Cyber Threat Hunting

Alfardan, Nadhem

  • 出版商: Manning
  • 出版日期: 2024-08-27
  • 售價: $2,300
  • 貴賓價: 9.5$2,185
  • 語言: 英文
  • 頁數: 425
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 163343947X
  • ISBN-13: 9781633439474
  • 尚未上市,歡迎預購

相關主題

商品描述

Follow the clues, track down the bad actors trying to access your systems, and uncover the chain of evidence left by even the most careful adversary. This practical guide to cyber threat hunting gives a reliable and repeatable framework to see and stop attacks.

In Cyber Threat Hunting you will learn how to:

  • Design and implement a cyber threat hunting framework
  • Think like your adversaries
  • Conduct threat hunting expeditions
  • Streamline how you work with other cyber security teams
  • Structure threat hunting expeditions without losing track of activities and clues
  • Use statistics and machine learning techniques to hunt for threats

Organizations that actively seek out security intrusions reduce the time that bad actors spend on their sites, increase their cyber resilience, and build strong resistance to sophisticated covert threats. Cyber Threat Hunting teaches you to recognize attempts to access your systems by seeing the clues your adversaries leave behind. It lays out the path to becoming a successful cyber security threat hunter, guiding you from your very first expedition to hunting in complex cloud-native environments.

Purchase of the print book includes a free eBook in PDF, Kindle, and ePub formats from Manning Publications.

About the technology

There's no question about whether your security will come under attack. It already is. The real question is whether you'll recognize and learn from the attacks when they occur. Cyber threat hunting makes the assumption that a system has been hacked and reveals the signs that have evaded detection tools, or been dismissed as unimportant. In the constantly evolving landscape of modern security, threat hunting is a vital practice to avoid complacency and harden your defenses against attack.

About the book

Cyber Threat Hunting teaches you how to identify potential breaches of your security. You'll learn by exploring real-life scenarios drawn from author Nadhem AlFardan's twenty years in information security. Beginning with the fundamentals, you'll build a practical hunting framework and discover good practices for optimizing and improving expeditions. You'll learn how to employ advanced techniques that draw on machine learning and statistical analysis to help spot anomalies. Best of all, this practical book comes with downloadable datasets and scenario templates so you can practice and hone your threat hunting techniques.

About the reader

For security, network, and systems professionals familiar with security tools and Python.

About the author

Dr. Nadhem AlFardan is a principal cyber security architect leading the security operation center practice for Cisco. Dr. AlFardan leads large security operations center programs for major organizations across several APAC, EMEA and the Americas. His role includes helping customers establish and enhance their cyber threat hunting practice.

商品描述(中文翻譯)

跟隨線索,追蹤試圖進入您系統的不良行為者,並揭示即使是最謹慎的對手留下的證據鏈。這本實用的網絡威脅狩獵指南提供了一個可靠且可重複使用的框架,以查看並阻止攻擊。

在《網絡威脅狩獵》中,您將學習如何:
- 設計和實施網絡威脅狩獵框架
- 與對手思考
- 進行威脅狩獵遠征
- 簡化與其他網絡安全團隊的合作方式
- 在不失去活動和線索的情況下組織威脅狩獵遠征
- 使用統計和機器學習技術尋找威脅

積極尋找安全入侵的組織可以減少不良行為者在其網站上花費的時間,增強其網絡韌性,並對複雜的隱蔽威脅建立強大的抵抗力。《網絡威脅狩獵》教您通過觀察對手留下的線索來識別試圖進入您系統的企圖。它為成為成功的網絡安全威脅狩獵者鋪平了道路,從您的第一次遠征到在複雜的雲原生環境中進行狩獵。

購買印刷版書籍包括免費的PDF、Kindle和ePub格式的電子書,由Manning Publications提供。

關於技術:
毫無疑問,您的安全將受到攻擊。它已經受到攻擊。真正的問題是,當攻擊發生時,您是否能夠識別並從中學習。網絡威脅狩獵假設系統已被入侵,並揭示了逃避檢測工具或被視為不重要而被忽略的跡象。在不斷變化的現代安全環境中,威脅狩獵是一種重要的實踐,以避免自滿並加強對攻擊的防禦。

關於本書:
《網絡威脅狩獵》教您如何識別潛在的安全漏洞。通過探索作者Nadhem AlFardan二十年信息安全領域的真實情境,您將學到如何建立一個實用的狩獵框架,並發現優化和改進遠征的良好實踐。您將學習如何應用機器學習和統計分析等高級技術來幫助發現異常情況。最重要的是,這本實用書籍附帶可下載的數據集和情境模板,讓您可以練習和磨練您的威脅狩獵技巧。

關於讀者:
適合熟悉安全工具和Python的安全、網絡和系統專業人士。

關於作者:
Dr. Nadhem AlFardan是思科公司的首席網絡安全架構師,負責領導安全操作中心實踐。Dr. AlFardan為亞太地區、歐洲、中東和美洲的多個重要組織領導大型安全操作中心項目。他的角色包括幫助客戶建立和增強他們的網絡威脅狩獵實踐。

作者簡介

Dr Nadhem AlFardan is a principal cyber security architect leading the security operation centre practice for Cisco. Dr AlFardan leads large security operations centre programs for major organisations across several APAC, EMEA and the Americas. His role includes helping customers establish and enhance their cyber threat hunting practice.

作者簡介(中文翻譯)

Dr Nadhem AlFardan是思科公司的首席網絡安全架構師,負責領導安全操作中心實踐。Dr AlFardan負責為亞太地區、歐洲中東非洲地區和美洲的重要組織領導大型安全操作中心項目。他的職責包括幫助客戶建立和提升他們的網絡威脅追蹤實踐。