Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Richard Bejtlich

Rating No ratings yet

Network security is not simply about building impenetrable walls—determined attackers will eventually overcome traditional defenses. The most effective computer security strategies integrate network security monitoring (NSM): the collection and analysis of data to help you detect and respond to intrusions. In The Practice of Network Security Monitoring, Mandiant CSO Richard Bejtlich shows you how to use NSM to add a robust layer of protection around your networks—no prior experience required. To help you avoid costly and inflexible solutions, he teaches you how to deploy, build, and run an NSM operation using open source software and vendor-neutral tools. You'll learn how to: • Determine where to deploy NSM platforms, and size them for the monitored networks • Deploy stand-alone or distributed NSM installations • Use command line and graphical packet analysis tools, and NSM consoles • Interpret network evidence from server-side and client-side intrusions • Integrate threat intelligence into NSM software to identify sophisticated adversaries There’s no foolproof way to keep attackers out of your network. But when they get in, you’ll be prepared. The Practice of Network Security Monitoring will show you how to build a security net to detect, contain, and control them. Attacks are inevitable, but losing sensitive data shouldn't be.

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A hands-on guide to building network security monitoring (NSM) with open source, vendor-neutral tools, so you can detect, contain, and respond to intruders who inevitably get past your perimeter. Best for network/security practitioners and incident responders who want practical detection capability rather than another firewall. 【Book Arc】 - **Opening (~0%–10%)**: Frames the core argument—prevention alone fails, so you must collect and analyze network data to detect and respond to intrusions; introduces the NSM mindset and the data types that make it work. - **Early (~10%–30%)**: Makes the case for NSM through a real incident timeline (the South Carolina Department of Revenue breach) and shows how time and visibility matter; walks through packet-level evidence with command-line and graphical tools like Tcpdump and Wireshark. - **Early–Middle (~30%–45%)**: Moves into deployment planning—where to place NSM platforms across internal, DMZ, and wireless segments, how NAT affects visibility, and how to size storage for full content, session, and text data. - **Middle (~45%–60%)**: Covers installation, starting with a stand-alone Security Onion (SO) platform and then scaling to a server-plus-sensors distributed deployment, including server sizing and data placement. - **Late (~60%–85%)**: Surveys the analysis toolset—session data with Argus, graphical packet analysis with Wireshark, Xplico, and NetworkMiner, and NSM consoles such as Sguil for triaging alerts. - **Ending (~85%–100%)**: Extends toward operational practice—interpreting server-side and client-side intrusion evidence and integrating threat intelligence to catch sophisticated adversaries (excerpts do not cover these chapters in detail). 【Key Takeaways】 - **Prevention is not enough; detection and response are the real goal** (Opening): the book's central thesis is that determined attackers will get in, so NSM exists to catch them and limit damage. - **NSM rests on multiple data types** (Early): full content, session, statistical, and alert data each serve different analysis needs, and mature operations collect all of them rather than waiting on IDS alerts alone. - **Time is the enemy in incident response** (Early): the South Carolina case shows weeks elapsing between initial phishing compromise and data theft—visibility shortens that window. - **Placement and sizing are engineering decisions** (Middle): where you tap the network (internal, DMZ, wireless) and how much storage you provision determine what evidence you can actually analyze. - **Deployment scales from stand-alone to distributed** (Middle): a single SO box works for small environments, while server-plus-sensors setups centralize session data and coordinate multiple collection points. - **Tooling spans command line to console** (Late): Tcpdump, Wireshark, Argus, Xplico, NetworkMiner, and Sguil each fit a different stage of collection and analysis. - **Threat intelligence sharpens detection** (Ending): integrating intel into NSM software helps surface sophisticated adversaries that signature-only approaches miss. 【Reading Tips】 - Deep-read the early incident timeline and the NSM rationale chapters—they justify everything that follows and are the most persuasive part of the book. - Treat the deployment and installation chapters as a lab manual: follow along in a test environment, since the book explicitly warns against experimenting on production networks. - Skim tool-by-tool walkthroughs (Wireshark, Xplico, NetworkMiner) if you already know a tool, but note which data type each tool serves. - Pay attention to the storage-sizing formulas and server requirements—these are the details that make or break a real deployment. - Keep the legal disclaimer in mind: monitoring traffic can violate laws if done outside your authority. 【Coverage Limits】 This guide is based on stratified excerpts covering roughly the first half of the book plus the table of contents; the later chapters on consoles, intrusion interpretation, and threat intelligence are only lightly represented, so those sections are summarized at a high level rather than in detail.
Excerpt 1
puter • Integrate threat intelligence into NSM software to security strategies integrate network security monitoring U N D E R S T A N D I N G I N C I D E N...
View in text
Excerpt 2
xecuting malware and becoming compromised in the process . Available evidence indicates that the malware stole the user’s username and password . August 27,...
View in text
Excerpt 3
scalable and cost-effective security measure. NSM drawbacks It would not be fair to discuss all the positives of the NSM experience with- out mentioning a fe...
View in text
Excerpt 4
ging situations require a server-plus-sensors deployment. As explained in Chapter 3, in a server-plus-sensors configuration, one or more sensors collect NSM...
View in text
Excerpt 5
SSEC 443/tcp ALLOW Anywhere Apache 444/tcp ALLOW Anywhere Snorby 7734/tcp ALLOW Anywhere Sguil client to server 7736/tcp ALLOW Anywhere Sguil agents to serve...
View in text
Excerpt 6
6-24: Looping through data with Tshark to find HTTP traffic Tshark display filters also make it easy to search for traffic to or from a range of IP addresses...
View in text
Excerpt 7
d content Information carved from network traffic, such as files or web pages. Session data A high-level summary of network conversations, focusing on who ta...
View in text
Excerpt 8
r the best chance to prevent the adversary from accomplish- ing his mission . The bottom line is that collection requires several components in order to be e...
View in text
Tags
AI categories
CybersecurityDevOps
network security
ISBN: 1593275099
Publisher: No Starch Press
Publish Year: 2013
Language: English
Pages: 376
File Format: PDF
File Size: 17.4 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…