Showing posts with label infosec. Show all posts
Showing posts with label infosec. Show all posts

5/01/2012

Computer Security: Art and Science Review

Computer Security: Art and Science
Average Reviews:

(More customer reviews)
Please understand that the Amazon star system, while very powerful has limits, I feel this book is 5 stars as a textbook for an undergrad computer security course, 4 stars for a graduate student and 3 stars for a book on the average information security worker's shelf.
Computer Security Art and Science has been years in the making and for good reason; it is over a thousand pages. The book seems best suited for four groups of readers. The first group is college students; this will probably be a popular choice as a textbook for undergraduate level students and with additional materials, graduate level students. It is a complete guide to computer security terminology and theory. Other groups of readers that would benefit from this book include security knowledgeable managers seeking to assess the knowledge of potential employees especially in policy and architecture positions. A third group includes anyone preparing for information security certifications. If you are wish to certify you will benefit from a close reading of this text before attempting your examination. Finally, anyone seeking to understand the big picture of information security would benefit from Computer Security Art and Science. However the book's value is primarily as a textbook!
Like most authors writing a security book, Matt has chosen to start at a basic level beginning with a discussion of confidentiality, integrity and availability. As a reviewer I was quietly wondering how long he would stay there. The answer proved to be one chapter only and at the back of the chapter one the author has included insightful, thought provoking study questions. If I were considering hiring someone who claimed to have experience in information security that could not answer these questions, I would show them the door.
Now to consider the rest of the book! On the first page of chapter two we are introduced to logical equations. This is where the casual reader is likely to get off the bus while the diligent student with a qualified instructor gets on. As soon as I saw the equations with no explanation of how to read them, I could see someone browsing in a bookstore shut the cover and move on. Be brave and press on is my advice; the book is well worth it even if some of the illustrations are beyond comprehension without a teacher's guide. It says in the preface this book was designed to be a college level textbook. They have to put a few inscrutable pages in the book so the professors can appear to be smarter than the students.
The cryptography section, chapters 9 - 11 are very approachable and while not as in depth as some other sections, they would help anyone preparing for the various industry security certifications including CompTIA's Security +, ISC2's CISSP and SANS' GSEC. In fact the entire book would be beneficial for any of these.
The table of contents says that part 6 of the book, assurance, chapters 18 - 21, were contributed by a different author, Elisabeth Sullivan. I read those chapters closely and could not detect a different tone or level of quality; the authors are to be congratulated for that. Nice use of humor on the heading title for 18.1.1, "The Need for Assurance" and where else can you read about "Extreme Programming".
No book is perfect, the intrusion detection and penetration testing discussions need to be beefed up, but chapter 29, Program Security more than makes up for them. That chapter should be required reading before anyone is allowed to touch a compiler.
I donate most of the books people send me to review to my local library, but this one stays on the shelf and I am setting an iCal reminder to re-read the policy and audit sections a couple months from now.

Click Here to see more reviews about: Computer Security: Art and Science



Buy NowGet 28% OFF

Click here for more information about Computer Security: Art and Science

Read More...

1/22/2012

Snort IDS and IPS Toolkit (Jay Beale's Open Source Security) Review

Snort IDS and IPS Toolkit (Jay Beale's Open Source Security)
Average Reviews:

