Practical Intrusion Analysis: Prevention and Detection for the Twenty-First Century (Paperback)
暫譯: 實用入侵分析:二十一世紀的預防與檢測

Ryan Trost

  • 出版商: Addison Wesley
  • 出版日期: 2009-06-01
  • 售價: $2,000
  • 貴賓價: 9.5$1,900
  • 語言: 英文
  • 頁數: 480
  • 裝訂: Paperback
  • ISBN: 0321591801
  • ISBN-13: 9780321591807
  • 相關分類: 資訊安全
  • 立即出貨 (庫存 < 3)

買這商品的人也買了...

相關主題

商品描述

Practical Intrusion Analysis provides a solid fundamental overview of the art and science of intrusion analysis.”

   –Nate Miller, Cofounder, Stratum Security

 

The Only Definitive Guide to New State-of-the-Art Techniques in Intrusion Detection and Prevention

 

Recently, powerful innovations in intrusion detection and prevention have evolved in response to emerging threats and changing business environments. However, security practitioners have found little reliable, usable information about these new IDS/IPS technologies. In Practical Intrusion Analysis, one of the field’s leading experts brings together these innovations for the first time and demonstrates how they can be used to analyze attacks, mitigate damage, and track attackers.

 

Ryan Trost reviews the fundamental techniques and business drivers of intrusion detection and prevention by analyzing today’s new vulnerabilities and attack vectors. Next, he presents complete explanations of powerful new IDS/IPS methodologies based on Network Behavioral Analysis (NBA), data visualization, geospatial analysis, and more.

 

Writing for security practitioners and managers at all experience levels, Trost introduces new solutions for virtually every environment. Coverage includes

 

  • Assessing the strengths and limitations of mainstream monitoring tools and IDS technologies
  • Using Attack Graphs to map paths of network vulnerability and becoming more proactive about preventing intrusions
  • Analyzing network behavior to immediately detect polymorphic worms, zero-day exploits, and botnet DoS attacks
  • Understanding the theory, advantages, and disadvantages of the latest Web Application Firewalls
  • Implementing IDS/IPS systems that protect wireless data traffic
  • Enhancing your intrusion detection efforts by converging with physical security defenses
  • Identifying attackers’ “geographical fingerprints” and using that information to respond more effectively
  • Visualizing data traffic to identify suspicious patterns more quickly
  • Revisiting intrusion detection ROI in light of new threats, compliance risks, and technical alternatives

 

Includes contributions from these leading network security experts:

 

Jeff Forristal, a.k.a. Rain Forest Puppy, senior security professional and creator of libwhisker


Seth Fogie, CEO, Airscanner USA; leading-edge mobile security researcher; coauthor of Security Warrior

 

Dr. Sushil Jajodia, Director, Center for Secure Information Systems; founding Editor-in-Chief, Journal of Computer Security

 

Dr. Steven Noel, Associate Director and Senior Research Scientist, Center for Secure Information Systems, George Mason University

 

Alex Kirk, Member, Sourcefire Vulnerability Research Team

 

商品描述(中文翻譯)

實用入侵分析提供了入侵分析藝術與科學的堅實基礎概述。”
–Nate Miller, Stratum Security 共同創辦人

唯一的權威指南,介紹入侵檢測與防護的新技術

最近,針對新興威脅和變化的商業環境,入侵檢測與防護技術出現了強大的創新。然而,安全從業人員發現有關這些新 IDS/IPS 技術的可靠且可用的信息寥寥無幾。在實用入侵分析中,該領域的領先專家首次將這些創新整合在一起,並展示如何利用它們來分析攻擊、減輕損害和追蹤攻擊者。

Ryan Trost 通過分析當今的新漏洞和攻擊向量,回顧了入侵檢測與防護的基本技術和商業驅動因素。接著,他詳細解釋了基於網路行為分析(Network Behavioral Analysis, NBA)、數據可視化、地理空間分析等的強大新 IDS/IPS 方法論。

Trost 為各種經驗水平的安全從業人員和管理者撰寫,介紹了幾乎適用於每個環境的新解決方案。內容包括:

- 評估主流監控工具和 IDS 技術的優勢與限制
- 使用攻擊圖(Attack Graphs)來映射網路漏洞的路徑,並更主動地防止入侵
- 分析網路行為以立即檢測多形蟲、零日漏洞和僵屍網路的 DoS 攻擊
- 理解最新網路應用防火牆的理論、優勢和劣勢
- 實施保護無線數據流量的 IDS/IPS 系統
- 通過與物理安全防禦的融合來增強入侵檢測工作
- 識別攻擊者的“地理指紋”,並利用該信息更有效地回應
- 可視化數據流量以更快識別可疑模式
- 重新評估入侵檢測的投資回報率,考慮新威脅、合規風險和技術替代方案

包括以下網路安全專家的貢獻:

Jeff Forristal,別名 Rain Forest Puppy,高級安全專業人員及 libwhisker 的創建者

Seth Fogie,Airscanner USA 首席執行官;前沿移動安全研究員;Security Warrior 的合著者

Dr. Sushil Jajodia,安全信息系統中心主任;Journal of Computer Security 創始主編

Dr. Steven Noel,喬治梅森大學安全信息系統中心副主任及高級研究科學家

Alex Kirk,Sourcefire 漏洞研究團隊成員