doctornuke home page

Search Advanced SearchView Cart   Checkout   
 Location:  Home » books » Intrusion Detection with SNORT: Advanced IDS Techniques Using SNORT, Apache, MySQL, PHP, and ACID (Bruce Perens' Open Source Series)  
safe buy by amazon
Categories
books
ipod
hdtv
musical inst.
speakers
dvd
mobile phone
imac
macbook
notebook
circuit kits
cameras
software
kindle
Subcategories
Accounting
Audiobooks
Biography & History
Business Life
By Publisher
Economics
Finance
General
Industries & Professions
International
Investing
Job Hunting & Careers
Management & Leadership
Marketing & Sales
Organizational Behavior
Personal Finance
Popular Economics
Real Estate
Reference
Skills
Small Business & Entrepreneurship
Women & Business
New Releases
Six Disciplines Execution Revolution: Solving the One Business Problem That Makes Solving All Other Problems Easier
Killing Sacred Cows: Overcoming the Financial Myths That Are Destroying Your Prosperity
The Shock Doctrine: The Rise of Disaster Capitalism
Nickel and Dimed: On (Not) Getting By in America
Yes!: 50 Scientifically Proven Ways to Be Persuasive
Will Work from Home: Earn the Cash--Without the Commute
When Markets Collide: Investment Strategies for the Age of Global Economic Change
The Unofficial Guide Walt Disney World 2009 (Unofficial Guides)
Words That Work, Revised, Updated Edition: It's Not What You Say, It's What People Hear
Ahead of the Curve: Two Years at Harvard Business School
Bestsellers
Six Disciplines Execution Revolution: Solving the One Business Problem That Makes Solving All Other Problems Easier
Three Cups of Tea: One Man's Mission to Promote Peace . . . One School at a Time
StrengthsFinder 2.0: A New and Upgraded Edition of the Online Test from Gallup's Now, Discover Your Strengths
Good to Great: Why Some Companies Make the Leap... and Others Don't
Killing Sacred Cows: Overcoming the Financial Myths That Are Destroying Your Prosperity
The 7 Habits of Highly Effective People
The 4-Hour Workweek: Escape 9-5, Live Anywhere, and Join the New Rich
Getting Things Done: The Art of Stress-Free Productivity
Managerial Accounting
The Tipping Point: How Little Things Can Make a Big Difference
dn shop

Intrusion Detection with SNORT: Advanced IDS Techniques Using SNORT, Apache, MySQL, PHP, and ACID (Bruce Perens' Open Source Series)

Intrusion Detection with SNORT: Advanced IDS Techniques Using SNORT, Apache, MySQL, PHP, and ACID (Bruce Perens' Open Source Series)

zoom enlarge 
Author: Rafeeq Ur Rehman
Publisher: Prentice Hall PTR
Category: Book

List Price: $44.99
Buy New: $18.25
You Save: $26.74 (59%)



New (19) Used (12) from $9.53

Rating: 3.5 out of 5 stars 7 reviews
Sales Rank: 754952

Media: Paperback
Number Of Items: 1
Pages: 288
Shipping Weight (lbs): 1
Dimensions (in): 9 x 7 x 0.7

ISBN: 0131407333
Dewey Decimal Number: 005
UPC: 076092023302
EAN: 9780131407336
ASIN: 0131407333

Publication Date: May 18, 2003
Availability: Usually ships in 1-2 business days
Shipping: Expedited shipping available
Condition: W4UP - NEW

Editorial Reviews:

Product Description
Network security has become an important part of corporate IT strategy and safeguarding all the nooks and crannies of your network can be timely and expensive. This book provides information about how to use free Open Source tools to build and manage an Intrusion Detection System. Rehman provides detailed information about using SNORT as an IDS and using Apache, MySQL, PHP and ACID to analyze intrusion data. The book contains custom scripts, real-life examples for SNORT, and to-the-point information about installing SNORT IDS so readers can build and run their sophisticated intrusion detection systems.SNORT is your network's packet sniffer that monitors network traffic in real time, scrutinizing each packet closely to detect a dangerous payload or suspicious anomalies.NSS Group, a European network security testing organization, tested SNORT along with intrusion detection system (IDS) products from 15 major vendors including Cisco, Computer Associates, and Symantec. According to NSS, SNORT, which was the sole Open Source freeware product tested, clearly outperformed the proprietary products.


Customer Reviews:   Read 2 more reviews...

