. The Security Process
    • What Is Security?
    • What is Risk?
      • Threat
      • Vulnerability
      • Asset Value
    • A Case Study on risk
    • Security Principles: Characteristics of the Intruder
      • Some Intruders Are Smarter Than You
      • Many Intruders Are Unpredictable
      • Prevention Eventually Fails
    • Security Principles: Phases of Compromise
      • Reconnaissance
      • Exploitation
      • Reinforcement
      • Consolidation
      • Pillage
    • Security Principles: Defensible Networks
      • Defensible Networks Can Be Watched
      • Defensible Networks Limit an Intruder's Freedom to Maneuver
      • Defensible Networks Offer a Minimum Number of Services
      • Defensible Networks Can Be Kept Current
    • Conclusion
  2. What is Network Security Monitoring?
    • Indications and Warnings
    • Collection, Analysis and Escalation
    • Detecting and Responding to Intrusions
    • Why Do IDS Deployments Often Fail?
    • Outsiders versus Insiders: What Is NSM's Focus?
    • Security Principles: Detection
      • Intruders Who Can Communicate with Victims Can Be Detected
      • Detection through Sampling Is Better Than No Detection
      • Detection through Traffic Analysis Is Better than No Detection
    • Security Principles: Limitations
      • Collecting Everything is Ideal but Problematic
      • Real Time Isn't Always the Best Time
      • Extra Work Has a Cost
    • What NSM is Not
      • NSM Is Not Device Management
      • NSM Is Not Security Event Management
      • NSM Is Not Network-Based Forensics
      • NSM Is Not Intrusion Prevention
    • NSM in Action
    • Conclusion
  3. Deployment Considerations
    • Threat Models and Monitoring Zones
      • The Perimeter
      • The Demilitarized Zone
      • The Wireless Zone
      • The Intranet
    • Accessing Traffic in Each Zone
      • Hubs
      • SPAN Ports
      • Taps
      • Inline Devices
    • Wireless Monitoring
    • Sensor Architecture
      • Hardware
      • Operating Systems
    • Sensor Management
      • Console Access
      • In-Band Remote Access
      • Out-of-Band Remote Access
    • Conclusion
  4. The Reference Intrusion Model
    • The Scenario
    • The Attack
    • Conclusion
  5. Full Content Data
  6. Additional Data Analysis
  7. Session Data
  8. Statistical Data
  9. Alert Data: Bro and Prelude
  10. Alert Data: NSM Using Sguil
  11. Best Practices
  12. Case Studies for Managers
  13. Analyst Training Program
  14. Discovering DNS
  15. Harnessing the Power of Session Data
  16. Packet Monkey Heaven
  17. Tools for Attacking Network Security Monitoring
  18. Tactics for Attacking Network Security Monitoring
  19. The Future of Network Security Monitoring
The Tao of Network Security Monitoring Appendices
  1. Protocol Header Reference
  2. Intellectual History of Network Security Monitoring
  3. Protocol Anomaly Detection
  4. Index

Monitoring

















Poised Solutions Web Development and Web Design by Poised Solutions IT Practice

Guild of Developers  •  PantheonOS  •  Cyber Security