Book description
Network security is not simply about building impenetrable walls — determined attackers will eventually overcome traditional defenses. The most effective computer security strategies integrate network security monitoring (NSM): the collection and analysis of data to help you detect and respond to intrusions.
In The Practice of Network Security Monitoring, Mandiant CSO Richard Bejtlich shows you how to use NSM to add a robust layer of protection around your networks — no prior experience required. To help you avoid costly and inflexible solutions, he teaches you how to deploy, build, and run an NSM operation using open source software and vendor-neutral tools.
You'll learn how to:
- Determine where to deploy NSM platforms, and size them for the monitored networks
- Deploy stand-alone or distributed NSM installations
- Use command line and graphical packet analysis tools, and NSM consoles
- Interpret network evidence from server-side and client-side intrusions
- Integrate threat intelligence into NSM software to identify sophisticated adversaries
There's no foolproof way to keep attackers out of your network. But when they get in, you'll be prepared. The Practice of Network Security Monitoring will show you how to build a security net to detect, contain, and control them. Attacks are inevitable, but losing sensitive data shouldn't be.
Publisher resources
Table of contents
- Dedication
- Foreword
- Preface
-
I. Getting Started
- 1. Network Security Monitoring Rationale
- 2. Collecting Network Traffic: Access, Storage, and Management
- II. Security Onion Deployment
-
III. Tools
- 6. Command Line Packet Analysis Tools
- 7. Graphical Packet Analysis Tools
- 8. NSM Consoles
-
IV. NSM in Action
- 9. NSM Operations
- 10. Server-side Compromise
- 11. Client-side Compromise
-
12. Extending SO
- Using Bro to Track Executables
-
Using Bro to Extract Binaries from Traffic
- Configuring Bro to Extract Binaries from Traffic
- Collecting Traffic to Test Bro
- Testing Bro to Extract Binaries from HTTP Traffic
- Examining the Binary Extracted from HTTP
- Testing Bro to Extract Binaries from FTP Traffic
- Examining the Binary Extracted from FTP
- Submitting a Hash and Binary to VirusTotal
- Restarting Bro
- Using APT1 Intelligence
- Reporting Downloads of Malicious Binaries
- Conclusion
- 13. Proxies and Checksums
- Conclusion
-
A. SO Scripts and Configuration
-
SO Control Scripts
- /usr/sbin/nsm
- /usr/sbin/nsm_all_del
- /usr/sbin/nsm_all_del_quick
- /usr/sbin/nsm_sensor
- /usr/sbin/nsm_sensor_add
- /usr/sbin/nsm_sensor_backup-config
- /usr/sbin/nsm_sensor_backup-data
- /usr/sbin/nsm_sensor_clean
- /usr/sbin/nsm_sensor_clear
- /usr/sbin/nsm_sensor_del
- /usr/sbin/nsm_sensor_edit
- /usr/sbin/nsm_sensor_ps-daily-restart
- /usr/sbin/nsm_sensor_ps-restart
- /usr/sbin/nsm_sensor_ps-start
- /usr/sbin/nsm_sensor_ps-status
- /usr/sbin/nsm_sensor_ps-stop
- /usr/sbin/nsm_server
- /usr/sbin/nsm_server_add
- /usr/sbin/nsm_server_backup-config
- /usr/sbin/nsm_server_backup-data
- /usr/sbin/nsm_server_clear
- /usr/sbin/nsm_server_del
- /usr/sbin/nsm_server_edit
- /usr/sbin/nsm_server_ps-restart
- /usr/sbin/nsm_server_ps-start
- /usr/sbin/nsm_server_ps-status
- /usr/sbin/nsm_server_ps-stop
- /usr/sbin/nsm_server_sensor-add
- /usr/sbin/nsm_server_sensor-del
- /usr/sbin/nsm_server_user-add
-
SO Configuration Files
- /etc/nsm/
- /etc/nsm/administration.conf
- /etc/nsm/ossec/
- /etc/nsm/pulledpork/
- /etc/nsm/rules/
- /etc/nsm/securityonion/
- /etc/nsm/securityonion.conf
- /etc/nsm/sensortab
- /etc/nsm/servertab
- /etc/nsm/templates/
- /etc/nsm/$HOSTNAME-$INTERFACE/
- /etc/cron.d/
- Bro
- CapMe
- ELSA
- Squert
- Snorby
- Syslog-ng
- /etc/network/interfaces
- Index
- About the Author
- B. Updates
- Copyright
-
SO Control Scripts
Product information
- Title: The Practice of Network Security Monitoring
- Author(s):
- Release date: July 2013
- Publisher(s): No Starch Press
- ISBN: 9781593275099
You might also like
book
Applied Network Security Monitoring
Applied Network Security Monitoring is the essential guide to becoming an NSM analyst from the ground …
book
Network Security Assessment, 3rd Edition
How secure is your network? The best way to find out is to attack it, using …
book
Cyber Security and Network Security
CYBER SECUTIRY AND NETWORK SECURITY Written and edited by a team of experts in the field, …
book
The Tao of Network Security Monitoring Beyond Intrusion Detection
"The book you are about to read will arm you with the knowledge you need to …