doctornuke home page

Search Advanced SearchView Cart   Checkout   
 Location:  Home » books » Encryption » Intrusion Detection with SNORT: Advanced IDS Techniques Using SNORT, Apache, MySQL, PHP, and ACID (Bruce Perens' Open Source Series)  
safe buy by amazon
Categories
books
ipod
hdtv
musical inst.
speakers
dvd
mobile phone
imac
macbook
notebook
circuit kits
cameras
software
kindle
Related Categories
• Encryption
Security & Encryption
Web Development
Computers & Internet
Subjects
• PHP
Programming
Web Development
Computers & Internet
Subjects
• Privacy
Business & Culture
Computers & Internet
Subjects
Books
• Network Security
Networking
Computers & Internet
Subjects
Books
• General
Networks, Protocols & APIs
Networking
Computers & Internet
Subjects
• MySQL & mSQL
Specific Databases
Databases
Computers & Internet
Subjects
• General
Computers & Internet
Subjects
Books
• General
E-commerce
Industries & Professions
Business & Investing
Subjects
• Networking
Computer Science
New & Used Textbooks
Custom Stores
Specialty Stores
• Qualifying Textbooks
Custom Stores
Specialty Stores
Books
• Paperback
Binding (binding)
Refinements
Books
• Printed Books
Format (feature_browse-bin)
Refinements
Books
Subcategories
All Titles
Arts & Photography
Biographies & Memoirs
Business & Investing
Children's Books
Computers & Internet
Cooking, Food & Wine
Engineering
Entertainment
Gay & Lesbian
General AAS
Home & Garden
Literature & Fiction
Medicine
Nonfiction
Outdoors & Nature
Parenting & Families
Professional
Reference
Religion & Spirituality
Science
Teens
Travel
Mass Market
Trade
dn shop

Intrusion Detection with SNORT: Advanced IDS Techniques Using SNORT, Apache, MySQL, PHP, and ACID (Bruce Perens' Open Source Series)

Intrusion Detection with SNORT: Advanced IDS Techniques Using SNORT, Apache, MySQL, PHP, and ACID (Bruce Perens' Open Source Series)

zoom enlarge 
Author: Rafeeq Ur Rehman
Publisher: Prentice Hall PTR
Category: Book

List Price: $44.99
Buy New: $18.25
You Save: $26.74 (59%)



New (20) Used (15) from $7.54

Rating: 3.5 out of 5 stars 7 reviews
Sales Rank: 391851

Media: Paperback
Number Of Items: 1
Pages: 288
Shipping Weight (lbs): 1
Dimensions (in): 9 x 7 x 0.7

ISBN: 0131407333
Dewey Decimal Number: 005
UPC: 076092023302
EAN: 9780131407336
ASIN: 0131407333

Publication Date: May 18, 2003
Availability: Usually ships in 1-2 business days
Shipping: Expedited shipping available
Condition: W4UP - NEW

Similar Items:

  • Managing Security with Snort and IDS Tools
  • Intrusion Detection with Snort
  • Snort Intrusion Detection and Prevention Toolkit (Jay Beale's Open Source Security)
  • Snort Cookbook
  • Snort for Dummies

Editorial Reviews:

Product Description
Network security has become an important part of corporate IT strategy and safeguarding all the nooks and crannies of your network can be timely and expensive. This book provides information about how to use free Open Source tools to build and manage an Intrusion Detection System. Rehman provides detailed information about using SNORT as an IDS and using Apache, MySQL, PHP and ACID to analyze intrusion data. The book contains custom scripts, real-life examples for SNORT, and to-the-point information about installing SNORT IDS so readers can build and run their sophisticated intrusion detection systems.SNORT is your network's packet sniffer that monitors network traffic in real time, scrutinizing each packet closely to detect a dangerous payload or suspicious anomalies.NSS Group, a European network security testing organization, tested SNORT along with intrusion detection system (IDS) products from 15 major vendors including Cisco, Computer Associates, and Symantec. According to NSS, SNORT, which was the sole Open Source freeware product tested, clearly outperformed the proprietary products.


Customer Reviews:   Read 2 more reviews...

4 out of 5 stars Good IDS|Snort book   August 14, 2003
 5 out of 7 found this review helpful

This book is an effective introduction to Intruder Detection, demonstrating how popular open-source tools can be used. I found the code samples, table, diagrams and screenshots to be clear and useful. I learned what I'd hoped to learn and feel empowered to set up an IDS myself. Plenty of links and resources when I want to learn more.

