• Fri frakt över 249 kr
  • •
  • Snabba leveranser
  • •
  • Billiga böcker
Kundservice

Du är på sajten för privatpersoner.

Företag, bibliotek eller offentlig verksamhet?

Du handlar på classic.bokus.com, där alla dina funktioner finns intakta.
Till classic.bokus.com
Bokus logotyp. Gå till startsidan.
  • Erbjudanden
  • Nyheter
  • Student
  • Topplistor
  • Barn & ungdom
  • Bokus Play
  • E-böcker
  • Pocketböcker
  • Spel & pussel

10% studentrabatt med kod TERM26

Sidfot

Mina sidor

    Hjälp

    • Kundservice
    • Vanliga frågor och svar
    • Frakt och leverans
    • Retur vid ångerrätt
    • Reklamera vara
    • Betalning
    • Köpvillkor
    • Allmänna villkor
    • Information om webbplatsens tillgänglighet

    Om Bokus

    • Om oss
    • Pressrum
    • För studenter
    • För företag
    • För bibliotek och offentlig verksamhet
    • För leverantörer
    • Hållbarhet

    Populärt

    • Aktuella erbjudanden
    • Presentkort
    • Studentlitteratur
    • Nya böcker
    • Topplistor
    • Signerade böcker
    • Engelska böcker

    Inspiration

    • Boktips
    • BookTok
    • Populära bokserier
    • Barnbokskaraktärer
    • Populära författare

    Mina sidor

      Hjälp

      • Kundservice
      • Vanliga frågor och svar
      • Frakt och leverans
      • Retur vid ångerrätt
      • Reklamera vara
      • Betalning
      • Köpvillkor
      • Allmänna villkor
      • Information om webbplatsens tillgänglighet

      Om Bokus

      • Om oss
      • Pressrum
      • För studenter
      • För företag
      • För bibliotek och offentlig verksamhet
      • För leverantörer
      • Hållbarhet

      Populärt

      • Aktuella erbjudanden
      • Presentkort
      • Studentlitteratur
      • Nya böcker
      • Topplistor
      • Signerade böcker
      • Engelska böcker

      Inspiration

      • Boktips
      • BookTok
      • Populära bokserier
      • Barnbokskaraktärer
      • Populära författare
      Logotyp för Bokus
      Följ oss på Facebook (extern länk)Följ oss på Instagram (extern länk)Följ oss på YouTube (extern länk)Följ oss på TikTok (extern länk)
      bokus @ CookiesAnpassa cookiesIntegritetspolicyKöpvillkor
      Till Citymail hemsida (extern länk)Till Budbee hemsida (extern länk)Till Postnord hemsida (extern länk)Till Schenker hemsida (extern länk)Till Early Bird hemsida (extern länk)Till Walleys hemsida (extern länk)
      1. Data och IT
      2. Nätverk och kommunikation

      Snort Cookbook

      AvAngela Orebaugh

      Häftad, Engelska, 2005

      Del i serien Cookbooks Ser.

      302 kr

      Beställningsvara. Skickas inom 5-8 vardagar. Fri frakt över 249 kr.

      Beskrivning

      If you are a network administrator, you're under a lot of pressure to ensure that mission-critical systems are completely safe from malicious code, buffer overflows, stealth port scans, SMB probes, OS fingerprinting attempts, CGI attacks, and other network intruders. Designing a reliable way to detect intruders before they get in is an essential - but often overwhelming - challenge. SNORT, the defacto open source standard of intrusion detection tools, is capable of performing real-time traffic analysis and packet logging on IP network. It can perform protocol analysis, content searching, and matching. SNORT can save countless headaches; the new SNORT Cookbook will save countless hours of sifting through dubious online advice or wordy tutorials in order to leverage the full power of SNORT. Each recipe in the popular and practical problem-solution-discussion O'Reilly cookbook format contains a clear and thorough description of the problem, a concise but complete discussion of a solution, and real-world examples that illustrate that solution.The SNORT Cookbook covers important issues that sys admins and security pros will us everyday, such as: - installation - optimization - logging - alerting - rules and signatures - detecting viruses - countermeasures - detecting common attacks - administration - honeypots - log analysis But the SNORT Cookbook offers far more than quick cut-and-paste solutions to frustrating security issues. Those who learn best in the trenches - and don't have the hours to spare to pore over tutorials or troll online for best-practice snippets of advice - will find that the solutions offered in this ultimate SNORT sourcebook not only solve immediate problems quickly, but also showcase the best tips and tricks they need to master be security gurus - and still have a life.

      Produktinformation

      • Utgivningsdatum:2005-05-03
      • Mått:1820 x 160 x 2310 mm
      • Vikt:450 g
      • Format:Häftad
      • Språk:Engelska
      • Serie:Cookbooks Ser.
      • Antal sidor:270
      • Förlag:O'Reilly Media
      • ISBN:9780596007911

      Utforska kategorier

      • Nätverk och kommunikation inom Data och IT
      • IT-säkerhet inom Data och IT

      Mer om författaren

      Angela Orebaugh (CISSP, GCIA, GCFW, GCIH, GSEC, CCNA) has worked in information technology for 10 years. She is currently an associate at Booz Allen Hamilton in the Washington, DC metro area. Her focus is on perimeter defense, secure architecture design, vulnerability assessments, penetration testing, and intrusion-detection. Angela is an expert in many commercial and open source intrusion detection and analysis tools including Ethereal, Snort, Nessus, and Nmap. She is a graduate of James Madison University with a masters in computer science, and she is currently pursuing her PhD with a concentration in information security at George Mason University. Her GCFW practical received honors recognition and was used as a case study in the book Network Perimeter Security: The Definitive Guide to Firewalls, VPNs, Routers, and Network Intrusion Detection by Stephen Northcutt (ISBN: 0735712328). Angela is a researcher, writer, and speaker for SANS Institute, where she has helped to develop and revise SANS course material and also serves as the Senior Mentor Coach for the SANS Local Mentor Program.

      Innehållsförteckning

      • Preface; 1. Installation and Optimization; 1.1 Installing Snort from Source on Unix; 1.2 Installing Snort Binaries on Linux; 1.3 Installing Snort on Solaris; 1.4 Installing Snort on Windows; 1.5 Uninstalling Snort from Windows; 1.6 Installing Snort on Mac OS X; 1.7 Uninstalling Snort from Linux; 1.8 Upgrading Snort on Linux; 1.9 Monitoring Multiple Network Interfaces; 1.10 Invisibly Tapping a Hub; 1.11 Invisibly Sniffing Between Two Network Points; 1.12 Invisibly Sniffing 100 MB Ethernet; 1.13 Sniffing Gigabit Ethernet; 1.14 Tapping a Wireless Network; 1.15 Positioning Your IDS Sensors; 1.16 Capturing and Viewing Packets; 1.17 Logging Packets That Snort Captures; 1.18 Running Snort to Detect Intrusions; 1.19 Reading a Saved Capture File; 1.20 Running Snort as a Linux Daemon; 1.21 Running Snort as a Windows Service; 1.22 Capturing Without Putting the Interface into Promiscuous Mode; 1.23 Reloading Snort Settings; 1.24 Debugging Snort Rules; 1.25 Building a Distributed IDS (Plain Text); 1.26 Building a Distributed IDS (Encrypted); 2. Logging, Alerts, and Output Plug-ins; 2.1 Logging to a File Quickly; ; 2.2 Logging Only Alerts; 2.3 Logging to a CSV File; ; 2.4 Logging to a Specific File; 2.5 Logging to Multiple Locations; ; 2.6 Logging in Binary; 2.7 Viewing Traffic While Logging; ; 2.8 Logging Application Data; 2.9 Logging to the Windows Event Viewer; 2.10 Logging Alerts to a Database; 2.11 Installing and Configuring MySQL; 2.12 Configuring MySQL for Snort; 2.13 Using PostgreSQL with Snort and ACID; 2.14 Logging in PCAP Format (TCPDump); 2.15 Logging to Email; 2.16 Logging to a Pager or Cell Phone; 2.17 Optimizing Logging; 2.18 Reading Unified Logged Data; 2.19 Generating Real-Time Alerts; 2.20 Ignoring Some Alerts; 2.21 Logging to System Logfiles; 2.22 Fast Logging; 2.23 Logging to a Unix Socket; 2.24 Not Logging; 2.25 Prioritizing Alerts; 2.26 Capturing Traffic from a Specific TCP Session; 2.27 Killing a Specific Session; 3. Rules and Signatures; 3.1 How to Build Rules; 3.2 Keeping the Rules Up to Date; 3.3 Basic Rules You Shouldn't Leave Home Without; 3.4 Dynamic Rules; 3.5 Detecting Binary Content; 3.6 Detecting Malware; 3.7 Detecting Viruses; 3.8 Detecting IM; 3.9 Detecting P2P; 3.10 Detecting IDS Evasion; 3.11 Countermeasures from Rules; 3.12 Testing Rules; 3.13 Optimizing Rules; 3.14 Blocking Attacks in Real Time; 3.15 Suppressing Rules; 3.16 Thresholding Alerts; 3.17 Excluding from Logging; 3.18 Carrying Out Statistical Analysis; 4. Preprocessing: An Introduction; 4.1 Detecting Stateless Attacks and Stream Reassembly; 4.2 Detecting Fragmentation Attacks and Fragment Reassemblywith Frag2; 4.3 Detecting and Normalizing HTTP Traffic; 4.4 Decoding Application Traffic; 4.5 Detecting Port Scans and Talkative Hosts; 4.6 Getting Performance Metrics; 4.7 Experimental Preprocessors; 4.8 Writing Your Own Preprocessor; 5. Administrative Tools; 5.1 Managing Snort Sensors; 5.2 Installing and Configuring IDScenter; 5.3 Installing and Configuring SnortCenter; 5.4 Installing and Configuring Snortsnarf; 5.5 Running Snortsnarf Automatically; 5.6 Installing and Configuring ACID; 5.7 Securing ACID; 5.8 Installing and Configuring Swatch; 5.9 Installing and Configuring Barnyard; 5.10 Administering Snort with IDS Policy Manager; 5.11 Integrating Snort with Webmin; 5.12 Administering Snort with HenWen; 5.13 Newbies Playing with Snort Using EagleX; 6. Log Analysis; 6.1 Generating Statistical Output from Snort Logs; 6.2 Generating Statistical Output from Snort Databases; 6.3 Performing Real-Time Data Analysis; 6.4 Generating Text-Based Log Analysis; 6.5 Creating HTML Log Analysis Output; 6.6 Tools for Testing Signatures; 6.7 Analyzing and Graphing Logs; 6.8 Analyzing Sniffed (Pcap) Traffic; 6.9 Writing Output Plug-ins; 7. Miscellaneous Other Uses; 7.1 Monitoring Network Performance; 7.2 Logging Application Traffic; 7.3 Recognizing HTTP Traffic on Unusual Ports; ; 7.4 Creating a Reactive IDS; 7.5 Monitoring a Network Using Policy-Based IDS; 7.6 Port Knocking; 7.7 Obfuscating IP Addresses; 7.8 Passive OS Fingerprinting; 7.9 Working with Honeypots and Honeynets; 7.10 Performing Forensics Using Snort; 7.11 Snort and Investigations; 7.12 Snort as Legal Evidence in the U.S.; 7.13 Snort as Evidence in the U.K.; 7.14 Snort as a Virus Detection Tool; 7.15 Staying Legal; Index
      Hoppa över listan