(More customer reviews)
Syngress published "Snort 2.0" in Mar 03, and I gave it a four star review in Jul 03. Syngress followed with "Snort 2.1" in May 04, and I gave it a four star review in Jul 04. I recommend reading those reviews, since the latest edition -- "Snort IDS and IPS Toolkit" (SIAIT) -- makes many of the same mistakes as its predecessors. Worse, it includes material that was already outdated in BOTH previous editions. If you absolutely must buy a book on Snort, this edition is your only real choice. Otherwise, I would stick with the manual and online articles.
SIAIT looks impressive page-wise, but it suffers from the multiple-author, no-editing, rush-to-production problems unfortunately inherent in many Syngress titles. One would think that including many contributing authors (11, apparently) would make for a strong book. In reality, the book contributes very little beyond what appears in "Snort 2.1," despite the fact that "only" chapters 8, 10, 11, and 13 appear to be repeats or largely rehashes of older material. Comparing to "Snort 2.1," these compare to old chapters 7, 10, 12, and 11, respectively.
The absolute worst part of this book is the re-introduction of all the outdated information in chapters 8 and 10. It is 2007 and we are STILL reading on p 353 that XML output is "our favorite and relatively new logging format" and on p 367 that "Unified logs are the future of Snort reporting." (I cited both of these as being old news in Jul 04!) I should note that these chapters are not entirely duplicates; if you compare output such as that on page 335 of "Snort 2.1" with page 365 in SIAIT you'll see the author replaced the original 2003 timestamps with 2006! This is the height of lazy publishing. Chapter 10 features similar tricks, where traffic is the same except for global replacements of IP addresses and timestamps; notice the ACK numbers are still the same and the test uses Snort 1.8.
There's plenty more in this book to make you cringe. Mentions of Netbus, SubSeven, BO2k, ExploreZip, QAZ, and the like in ch 1 will make you think it's 1999 all over again. In ch 2 you can be mislead into thinking that "there will be rule upgrades released with each major version of Snort for those who do not care to register." In reality the last rule set for unregistered users arrived with Snort 2.4 in Jul 05. Ch 3 wastes time rambling about SMP, threads, operating systems, and other topics I can better learn in a non-Snort book. I also liked reading how to install Snort 2.4.3 on OpenBSD in a book about Snort 2.6.x. Ch 3 also featured such pearls of wisdom as recommendations to not run Metasploit but instead use worthless stateless tools like Snot and Sneeze (p 123).
A few more choice words could be said about these disasters. Check out the "three way handshake" diagram on p 238 that shows FIN ACK / FIN ACK / FIN, and the "graceful close" diagram on p 239 that shows FIN / FIN ACK / ACK / ACK. These sorts of train wrecks are evidence that someone is asleep at the publishing house. Returning to the old material theme for ch 9, be prepared for screenshots or output from BASE 1.0.2 from Jul 04, Sguil 0.3.1 from Apr 04, and SnortSnarf from Jan 03. Finally, ch 12: why bother?
I have a few positive comments. The best chapter in SIAIT is ch 5 (Inner Workings). I liked seeing Afterglow, Tenshi, and SEC in ch 9. I enjoyed hearing something about performance profiling in ch 6. I thought the rules chapter was ok, but (to repeat a plea from my earlier reviews) would someone please consider writing a real rule writing reference that exceeds the introductory material found in this book and elsewhere? We also need coverage of shared object rules and other advanced Snort features.
It should be clear by now that the Syngress Snort book procession needs to end. Another publisher should consider writing a real Snort book for version 3.0 once it is available.

Click Here to see more reviews about: Snort IDS and IPS Toolkit (Jay Beale's Open Source Security)

This all new book covering the brand new Snort version 2.6 from members of the Snort developers team.This fully integrated book, CD, and Web toolkit covers everything from packet inspection to optimizing Snort for speed to using the most advanced features of Snort to defend even the largest and most congested enterprise networks. Leading Snort experts Brian Caswell, Andrew Baker, and Jay Beale analyze traffic from real attacks to demonstrate the best practices for implementing the most powerful Snort features. The accompanying CD contains examples from real attacks allowing readers test their new skills. The book will begin with a discussion of packet inspection and the progression from intrusion detection to intrusion prevention. The authors provide examples of packet inspection methods including: protocol standards compliance, protocol anomaly detection, application control, and signature matching. In addition, application-level vulnerabilities including Binary Code in HTTP headers, HTTP/HTTPS Tunneling, URL Directory Traversal, Cross-Site Scripting, and SQL Injection will also be analyzed. Next, a brief chapter on installing and configuring Snort will highlight various methods for fine tuning your installation to optimize Snort performance including hardware/OS selection, finding and eliminating bottlenecks, and benchmarking and testing your deployment. A special chapter also details how to use Barnyard to improve the overall performance of Snort. Next, best practices will be presented allowing readers to enhance the performance of Snort for even the largest and most complex networks. The next chapter reveals the inner workings of Snort by analyzing the source code. The next several chapters will detail how to write, modify, and fine-tune basic to advanced rules and pre-processors. Detailed analysis of real packet captures will be provided both in the book and the accompanying CD. Several examples for optimizing output plugins will then be discussed including a comparison of MySQL and PostrgreSQL. Best practices for monitoring Snort sensors and analyzing intrusion data follow with examples of real world attacks using: ACID, BASE, SGUIL, SnortSnarf, Snort_stat.pl, Swatch, and more.The last part of the book contains several chapters on active response, intrusion prevention, and using Snort's most advanced capabilities for everything from forensics and incident handling to building and analyzing honey pots. Data from real world attacks will be presented throughout this part as well as on the accompanying CD. * This fully integrated book, CD, and Web toolkit covers everything all in one convenient package * It is authored by members of the Snort team and it is packed full of their experience and expertise* Includes full coverage of the brand new Snort version 2.6, packed full of all the latest information