4 out of 5 stars Good IDS|Snort book   August 14, 2003
 5 out of 7 found this review helpful

This book is an effective introduction to Intruder Detection, demonstrating how popular open-source tools can be used. I found the code samples, table, diagrams and screenshots to be clear and useful. I learned what I'd hoped to learn and feel empowered to set up an IDS myself. Plenty of links and resources when I want to learn more.

I read a few of the other reviews here after I read the book... especially Richard B's. I noticed some of the same techinical mistakes, but don't feel that they are a big deal. As a sr. software engineer and techinical editor, I always read critically, just mentally note them and continue. They aren't the kind of mistakes that make the code useless, or would confuse/mislead any level of reader. Another editing pass would help most books, and I none of the grammar mistakes annoy me - I read to learn what I can and move on, not to nitpick or get annoyed.

As far as 1.9 vs. 2.0, I've looked at the snort site and agree that the release is signficant, but it doesn't break backwards compatibility, so it doesn't make this book any less revelant. 2.0 seems to mostly change the backend implementation - *the application is used identically* so I suspect the vast majority of this book is unaffected. The Syngress book covers 2.0, yet so does the website, which hypes this two-times-more-expensive book. That book too will no doubt soon be superceded, so read whatever you buy immediately ;-)


5 out of 5 stars Great hands-on coverage of snort   August 2, 2003
 3 out of 6 found this review helpful

I really like books that are to the point and filled with examples. This is such a book. It enables the reader to get up and going quickly. The reader is guided through installation and each component of SNORT. Once the basics are covered, the author moves to more advanced topics and integrating other tools like Apache, MySQL, and ACID. All told, it presents an excellent approach to building an IDS.


3 out of 5 stars Weakest of the Snort books published thus far   July 16, 2003
 18 out of 21 found this review helpful

"Intrusion Detection with Snort: Advanced IDS, etc." (IDWS) was the second of this year's intrusion detection books I've reviewed. The first was Tim Crothers' "Implementing Intrusion Detection Systems" (4 stars). I was disappointed by IDWS, since I have a high opinion of Prentice Hall and the new "Bruce Perens' Open Source Series." (I'm looking forward to the book on CIFS, for example.) IDWS read poorly and doesn't deliver as much useful content as the competing Syngress book "Snort 2.0."

The most difficult aspect of reading IDWS is the author's grammar, particularly his avoidance of using definitive articles like "the", and other important words. For instance, p. 3 says "Apache web server takes help from ACID, etc." p. 133 claims "However, if you are using HTTP decode preprocessor, this attempt can detected." Beyond grammar, the author demonstrates weak knowledge of the IDS field, stating on p. 1 "Intrusion detection methods starting appearing in the last few years." James Anderson led the way in 1980, followed by Denning and Neumann in 1983 and Todd Heberlein in 1990! The author also repeatedly compares IDS to anti-virus signatures, which is simplistic and incorrect.

Technical errors further hamper IDWS. p. 89 makes the mistake of saying TCP sequence numbers count packets; they really count bytes of application data. p. 96-97 confuses the use of standard Boolean operators (AND, OR, NOT) with their use in Snort, which is different. (SF+ means SYN and FIN and zero or more other flags, not SYN AND FIN alone.) The fuzzy diagrams don't appear professional, and acronyms like "PHP" are defined incorrectly as "Pretty Home Page" (rather than the self-referencing "PHP Hypertext Processor.")

Coverage of important topics is lacking or outdated. First, Snort 1.9 is the basis for the text. However, 2.0 is available and covered by the Syngress book. The output system Barnyard and unified logging receive a total of one page. No meaningful mention is made of the effects of collecting traffic via hub, SPAN port, or tap. The port list on pp. 87-88 shows "well known ports," but doesn't say if they are TCP or UDP. The author makes odd claims about Snort "not [being] able to analyze application layer protocols," which is misleading. Snort rules aren't designed specifically for HTTP, for example, but they can be used to inspect HTTP requests and responses.

My favorite part of IDWS was the coverage of using the MySQL database. Appendix B provides helpful supplemental material on this subject also. Bottom line: I would pass on IDWS but keep an eye on the other titles in the PHPTR "Open Source Series."



2 out of 5 stars Not enough detail, and not up to date   May 28, 2003
 11 out of 15 found this review helpful

This is the first book that I read on Snort, and I wish I had gone with something else. This book really reads like more of an overview of intrusion detection and Snort, rather than a useful reference for actually using Snort. This would be fine if the title did NOT include the words "Advanced" or "Techniques," because there is not a lot of either in this book. It also doesn't help that it's not written to the latest release. If you want to understand intrusion detection a little better and you are considering to try Snort, then this books is fine. If you want or need more, this just isn't the book.