I read a few of the other reviews here after I read the book... especially Richard B's. I noticed some of the same techinical mistakes, but don't feel that they are a big deal. As a sr. software engineer and techinical editor, I always read critically, just mentally note them and continue. They aren't the kind of mistakes that make the code useless, or would confuse/mislead any level of reader. Another editing pass would help most books, and I none of the grammar mistakes annoy me - I read to learn what I can and move on, not to nitpick or get annoyed.

As far as 1.9 vs. 2.0, I've looked at the snort site and agree that the release is signficant, but it doesn't break backwards compatibility, so it doesn't make this book any less revelant. 2.0 seems to mostly change the backend implementation - *the application is used identically* so I suspect the vast majority of this book is unaffected. The Syngress book covers 2.0, yet so does the website, which hypes this two-times-more-expensive book. That book too will no doubt soon be superceded, so read whatever you buy immediately ;-)


5 out of 5 stars Great hands-on coverage of snort   August 2, 2003
 3 out of 6 found this review helpful

I really like books that are to the point and filled with examples. This is such a book. It enables the reader to get up and going quickly. The reader is guided through installation and each component of SNORT. Once the basics are covered, the author moves to more advanced topics and integrating other tools like Apache, MySQL, and ACID. All told, it presents an excellent approach to building an IDS.


3 out of 5 stars Weakest of the Snort books published thus far   July 16, 2003
 18 out of 21 found this review helpful

"Intrusion Detection with Snort: Advanced IDS, etc." (IDWS) was the second of this year's intrusion detection books I've reviewed. The first was Tim Crothers' "Implementing Intrusion Detection Systems" (4 stars). I was disappointed by IDWS, since I have a high opinion of Prentice Hall and the new "Bruce Perens' Open Source Series." (I'm looking forward to the book on CIFS, for example.) IDWS read poorly and doesn't deliver as much useful content as the competing Syngress book "Snort 2.0."

The most difficult aspect of reading IDWS is the author's grammar, particularly his avoidance of using definitive articles like "the", and other important words. For instance, p. 3 says "Apache web server takes help from ACID, etc." p. 133 claims "However, if you are using HTTP decode preprocessor, this attempt can detected." Beyond grammar, the author demonstrates weak knowledge of the IDS field, stating on p. 1 "Intrusion detection methods starting appearing in the last few years." James Anderson led the way in 1980, followed by Denning and Neumann in 1983 and Todd Heberlein in 1990! The author also repeatedly compares IDS to anti-virus signatures, which is simplistic and incorrect.

Technical errors further hamper IDWS. p. 89 makes the mistake of saying TCP sequence numbers count packets; they really count bytes of application data. p. 96-97 confuses the use of standard Boolean operators (AND, OR, NOT) with their use in Snort, which is different. (SF+ means SYN and FIN and zero or more other flags, not SYN AND FIN alone.) The fuzzy diagrams don't appear professional, and acronyms like "PHP" are defined incorrectly as "Pretty Home Page" (rather than the self-referencing "PHP Hypertext Processor.")

Coverage of important topics is lacking or outdated. First, Snort 1.9 is the basis for the text. However, 2.0 is available and covered by the Syngress book. The output system Barnyard and unified logging receive a total of one page. No meaningful mention is made of the effects of collecting traffic via hub, SPAN port, or tap. The port list on pp. 87-88 shows "well known ports," but doesn't say if they are TCP or UDP. The author makes odd claims about Snort "not [being] able to analyze application layer protocols," which is misleading. Snort rules aren't designed specifically for HTTP, for example, but they can be used to inspect HTTP requests and responses.

My favorite part of IDWS was the coverage of using the MySQL database. Appendix B provides helpful supplemental material on this subject also. Bottom line: I would pass on IDWS but keep an eye on the other titles in the PHPTR "Open Source Series."



2 out of 5 stars Not enough detail, and not up to date   May 28, 2003
 11 out of 15 found this review helpful

This is the first book that I read on Snort, and I wish I had gone with something else. This book really reads like more of an overview of intrusion detection and Snort, rather than a useful reference for actually using Snort. This would be fine if the title did NOT include the words "Advanced" or "Techniques," because there is not a lot of either in this book. It also doesn't help that it's not written to the latest release. If you want to understand intrusion detection a little better and you are considering to try Snort, then this books is fine. If you want or need more, this just isn't the book.


