How to Cheat at Configuring Open Source Security Tools
Gregg, Michael; Seagren, Eric; Orebaugh, Angela; Jonkman, Matt; Marty, Raffael
In stock
Regular price
19.250 KD
inc. VAT
Couldn't load pickup availability
Table of contents
- Cover
- Contentsix
- Chapter 1. Testing and Auditing Your Systems1
- Introduction2
- Taking Inventory2
- Vulnerability Scanning23
- OSSTMM34
- Summary36
- Solutions Fast Track36
- Frequently Asked Questions37
- Chapter 2. Protecting Your Perimeter39
- Introduction40
- Firewall Types40
- Firewall Architectures41
- Implementing Firewalls45
- Providing Secure Remote Access85
- Summary117
- Solutions Fast Track117
- Frequently Asked Questions119
- Chapter 3. Protecting Network Resources121
- Introduction122
- Performing Basic Hardening122
- Hardening Windows Systems125
- Hardening Linux Systems142
- Hardening Infrastructure Devices151
- Patching Systems152
- Personal Firewalls154
- Providing Antivirus and Antispyware Protection161
- Encrypting Sensitive Data170
- Summary176
- Solutions Fast Track176
- Frequently Asked Questions178
- Chapter 4. Introducing Snort181
- Introduction182
- How an IDS Works183
- Where Snort Fits185
- Snort System Requirements186
- Exploring Snort's Features188
- Using Snort on Your Network195
- Security Considerations with Snort207
- Summary210
- Solutions Fast Track210
- Frequently Asked Questions211
- Chapter 5. Installing Snort 2.6213
- Introduction214
- Choosing the Right OS214
- Hardware Platform Considerations230
- Installing Snort235
- Configuring Snort243
- Testing Snort254
- Maintaining Snort257
- Updating Snort259
- Summary260
- Solutions Fast Track260
- Frequently Asked Questions262
- Chapter 6. Configuring Snort and Add-Ons263
- Placing Your NIDS264
- Configuring Snort on a Windows System266
- Configuring Snort on a Linux System280
- Demonstrating Effectiveness293
- Summary294
- Solutions Fast Track295
- Frequently Asked Questions296
- Chapter 7. Introducing Wireshark: Network Protocol Analyzer297
- Introduction298
- What is Wireshark?298
- Supporting Programs310
- Using Wireshark in Your Network Architecture315
- Using Wireshark for Network Troubleshooting317
- Using Wireshark for System Administration320
- Securing Ethereal323
- Optimizing Wireshark324
- Advanced Sniffing Techniques325
- Securing Your Network from Sniffers328
- Employing Detection Techniques330
- Summary332
- Solutions Fast Track332
- Frequently Asked Questions334
- Chapter 8. Getting and Installing Wireshark337
- Introduction338
- Getting Wireshark338
- Packet Capture Drivers340
- Installing Wireshark on Windows346
- Installing Wireshark on Linux347
- Installing Wireshark on Mac OSX349
- Installing Wireshark from Source355
- Summary360
- Solutions Fast Track360
- Frequently Asked Questions362
- Chapter 9. Using Wireshark363
- Introduction364
- Getting Started with Wireshark364
- Exploring the Main Window365
- Other Window Components371
- Exploring the Menus373
- View385
- Go392
- Capture393
- Analyze403
- Statistics413
- Help428
- Pop-up Menus433
- Using Command-line Options437
- Summary439
- Solutions Fast Track439
- Frequently Asked Questions440
- Chapter 10. Network Reporting and Troubleshooting with other Tools443
- Introduction444
- Reporting on Bandwidth Usage and Other Metrics444
- Collecting Data for Analysis445
- Understanding SNMP447
- Troubleshooting Network Problems from the Command Line468
- Additional Troubleshooting Tools472
- Summary474
- Solutions Fast Track475
- Frequently Asked Questions476
- Chapter 11. Wireless Monitoring and Intrusion Detection477
- Introduction478
- Designing for Detection478
- Defensive Monitoring Considerations480
- Intrusion Detection Strategies485
- Conducting Vulnerability Assessments491
- Incident Response and Handling494
- Conducting Site Surveys for Rogue Access Points497
- Summary501
- Solutions Fast Track502
- Frequently Asked Questions503
- Index505
Book details
- Vendor Elsevier S & T
- SKU 9781597491709
- ISBN-13 9780080553566
- Author Gregg, Michael; Seagren, Eric; Orebaugh, Angela; Jonkman, Matt; Marty, Raffael
- Category Computers
- Subject General
Do you have questions about this book?
