Tao of Network Security Monitoring, The: Beyond Intrusion Detection
©2005 |Addison-Wesley Professional | Available
©2005 |Addison-Wesley Professional | Available
Once your security is breached, everyone will ask the same question: now
what? Answering this question has cost companies hundreds of thousands of
dollars in incident response and computer forensics fees. This book reduces
the investigative workload of computer security incident response teams
(CSIRT) by posturing organizations for incident response success.
Firewalls can fail. Intrusion-detection systems can be bypassed. Network
monitors can be overloaded. These are the alarming but true facts about
network security. In fact, too often, security administrators' tools can serve as
gateways into the very networks they are defending.
Now, a novel approach to network monitoring seeks to overcome these
limitations by providing dynamic information about the vulnerability of all
parts of a network. Called network security monitoring (NSM), it draws on a
combination of auditing, vulnerability assessment, intrusion detection and
prevention, and incident response for the most comprehensive approach to
network security yet. By focusing on case studies and the application of opensource
tools, the author helps readers gain hands-on knowledge of how to
better defend networks and how to mitigate damage from security incidents.
Quickly develop and apply the skills needed to detect, prevent, and respond to new and emerging computer security exploits.
° Explores examples of actual compromised networks to illustrate how losses could have been avoided through network security monitoring.
° Written by Richard Bejtlich--a recognized authority and speaker on digital security.
° Foreword by Ron Gula, the original author of the Dragon intrusion detection system.
° Launch at Black Hat USA, July 26-29, 2004 in Las Vegas.
About the Author.
About the Contributors.
I. INTRODUCTION TO NETWORK SECURITY MONITORING.
1. The Security Process.
What Is Security?
What Is Risk?
A Case Study on Risk.
Security Principles: Characteristics of the Intruder.
Security Principles: Phases of Compromise.
Security Principles: Defensible Networks.
2. What Is Network Security Monitoring?
Indications and Warnings.
Collection, Analysis, and Escalation.
Detecting and Responding to Intrusions.
Why Do IDS Deployments Often Fail?
Outsiders versus Insiders: What Is NSM's Focus?
Security Principles: Detection.
Security Principles: Limitations.
What NSM Is Not.
NSM in Action.
3. Deployment Considerations.
Threat Models and Monitoring Zones.
Accessing Traffic in Each Zone.
II. NETWORK SECURITY MONITORING PRODUCTS.
4. The Reference Intrusion Model.
5. Full Content Data.
A Note on Software.
Snort as Packet Logger.
Finding Specific Parts of Packets with Tcpdump, Tethereal, and Snort.
A Note on Commercial Full Content Collection Options.
6. Additional Data Analysis.
Editcap and Mergecap.
7. Session Data.
Forms of Session Data.
sFlow and sFlow Toolkit.
8. Statistical Data.
What Is Statistical Data?
9. Alert Data: Bro and Prelude.
10. Alert Data: NSM Using Sguil.
So What Is Sguil?
The Basic Sguil Interface.
Sguil's Answer to "Now What?"
Making Decisions with Sguil.
Sguil versus the Reference Intrusion Model.
III. NETWORK SECURITY MONITORING PROCESSES.
11. Best Practices.
Back to Assessment.
12. Case Studies for Managers.
Introduction to Hawke Helicopter Supplies.
Case Study 1: Emergency Network Security Monitoring.
Case Study 2: Evaluating Managed Security Monitoring Providers.
Case Study 3: Deploying an In-House NSM Solution.
IV. Network Security Monitoring People.
13. Analyst Training Program.
Weapons and Tactics.
Scripting and Programming.
Management and Policy.
Training in Action.
Periodicals and Web Sites.
Case Study: Staying Current with Tools.
14. Discovering DNS.
Normal Port 53 Traffic.
Suspicious Port 53 Traffic.
Malicious Port 53 Traffic.
15. Harnessing the Power of Session Data.
The Session Scenario.
Session Data from the Wireless Segment.
Session Data from the DMZ Segment.
Session Data from the VLANs.
Session Data from the External Segment.
16. Packet Monkey Heaven.
Truncated TCP Options.
Chained Covert Channels.
V. THE INTRUDER VERSUS NETWORK SECURITY MONITORING.
17. Tools for Attacking Network Security Monitoring.
Cisco IOS Denial of Service.
Solaris Sadmin Exploitation Attempt.
Microsoft RPC Exploitation.
18. Tactics for Attacking Network Security Monitoring.
Degrade or Deny Collection.
Self-Inflicted Problems in NSM.
Epilogue The Future of Network Security Monitoring.
Remote Packet Capture and Centralized Analysis.
Integration of Vulnerability Assessment Products.
NSM Beyond the Gateway.
Appendix A: Protocol Header Reference.
Appendix B: Intellectual History of Network Security Monitoring.
Appendix C: Protocol Anomaly Detection.
Pearson offers affordable and accessible purchase options to meet the needs of your students. Connect with us to learn more.
K12 Educators: Contact your Savvas Learning Company Account General Manager for purchase options. Instant Access ISBNs are for individuals purchasing with credit cards or PayPal.
Savvas Learning Company is a trademark of Savvas Learning Company LLC.
Richard Bejtlich is founder of TaoSecurity, a company that helps clients detect, contain, and remediate intrusions using Network Security Monitoring (NSM) principles. He was formerly a principal consultant at Foundstone--performing incident response, emergency NSM, and security research and training--and created NSM operations for ManTech International Corporation and Ball Aerospace & Technologies Corporation. For three years, Bejtlich defended U.S. information assets as a captain in the Air Force Computer Emergency Response Team (AFCERT). Formally trained as an intelligence officer, he is a graduate of Harvard University and of the U.S. Air Force Academy. He has authored or coauthored several security books, including The Tao of Network Security Monitoring (Addison-Wesley, 2004).
We're sorry! We don't recognize your username or password. Please try again.
The work is protected by local and international copyright laws and is provided solely for the use of instructors in teaching their courses and assessing student learning.
You have successfully signed out and will be required to sign back in should you need to download more resources.