How to Cheat at Configuring Open Source Security Tools
Michael Gregg, Eric Seagren, Angela Orebaugh, Josh Burke, Matt JonkmanBooks.org participates in affiliate programs including Bookshop.org and the Amazon Services LLC Associates Program. We may earn a commission from qualifying purchases made through links on this page, at no additional cost to you.
Overview
The Perfect Reference for the Multitasked SysAdminThis is the perfect guide if network security tools is not your specialty. It is the perfect introduction to managing an infrastructure with freely available, and powerful, Open Source tools. Learn how to test and audit your systems using products like Snort and Wireshark and some of the add-ons available for both. In addition, learn handy techniques for network troubleshooting and protecting the perimeter.
* Take Inventory See how taking an inventory of the devices on your network must be repeated regularly to ensure that the inventory remains accurate.
* Use Nmap Learn how Nmap has more features and options than any other free scanner.
* Implement Firewalls Use netfilter to perform firewall logic and see how SmoothWall can turn a PC into a dedicated firewall appliance that is completely configurable.
* Perform Basic Hardening Put an IT security policy in place so that you have a concrete set of standards against which to measure.
* Install and Configure Snort and Wireshark Explore the feature set of these powerful tools, as well as their pitfalls and other security considerations.
* Explore Snort Add-Ons Use tools like Oinkmaster to automatically keep Snort signature files current.
* Troubleshoot Network Problems See how to reporting on bandwidth usage and other metrics and to use data collection methods like sniffing, NetFlow, and SNMP.
* Learn Defensive Monitoring Considerations See how to define your wireless network boundaries, and monitor to know if theyβre being exceeded and watch for unauthorized traffic on your network.
*Covers the top 10 most popular open source security tools including Snort, Nessus, Wireshark, Nmap, and Kismet
*Companion Web site contains dozens of working scripts and tools for readers
*Follows Syngress' proven "How to Cheat" pedagogy providing readers with everything they need and nothing they don't
Synopsis
The Perfect Reference for the Multitasked SysAdmin
This is the perfect guide if network security tools is not your specialty. It is the perfect introduction to managing an infrastructure with freely available, and powerful, Open Source tools. Learn how to test and audit your systems using products like Snort and Wireshark and some of the add-ons available for both. In addition, learn handy techniques for network troubleshooting and protecting the perimeter.
* Take Inventory See how taking an inventory of the devices on your network must be repeated regularly to ensure that the inventory remains accurate.
* Use Nmap Learn how Nmap has more features and options than any other free scanner.
* Implement Firewalls Use netfilter to perform firewall logic and see how SmoothWall can turn a PC into a dedicated firewall appliance that is completely configurable.
* Perform Basic Hardening Put an IT security policy in place so that you have a concrete set of standards against which to measure.
* Install and Configure Snort and Wireshark Explore the feature set of these powerful tools, as well as their pitfalls and other security considerations.
* Explore Snort Add-Ons Use tools like Oinkmaster to automatically keep Snort signature files current.
* Troubleshoot Network Problems See how to reporting on bandwidth usage and other metrics and to use data collection methods like sniffing, NetFlow, and SNMP.
* Learn Defensive Monitoring Considerations See how to define your wireless network boundaries, and monitor to know if they’re being exceeded and watch for unauthorized traffic on your network.
*Covers the top 10 most popular open source security tools including Snort, Nessus, Wireshark, Nmap, and Kismet
*Companion Web site contains dozens of working scripts and tools for readers
*Follows Syngress' proven "How to Cheat" pedagogy providing readers with everything they need and nothing they don't
Editorials
From Barnes & Noble
The Barnes & Noble ReviewMost sysadmins have plenty of responsibilities: network security's only one of them. But that won't save you if something goes badly wrong. This book can help you prevent that. And, since it's based on open source tools, you can use its techniques for free: no begging for budgets!
This is the stuff you need to know right now. You'll start by taking a complete inventory of your network, wired and wireless. You'll walk through securing your perimeter: firewalls, remote access, VPNs, and remote desktops. Next, you'll harden and patch the Windows and Linux systems you already have. The authors present comprehensive coverage of two powerful, mature open source security tools -- Snort intrusion detection, and Wireshark network protocol analysis. There's an extremely useful chapter on reporting and troubleshooting, too.
This whole book smells right: You can tell that these authors have been practicing what they're preaching. Bill Camarda, from the July 2007 Read Only