2 out of 5 stars Just OK   May 23, 2003
 8 out of 13 found this review helpful

I got this book and read through it (didn't take me long. It's pretty short and actually has less than 200 pages really covering Snort). I was disappointed that it did not come with a CD with all the software. Also, this book covers Snort 1.9.0, but 2.0 just came out. I'm not sure why they didn't update everything to the latest version, which would have made it much more usefel. I guess it's not bad if you really just want a quick introduction to IDSs and Snort, but look elsewhere if you really want an in depth book on Snort.

amazon store
Save money with InstrumentPro special promotions. Buy Tascam from Our affiliate store , safe up to 30%!


seo by doctornuke at TH

about us | privacy policy | terms and conditions

Doctornuke store , tech , php books , softwares , ipod , iphone , circuit , mobile phone , computer
notebooks , imac , accessories and apparels
credit card
amazon astore affiliates
sponsored links
Equifax ID Patrol - Sponsored Link
Ad - www.equifax.com Aug 22 2008 12:27AM GMT
Apple adds HyperOffice to iPhone Web App Line-up
Mobile Tech Review Aug 22 2008 12:27AM GMT
iPhone News: Steve Jobs Announces OS Update Coming in September
Mobile Tech Review Aug 22 2008 12:27AM GMT
Baichung to become Vodafone's first iPhone 3G customer in Kolkata
Webindia123 Aug 22 2008 12:21AM GMT
NEWS: White iPhone goes on sale at Carphone Warehouse
Pocket-lint.co.uk Aug 22 2008 12:16AM GMT
iPhone App Store and Web apps a hit with users
Macworld Aug 22 2008 12:12AM GMT
Apple sued over iPhone 3G reception issues
Presentation Master Aug 22 2008 12:11AM GMT
LinkedIn launches an iPhone app
Presentation Master Aug 22 2008 12:11AM GMT
iPhone 3G owner sues Apple over dropped calls, slow speeds
Good Gear Guide Aug 22 2008 12:07AM GMT
Palm unwraps the unlocked 3G Treo Pro
NetworkWorld Aug 22 2008 12:06AM GMT
Apple Sued For Dropped Calls on iPhone 3G
Hard OCP Aug 22 2008 12:04AM GMT
Fake Lines for Polish iPhone Launch
Hard OCP Aug 22 2008 12:03AM GMT
Apple Signs iPhone Deal In Russia
Red Herring Aug 22 2008 12:01AM GMT
iPhone 3G owner sues Apple over dropped calls, slow speeds
ARNnet Aug 21 2008 11:53PM GMT
iPhone 3G owner sues Apple over dropped calls, slow speeds
Australian PC World Aug 21 2008 11:51PM GMT
Facebook 2.0 for iPhone ? Details, Screenshots
Softpedia Aug 21 2008 11:50PM GMT
At the stroke of midnight, India says hello to iPhone
Ein News Aug 21 2008 11:19PM GMT
High-end BlackBerry Bold a business smartphone looking to attract some consumers
Sympatico Aug 21 2008 11:17PM GMT
Palm goes pro
ZDNet Asia Aug 21 2008 11:12PM GMT
High-end BlackBerry Bold a business smartphone looking to attract some consumers
Canoe Money Aug 21 2008 11:07PM GMT
Baichung to become Vodafone's first iPhone 3G customer in Kolkata
Deepika Global Aug 21 2008 11:05PM GMT
Airtel to launch iPhone at midnight; prices 8GB for Rs 31,000
Deepika Global Aug 21 2008 11:04PM GMT
iPhone 3G officially launches in RP
Philippine Daily Inquirer Aug 21 2008 11:02PM GMT
iPhone News: Steve Jobs An...
Mobile Tech Review Aug 21 2008 10:59PM GMT
High-end BlackBerry Bold a business smartphone looking to attract some consumers
Yahoo! Canada Aug 21 2008 10:58PM GMT
Actors paid to line up for iPhone launch in Poland (Reuters)
Yahoo! News Australia Aug 21 2008 10:57PM GMT
Apple, MTS agree on iPhone sales in Russia: source (Reuters)
Yahoo! News Australia Aug 21 2008 10:57PM GMT
Band for iPhone
NetworkWorld Aug 21 2008 10:53PM GMT
High - end BlackBerry Bold a business smartph...
Canadian Business Magazine Aug 21 2008 10:52PM GMT
Actors paid to line up for iPhone in Poland
stuff.co.nz Aug 21 2008 10:49PM GMT
Apple iPhone 3G makes its India debut
Reuters India Aug 21 2008 10:47PM GMT