Instant OSSEC Host-based Intrusion Detection System

Brad Lhotsky

  • 出版商: Packt Publishing
  • 出版日期: 2013-07-26
  • 售價: $1,340
  • 貴賓價: 9.5$1,273
  • 語言: 英文
  • 頁數: 62
  • 裝訂: Paperback
  • ISBN: 1782167641
  • ISBN-13: 9781782167648
  • 海外代購書籍(需單獨結帳)

買這商品的人也買了...

相關主題

商品描述

A hands-on guide exploring OSSEC HIDS for operational and security awareness

Overview

  • Learn something new in an Instant! A short, fast, focused guide delivering immediate results
  • Install, configure, and customize an OSSEC-HIDS for your environment
  • Manage your OSSEC-HIDS robust and comprehensive security checks
  • Write your own rules and decoders to enhance alert accuracy and expand operational and security intelligence

In Detail

Security software is often expensive, restricting, burdensome, and noisy. OSSEC-HIDS was designed to avoid getting in your way and to allow you to take control of and extract real value from industry security requirements. OSSEC-HIDS is a comprehensive, robust solution to many common security problems faced in organizations of all sizes.

"Instant OSSEC-HIDS" is a practical guide to take you from beginner to power user through recipes designed based on real- world experiences. Recipes are designed to provide instant impact while containing enough detail to allow the reader to further explore the possibilities. Using real world examples, this book will take you from installing a simple, local OSSEC-HIDS service to commanding a network of servers running OSSEC-HIDS with customized checks, alerts, and automatic responses.

You will learn how to maximise the accuracy, effectiveness, and performance of OSSEC-HIDS’ analyser, file integrity monitor, and malware detection module. You will flip the table on security software and put OSSEC-HIDS to work validating its own alerts before escalating them. You will also learn how to write your own rules, decoders, and active responses. You will rest easy knowing your servers can protect themselves from most attacks while being intelligent enough to notify you when they need help!

You will learn how to use OSSEC-HIDS to save time, meet security requirements, provide insight into your network, and protect your assets.

What you will learn from this book

  • Installing OSSEC-HIDS in local, server, and agent mode
  • Customizing alerting to increase the signal to noise ratio
  • Writing your own rules to extend, enhance, and tailor alerts to your environment
  • Writing your own decoders to add context to alerts and active responses
  • Learning tips for managing large OSSEC-HIDS installs
  • Monitoring command output for security and operational awareness
  • Auditing systems for compromise with a sensitivity to performance of those systems
  • Configuring Active Response to protect servers from SSH brute force attacks

Approach

Filled with practical, step-by-step instructions and clear explanations for the most important and useful tasks. A fast-paced, practical guide to OSSEC-HIDS that will help you solve host-based security problems.

Who this book is written for

This book is great for anyone concerned about the security of their servers-whether you are a system administrator, programmer, or security analyst, this book will provide you with tips to better utilize OSSEC-HIDS. Whether you’re new to OSSEC-HIDS or a seasoned veteran, you’ll find something in this book you can apply today!

This book assumes some knowledge of basic security concepts and rudimentary scripting experience.

商品描述(中文翻譯)

一個實用指南,探索 OSSEC HIDS 以增強操作和安全意識

概述
- 立即學習新知!一本短小、快速、專注的指南,提供即時成果
- 安裝、配置並自訂適合您環境的 OSSEC-HIDS
- 管理您的 OSSEC-HIDS,進行強大且全面的安全檢查
- 編寫自己的規則和解碼器,以提高警報準確性並擴展操作和安全情報

詳細內容
安全軟體通常價格昂貴、限制多、負擔重且噪音大。OSSEC-HIDS 的設計旨在不妨礙您的工作,並讓您能夠掌控並從行業安全要求中提取真正的價值。OSSEC-HIDS 是一個全面且強大的解決方案,能解決各種規模組織面臨的常見安全問題。

《即時 OSSEC-HIDS》是一本實用指南,將帶您從初學者提升至高級用戶,透過基於真實世界經驗設計的食譜。這些食譜旨在提供即時影響,同時包含足夠的細節,讓讀者能進一步探索可能性。透過真實案例,本書將引導您從安裝簡單的本地 OSSEC-HIDS 服務,到指揮運行 OSSEC-HIDS 的伺服器網絡,並進行自訂檢查、警報和自動回應。

您將學會如何最大化 OSSEC-HIDS 的分析器、檔案完整性監控和惡意軟體檢測模組的準確性、有效性和性能。您將顛覆安全軟體的傳統做法,讓 OSSEC-HIDS 在升級警報之前先驗證其自身的警報。您還將學會如何編寫自己的規則、解碼器和主動回應。您可以放心,您的伺服器能夠保護自己免受大多數攻擊,並在需要幫助時智能地通知您!

您將學會如何使用 OSSEC-HIDS 來節省時間、滿足安全要求、提供網絡洞察並保護您的資產。

您將從本書中學到的內容
- 在本地、伺服器和代理模式下安裝 OSSEC-HIDS
- 自訂警報以提高信號與噪音比
- 編寫自己的規則以擴展、增強和調整警報以符合您的環境
- 編寫自己的解碼器,以為警報和主動回應添加上下文
- 學習管理大型 OSSEC-HIDS 安裝的技巧
- 監控命令輸出以提高安全性和操作意識
- 針對系統的妥協進行審計,同時考慮這些系統的性能
- 配置主動回應以保護伺服器免受 SSH 暴力破解攻擊

方法
本書充滿實用的逐步指導和清晰的解釋,涵蓋最重要和有用的任務。這是一本快速且實用的 OSSEC-HIDS 指南,將幫助您解決基於主機的安全問題。

本書的讀者對象
本書非常適合任何關心伺服器安全的人士—無論您是系統管理員、程式設計師或安全分析師,本書將提供您更好利用 OSSEC-HIDS 的技巧。無論您是 OSSEC-HIDS 的新手還是資深用戶,您都能在本書中找到可以立即應用的內容!

本書假設讀者具備基本的安全概念知識和初步的腳本編寫經驗。