2 out of 5 stars Just OK   May 23, 2003
 8 out of 13 found this review helpful

I got this book and read through it (didn't take me long. It's pretty short and actually has less than 200 pages really covering Snort). I was disappointed that it did not come with a CD with all the software. Also, this book covers Snort 1.9.0, but 2.0 just came out. I'm not sure why they didn't update everything to the latest version, which would have made it much more usefel. I guess it's not bad if you really just want a quick introduction to IDSs and Snort, but look elsewhere if you really want an in depth book on Snort.

amazon store
Save money with InstrumentPro special promotions. Buy Tascam from Our affiliate store , safe up to 30%!


seo by doctornuke at TH

about us | privacy policy | terms and conditions

Doctornuke store , tech , php books , softwares , ipod , iphone , circuit , mobile phone , computer
notebooks , imac , accessories and apparels
credit card
amazon astore affiliates
sponsored links
XELODA Official Site - Sponsored Link
Ad - www.xeloda.com Aug 30 2008 8:03AM GMT
Review: Palm Treo Pro
Smart Phone Today Aug 30 2008 8:03AM GMT
Apple iPhone triggers a smartphone deluge
Economictimes Aug 30 2008 7:46AM GMT
Apple iPhone customers might soon be able to send and receive instant messages after the company files for a patent.
HalfLifeSource Aug 30 2008 7:16AM GMT
Apple works on iPhone glitches
Conde Nast Portfolio Aug 30 2008 7:11AM GMT
Palm on top of Treo 800w updates
Mobility Today Aug 30 2008 7:07AM GMT
7 iPhone 3G's and now I get green photos?
Mobility Today Aug 30 2008 7:07AM GMT
Palm on top of Treo 800w upd...
Mobility Today Aug 30 2008 7:06AM GMT
7 iPhone 3G's and now I get...
Mobility Today Aug 30 2008 7:06AM GMT
Apple to Fix iPhone Security Loophole
Earthweb News Aug 30 2008 6:26AM GMT
More Antenna Tests: iPhone Antenna Still in the Clear
RealTechNews Aug 30 2008 6:25AM GMT
iPhone girl scared by attention
Ein News Aug 30 2008 6:14AM GMT
Apple trying to fix iPhone flaw that lets unauthorized users gain access
Ein News Aug 30 2008 6:12AM GMT
BlackBerry Bold on AT&T pushed to October?
Electronista Aug 30 2008 6:06AM GMT
Samsung software speeds up smartphone memories
I Appliance Web Aug 30 2008 5:43AM GMT
iPhone 3G Snags Keeping RIM's New Bold at Bay?
Datamation Aug 30 2008 5:31AM GMT
Apple to Fix iPhone Security Loophole
Datamation Aug 30 2008 5:31AM GMT
Unlucky iPhoner twiddles thumbs for 8-hour sync
TechRadar.com Aug 30 2008 5:15AM GMT
iPhone girl scared by attention
Computing.co.uk Aug 30 2008 5:02AM GMT
Is The iPhone Coming To China?
Ein News Aug 30 2008 4:44AM GMT
Zimbra Boosts Up iPhone Support
SDA India Aug 30 2008 4:21AM GMT
HTC Plans of Yet Another Smartphone FULL STORY
SDA India Aug 30 2008 4:20AM GMT
Systeme U Selects Aldata G.O.L.D. Vocal PDA
Ein News Aug 30 2008 4:12AM GMT
Apple Delays Fix for iPhone Flaw
Ein News Aug 30 2008 4:12AM GMT
Why this iPhone fever?
Computerworld Singapore Aug 30 2008 3:58AM GMT
China Mobile to Subsidize iPhone
Ein News Aug 30 2008 3:51AM GMT
AT&T launches Microsoft System Center MDM 2008 for Windows smartphones
Computer Business Review Aug 30 2008 3:50AM GMT
Apple nearing China iPhone deal
Ein News Aug 30 2008 3:47AM GMT
A BlackBerry Phone Named Desired
Ein News Aug 30 2008 3:29AM GMT
Samsung Ultraslim TV Looks Like Giant iPhone 3G
Gizmodo Aug 30 2008 3:24AM GMT
iPhone girl scared by attention
IT News Australia Aug 30 2008 3:23AM GMT