Buy NowGet 34% OFF

Click here for more information about Snort IDS and IPS Toolkit (Jay Beale's Open Source Security)

Read More...

9/14/2011

FISMA Principles and Best Practices: Beyond Compliance Review

FISMA Principles and Best Practices: Beyond Compliance
Average Reviews:

(More customer reviews)
this is one of the better titles on FISMA.
If you work in the govt. arena and have to deal with FISMA, check this book out.
Written by an insider who knows his stuff.

Click Here to see more reviews about: FISMA Principles and Best Practices: Beyond Compliance

While many agenciesstruggle to comply with Federal Information Security Management Act (FISMA) regulations, those that have embraced its requirements have found that their comprehensive and flexible nature provides a sound security risk management framework for the implementation of essential system security controls. Detailing a proven approach for establishing and implementing a comprehensive information security program, FISMA Principles and Best Practices: Beyond Compliance integrates compliance review, technical monitoring, and remediation efforts to explain how to achieve and maintain compliance with FISMA requirements.Based on the author's experience developing, implementing, and maintaining enterprise FISMA-based information technology security programs at three major federal agencies, including the U.S. Department of Housing and Urban Development, the book gives you workable solutions for establishing and operating an effective security compliance program. It delineates the processes, practices, and principles involved in managing the complexities of FISMA compliance. Describing how FISMA can be used to form the basis for an enterprise security risk management program, the book:Provides a comprehensive analysis of FISMA requirementsHighlights the primary considerations forestablishing an effective security compliance programIllustrates successful implementation of FISMA requirements with numerous case studiesClarifying exactly what it takes to gain and maintain FISMA compliance, Pat Howard, CISO of the Nuclear Regulatory Commission, provides detailed guidelines so you can design and staff a compliance capability, build organizational relationships, gain management support, and integrate compliance into the system development life cycle. While there is no such thing as absolute protection, this up-to-date resource reflects the important security concepts and ideas for addressing information security requirements mandated for government agencies and companies subject to these standards.

Buy NowGet 17% OFF

Click here for more information about FISMA Principles and Best Practices: Beyond Compliance

Read More...

8/28/2011

Computer Security: Principles and Practice Review

Computer Security: Principles and Practice
Average Reviews:

(More customer reviews)
Stallings and Brown directs the book at a computer professional, who might be a programmer or system administrator. The book deliberately minimises the mathematical aspects. Much of the topic consists of layers above sophisticated encryption algorithms. Alas, a detailed treatment of the latter often requires heavy math background. If you do desire such a treatment, I recommend Matt Bishop's Introduction to Computer Security. That book was deprecated by some reviewers, who found it too mathematical.
Anyway, back to Stallings and Brown. It does proffer good technical explanations of various malware. Like worms and viruses. And attack modes like Denial of Service, and Distributed Denial of Service. Important variants are also covered - reflector and amplifier attacks.
Countermeasures to malware then naturally enter the narrative. So you learn how a firewall functions. Plus how to set up a honeypot to attract spam, phishing and malware.
So far, the above might be regarded as external attacks on your system. Sometimes, worms or viruses might try to take advantage of weaknesses in installed programs. Hence, another section of the book is for those of you who write such programs. Explaining how to guard against buffer and stack overflows, for example. These 2 are perhaps the most common entry points for malware.

Click Here to see more reviews about: Computer Security: Principles and Practice



Buy NowGet 31% OFF

Click here for more information about Computer Security: Principles and Practice

Read More...