Intrusion Detection with Snort

Jack Koziol

  • 出版商: SAMS
  • 出版日期: 2003-05-20
  • 定價: $1,750
  • 售價: 6.0$1,050
  • 語言: 英文
  • 頁數: 360
  • 裝訂: Paperback
  • ISBN: 157870281X
  • ISBN-13: 9781578702817
  • 立即出貨(限量) (庫存=1)

買這商品的人也買了...

商品描述

With over 100,000 installations, the Snort open-source network instrusion detection system is combined with other free tools to deliver IDS defense to medium - to small-sized companies, changing the tradition of intrusion detection being affordable only for large companies with large budgets.

Until now, Snort users had to rely on the official guide available on snort.org. That guide is aimed at relatively experience snort administrators and covers thousands of rules and known exploits.

The lack of usable information made using Snort a frustrating experience. The average Snort user needs to learn how to actually get their systems up-and-running.

Snort Intrusion Detection provides readers with practical guidance on how to put Snort to work. Opening with a primer to intrusion detection and Snort, the book takes the reader through planning an installation to building the server and sensor, tuning the system, implementing the system and analyzing traffic, writing rules, upgrading the system, and extending Snort.

Table of Contents

1. Intrusion Detection Primer.
2. Network Intrusion Detection with Snort.
3. Dissecting Snort.
4. Planning for the Snort Installation.
5. The Foundation-Hardware and Operating Systems.
6. Building the Server.
7. Building the Sensor.
8. Building the Analyst's Console.
9. Additional Installation Methods.
10. Tuning and Reducing False Positives.
11. Real-Time Alerting.
12. Basic Rule Writing.
13. Upgrading and Maintaining Snort.
14. Advanced Topics in Intrusion Prevention.
Appendix A. Troubleshooting.
Appendix B. Rule Documentation.
Index.

商品描述(中文翻譯)

憑藉超過10萬個安裝,Snort開源網絡入侵檢測系統與其他免費工具結合,為中小型企業提供入侵檢測防禦,改變了入侵檢測只適用於有龐大預算的大型企業的傳統觀念。

到目前為止,Snort用戶只能依賴於snort.org上提供的官方指南。該指南針對相對有經驗的Snort管理員,涵蓋了數千個規則和已知的攻擊手法。

缺乏可用的信息使得使用Snort成為一種令人沮喪的經歷。普通的Snort用戶需要學習如何實際運行他們的系統。

《Snort入侵檢測》為讀者提供了實用的指導,教導如何運用Snort。從入侵檢測和Snort的基礎開始,本書引導讀者進行安裝計劃、構建服務器和傳感器、調整系統、實施系統和分析流量、編寫規則、升級系統以及擴展Snort。

目錄:

1. 入侵檢測基礎知識
2. 使用Snort進行網絡入侵檢測
3. 解析Snort
4. Snort安裝計劃
5. 基礎硬件和操作系統
6. 構建服務器
7. 構建傳感器
8. 構建分析師控制台
9. 其他安裝方法
10. 調整和減少誤報
11. 實時警報
12. 基礎規則編寫
13. 升級和維護Snort
14. 入侵防禦的高級主題
附錄A. 故障排除
附錄B. 規則文檔
索引