CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer
image Intrusion Detection: Snort Cookbook image
Linux
Solutions and Examples for Snort Administrators
O'Reilly Releases "Snort Cookbook"

Sebastopol, CA--The principles of securing a computer system are no different than those of securing any other system, contend Angela Orebaugh, Simon Biles, and Jacob Babbin, authors of the new "Snort Cookbook" (O'Reilly, US $39.95). For example, if you're building a castle, you'll install a moat and high walls. You may also add a perimeter wall and keep for two additional layers of security. "But at the end of the day, you still need a way for supplies and people to get in and out," they note. "To make this part of your castle secure, you post watchmen, guards, and soldiers to ensure that only those who should be are getting in." Physical security in a company is similar, complete with locked doors, pass cards, and security guards.

But in securing a computer system, this final layer of security is
frequently overlooked. "Too often people assume that the perimeter
protection of the firewall is sufficient to keep all attackers at bay, not
considering that attackers might just walk over the bridge through the
front gate," Orebaugh, Biles, and Babbin remind readers. "Attackers don't
kick down the door, they walk through it pretending to be someone else."

An intrusion detection system (IDS) doesn't exist to check the identity of
people coming through the firewall, but to keep an eye out for behavior
that's against the rules, rather like the security guard who watches to
see if someone is tampering with the lock on the door marked "Private."
Snort, the de facto open source standard of IDS, is capable of performing
real-time traffic analysis and packet logging on IP networks. It conducts
protocol analysis, content searching, and matching.  Snort is the security
guard placed on the network to make sure it stays secure.

The "Snort Cookbook" covers important issues that system administrators
and security professionals deal with every day, saving them countless
hours of sifting through dubious online advice or wordy tutorials to make
use of the full power of Snort. Presented in the popular
problem-solution-discussion format of O'Reilly cookbooks, each recipe
contains a clear and thorough description of the problem, a concise but
complete discussion of a solution, and real-world examples that illustrate
that solution. Topics include:

-Installation
-Optimization
-Logging
-Alerting
-Rules and signatures
-Detecting viruses
-Countermeasures
-Detecting common attacks
-Administration
-Honeypots
-Log analysis

But the "Snort Cookbook" offers more than quick cut-and-paste solutions to
frustrating security issues. Those who learn best in the trenches--but
don't have the hours to spare to hunt down best-practice snippets of
advice--will find solutions to immediate problems in this ultimate Snort
sourcebook. Its tips and tricks will help readers deploy Snort like
security gurus--and still have time to have a life.

Additional Resources:

Chapter 7, "Miscellaneous Other Uses," is available online at:
http://www.oreilly.com/catalog/snortckbk/chapter/index.html

For more information about the book, including table of contents, index,
author bios, and samples, see:
http://www.oreilly.com/catalog/snortckbk/index.html

For a cover graphic in JPEG format, go to:
ftp://ftp.ora.com/pub/graphics/book_covers/hi-res/0596007914.jpg

Snort Cookbook
Angela Orebaugh, Simon Biles, and Jacob Babbin
ISBN: 0-596-00791-4, 270 pages, $39.95 US, $55.95 CA
order@oreilly.com
1-800-998-9938
1-707-827-7000
http://www.oreilly.com
1005 Gravenstein Highway North
Sebastopol, CA 95472

About O'Reilly
O'Reilly Media, Inc. is the premier information source for leading-edge
computer technologies. The company's books, conferences, and web sites
bring to light the knowledge of technology innovators. O'Reilly books,
known for the animals on their covers, occupy a treasured place on the
shelves of the developers building the next generation of software.
O'Reilly conferences and summits bring alpha geeks and forward-thinking
business leaders together to shape the revolutionary ideas that spark new
industries. From the Internet to XML, open source, .NET, Java, and web
services, O'Reilly puts technologies on the map. For more information:
http://www.oreilly.com

# # #

O'Reilly is a registered trademark of O'Reilly Media, Inc. All other
trademarks are property of their respective owners.
Posted on Wednesday, 20 April 2005 @ 01:47:32 UTC by Paul (1149 reads)
[ Trackback ]
image

"Intrusion Detection: Snort Cookbook" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· OpenSource
· HotScripts
· W3 Consortium
· More about Linux
· News by Paul


Most read story about Linux:
The world's easiest Linux desktop deployment and management - NOW FREE!

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer