Book details of 'Implementing Intrusion Detection Systems : A Hands-On Guide for Securing the Network '

| Title | Implementing Intrusion Detection Systems : A Hands-On Guide for Securing the Network |
| Author(s) | Tim Crothers |
| ISBN | 0764549499 |
| Language | English |
| Published | December 2002 |
| Publisher | Wiley |
Back to shelf Computer security
Amazon.com info for Implementing Intrusion Detection Systems : A Hands-On Guide for Securing the Network
The Virtual Bookcase Reviews of 'Implementing Intrusion Detection Systems : A Hands-On Guide for Securing the Network ':
Reviewer Rob Slade wrote:
The preface implies that this book is a professional reference for
building and maintaining intrusion detection systems (IDSs). I'd say
it has a fair way to go before it could make that claim.
Chapter one is an overview of intrusion detection. The basic concepts
are all included, but it is often difficult to understand the point
that the author is making. Net-based IDS gets a somewhat limited
review in chapter two, alongside a very brief introduction to TCP/IP.
There are lots of printouts of event and audit logs in chapter three
but very little explanation of the basic ideas behind host-based IDS.
Chapter four is supposed to tell us how to handle alerts, but the long
listings of packet traffic related to specific attacks (and not
interpreted particularly well) do not really provide any useful advice
on incident response. Chapters five and six raise a number of issues
to consider when planning and maintaining an IDS, but the collection
of information is neither organized nor exhaustive in terms of the
factors which need to be dealt with. Supposedly about tuning, chapter
seven is mostly about analysis of logs for an example attack. The
scripts involved in installing Snort on Linux are listed in chapter
eight.
This work is vague, unstructured, and incomplete. Yes, it would help
you get an intrusion detection system running, but it has neither the
conceptual depth of either of the two "Intrusion Detection"s, by
Amoroso (
see reviews) or Bace (
see reviews), the detail of
"Intrusion Signatures and Analysis" (
see reviews), nor even the
practicality of Koziol's "Intrusion Detection with Snort" (
see reviews).
copyright Robert M. Slade, 2003
Add my review for Implementing Intrusion Detection Systems : A Hands-On Guide for Securing the Network
Book description:
Your in-depth guide to implementing and optimizing an effective intrusion detection system for your network Here's the in-the-trenches handbook you've been looking for, loaded with information and tips from real case studies that will help you deploy, configure, and monitor an effective intrusion detection system. Step-by-step instructions guide you through the process of configuring identification and authentication, mandatory and discretionary access control, physical security, and more. You'll get practical knowledge of honeynets, IP and MAC addressing, log analysis, and IDS standards, and learn to manage network traffic volume in the IDS. Tim Crothers gives you the benefit of his own extensive experience, furnishing sample IDS deployments and professional tips that boost your efficiency. If you're responsible for network security, this is the guidebook that will help you get a good night's sleep-at last. You'll learn how to: Implement an effective IDS for host, network, and combined systems Understand challenges like evasion, unknown attacks, and false alerts Verify, test, and fine-tune intrusion detection systems Analyze various IDS products and determine what meets your organization's needs Cope with legal issues and architectural challenges Identify, verify, and respond to different types of attacks and alerts Investigate security breaches and prevent recurrences Book Info
Your in-depth guide to implementing and optimizing an effective intrusion detection system for your network. Softcover. From the Back Cover
Your in-depth guide to implementing and optimizing an effective intrusion detection system for your network Here’s the in-the-trenches handbook you’ve been looking for, loaded with information and tips from real case studies that will help you deploy, configure, and monitor an effective intrusion detection system. Step-by-step instructions guide you through the process of configuring identification and authentication, mandatory and discretionary access control, physical security, and more. You’ll get practical knowledge of honeynets, IP and MAC addressing, log analysis, and IDS standards, and learn to manage network traffic volume in the IDS. Tim Crothers gives you the benefit of his own extensive experience, furnishing sample IDS deployments and professional tips that boost your efficiency. If you’re responsible for network security, this is the guidebook that will help you get a good night’s sleep–at last. You’ll learn how to: * Implement an effective IDS for host, network, and combined systems * Understand challenges like evasion, unknown attacks, and false alerts * Verify, test, and fine-tune intrusion detection systems * Analyze various IDS products and determine what meets your organization’s needs * Cope with legal issues and architectural challenges * Identify, verify, and respond to different types of attacks and alerts * Investigate security breaches and prevent recurrences About the Author
TIM CROTHERS, CCNA, CIW, MCSE, MCT, CNE, is chief security engineer for ITM Technology, an e-security provider, and the author of Internet Lockdown. He developed the curriculum for an Internet security consulting practice he headed at Prosoft, and has also been a consultant and trainer for IBM, Lucent Technologies, DEC, and other leading organizations.