      Mer från samma författare

      Graham Clark, Angela Orebaugh, Michael Rash - Intrusion Prevention and Active Response, E-bok

      Intrusion Prevention and Active Response

      Graham Clark, Angela Orebaugh, Michael Rash

      E-bok
      2005

      423 kr

      Gilbert Ramirez, Angela Orebaugh, Jay Beale - Wireshark & Ethereal Network Protocol Analyzer Toolkit, E-bok

      Wireshark & Ethereal Network Protocol Analyzer Toolkit

      Gilbert Ramirez, Angela Orebaugh, Jay Beale

      E-bok
      2006

      423 kr

      Raffael Marty, Matt Jonkman, Angela Orebaugh, Eric Seagren, Michael Gregg - How to Cheat at Configuring Open Source Security Tools, E-bok

      How to Cheat at Configuring Open Source Security Tools

      Raffael Marty, Matt Jonkman, Angela Orebaugh, Eric Seagren, Michael Gregg

      E-bok
      2011

      423 kr

      Becky Pinkard, Angela Orebaugh - Nmap in the Enterprise, E-bok

      Nmap in the Enterprise

      Becky Pinkard, Angela Orebaugh

      E-bok
      2011

      634 kr

      Jacob Babbin, Simon Biles, Angela Orebaugh - Snort Cookbook, E-bok

      Snort Cookbook

      Jacob Babbin, Simon Biles, Angela Orebaugh

      E-bok
      2005

      374 kr

      Jacob Babbin, Simon Biles, Angela Orebaugh - Snort Cookbook, E-bok

      Snort Cookbook

      Jacob Babbin, Simon Biles, Angela Orebaugh

      E-bok
      2005

      374 kr

      Michael Gregg, Eric Seagren, Angela Orebaugh, Matt Jonkman, Raffael Marty - How to Cheat at Configuring Open Source Security Tools, Häftad

      How to Cheat at Configuring Open Source Security Tools

      Michael Gregg, Eric Seagren, Angela Orebaugh, Matt Jonkman, Raffael Marty

      Häftad, 2007

      710 kr

      Angela Orebaugh, Becky Pinkard - Nmap in the Enterprise, Häftad

      Nmap in the Enterprise

      Angela Orebaugh, Becky Pinkard

      Häftad, 2008

      602 kr

      Michael Rash, Angela Orebaugh, Graham Clark - Intrusion Prevention and Active Response, Häftad