The Perfect Reference for the Multitasked SysAdmin
This is the perfect guide if network security tools is not your specialty. It is the perfect introduction to managing an infrastructure with freely available, and powerful, Open Source tools. Learn how to test and audit your systems using products like Snort and Wireshark and some of the add-ons available for both. In addition, learn handy techniques for network troubleshooting and protecting the perimeter.
* Take Inventory
See how taking an inventory of the devices on your network must be repeated regularly to ensure that the inventory remains accurate.
* Use Nmap
Learn how Nmap has more features and options than any other free scanner.
* Implement Firewalls
Use netfilter to perform firewall logic and see how SmoothWall can turn a PC into a dedicated firewall appliance that is completely configurable.
* Perform Basic Hardening
Put an IT security policy in place so that you have a concrete set of standards against which to measure.
* Install and Configure Snort and Wireshark
Explore the feature set of these powerful tools, as well as their pitfalls and other security considerations.
* Explore Snort Add-Ons
Use tools like Oinkmaster to automatically keep Snort signature files current.
* Troubleshoot Network Problems
See how to reporting on bandwidth usage and other metrics and to use data collection methods like sniffing, NetFlow, and SNMP.
* Learn Defensive Monitoring Considerations
See how to define your wireless network boundaries, and monitor to know if they’re being exceeded and watch for unauthorized traffic on your network.
*Covers the top 10 most popular open source security tools including Snort, Nessus, Wireshark, Nmap, and Kismet
*Companion Web site contains dozens of working scripts and tools for readers
*Follows Syngress' proven "How to Cheat" pedagogy providing readers with everything they need and nothing they don't
This is the perfect guide if network security tools is not your specialty. It is the perfect introduction to managing an infrastructure with freely available, and powerful, Open Source tools. Learn how to test and audit your systems using products like Snort and Wireshark and some of the add-ons available for both. In addition, learn handy techniques for network troubleshooting and protecting the perimeter.
* Take Inventory
See how taking an inventory of the devices on your network must be repeated regularly to ensure that the inventory remains accurate.
* Use Nmap
Learn how Nmap has more features and options than any other free scanner.
* Implement Firewalls
Use netfilter to perform firewall logic and see how SmoothWall can turn a PC into a dedicated firewall appliance that is completely configurable.
* Perform Basic Hardening
Put an IT security policy in place so that you have a concrete set of standards against which to measure.
* Install and Configure Snort and Wireshark
Explore the feature set of these powerful tools, as well as their pitfalls and other security considerations.
* Explore Snort Add-Ons
Use tools like Oinkmaster to automatically keep Snort signature files current.
* Troubleshoot Network Problems
See how to reporting on bandwidth usage and other metrics and to use data collection methods like sniffing, NetFlow, and SNMP.
* Learn Defensive Monitoring Considerations
See how to define your wireless network boundaries, and monitor to know if they’re being exceeded and watch for unauthorized traffic on your network.
*Covers the top 10 most popular open source security tools including Snort, Nessus, Wireshark, Nmap, and Kismet
*Companion Web site contains dozens of working scripts and tools for readers
*Follows Syngress' proven "How to Cheat" pedagogy providing readers with everything they need and nothing they don't
Instant delivery by email
Your access email arrives within minutes of checkout, with a sign-in link for each book — no shipping, no waiting.
Read on any device
Books open in VitalSource Bookshelf on your phone, tablet, or computer, online or offline. Your library is always available at aafaq.vitalsource.com — just log in with the email you used at checkout.
Lost the email?
Resend it to yourself in seconds from My eBook orders, or email cs@aafaqeducation.com and we'll help.