      Intrusion Prevention and Active Response

      Michael Rash, Angela Orebaugh, Graham Clark

      Häftad, 2005

      710 kr

      Hoppa över listan

      Mer från samma serie

      John Viega - Secure Programming Cookbook for C & C++, Häftad

      Secure Programming Cookbook for C & C++

      John Viega

      Häftad, 2003

      561 kr

      Samuele Pedroni - Jython Essentials, Häftad

      Jython Essentials

      Samuele Pedroni

      Häftad, 2002

      265 kr

      Eric M Burke - Java Extreme Programming Cookbook, Häftad

      Java Extreme Programming Cookbook

      Eric M Burke

      Häftad, 2003

      265 kr

      Daniel J Barrett - Linux Security Cookbook, Häftad

      Linux Security Cookbook

      Daniel J Barrett

      Häftad, 2003

      302 kr

      Craig Hunt - sendmail Cookbook, Häftad

      sendmail Cookbook

      Craig Hunt

      Häftad, 2004

      376 kr

      Bruce W Perry - Java Servlet and JSP Cookbook, Häftad

      Java Servlet and JSP Cookbook

      Bruce W Perry

      Häftad, 2004

      376 kr

      Preston Gralla - Windows XP Cookbook, Häftad

      Windows XP Cookbook

      Preston Gralla

      Häftad, 2005

      339 kr

      Ken Bluttman - Access Data Analysis Cookbook, Häftad

      Access Data Analysis Cookbook

      Ken Bluttman

      Häftad, 2007

      376 kr

      Danny Goodman - JavaScript & DHTML Cookbook, Häftad

      JavaScript & DHTML Cookbook

      Danny Goodman

      Häftad, 2007

      339 kr

      Joey Lott - ActionScript 3.0 Cookbook, Häftad

      ActionScript 3.0 Cookbook

      Joey Lott

      Häftad, 2006

      302 kr

      Hoppa över listan

      Du kanske också är intresserad av

      Angela Orebaugh, Becky Pinkard - Nmap in the Enterprise, Häftad

      Nmap in the Enterprise

      Angela Orebaugh, Becky Pinkard

      Häftad, 2008

      602 kr

      Jacob Babbin, Simon Biles, Angela Orebaugh - Snort Cookbook, E-bok

      Snort Cookbook

      Jacob Babbin, Simon Biles, Angela Orebaugh

      E-bok
      2005

      374 kr

      Michael Rash, Angela Orebaugh, Graham Clark - Intrusion Prevention and Active Response, Häftad

      Intrusion Prevention and Active Response

      Michael Rash, Angela Orebaugh, Graham Clark

      Häftad, 2005

      710 kr

      Michael Gregg, Eric Seagren, Angela Orebaugh, Matt Jonkman, Raffael Marty - How to Cheat at Configuring Open Source Security Tools, Häftad

      How to Cheat at Configuring Open Source Security Tools

      Michael Gregg, Eric Seagren, Angela Orebaugh, Matt Jonkman, Raffael Marty

      Häftad, 2007

      710 kr

      Joey Lott - ActionScript 3.0 Cookbook, Häftad

      ActionScript 3.0 Cookbook

      Joey Lott

      Häftad, 2006

      302 kr

      Jacob Babbin, Simon Biles, Angela Orebaugh - Snort Cookbook, E-bok

      Snort Cookbook

      Jacob Babbin, Simon Biles, Angela Orebaugh

      E-bok
      2005

      374 kr

      Ken Bluttman - Access Data Analysis Cookbook, Häftad

      Access Data Analysis Cookbook

      Ken Bluttman

      Häftad, 2007

      376 kr

      Graham Clark, Angela Orebaugh, Michael Rash - Intrusion Prevention and Active Response, E-bok

      Intrusion Prevention and Active Response

      Graham Clark, Angela Orebaugh, Michael Rash

      E-bok
      2005

      423 kr

      Becky Pinkard, Angela Orebaugh - Nmap in the Enterprise, E-bok

      Nmap in the Enterprise

      Becky Pinkard, Angela Orebaugh

      E-bok
      2011

      634 kr

      Gilbert Ramirez, Angela Orebaugh, Jay Beale - Wireshark & Ethereal Network Protocol Analyzer Toolkit, E-bok

      Wireshark & Ethereal Network Protocol Analyzer Toolkit

      Gilbert Ramirez, Angela Orebaugh, Jay Beale

      E-bok
      2006

      423 kr