Customer Reviews


15 Reviews
5 star:
 (10)
4 star:
 (2)
3 star:    (0)
2 star:
 (2)
1 star:
 (1)
 
 
 
 
 
Average Customer Review
Share your thoughts with other customers
Create your own review
 
 
Only search this product's reviews

The most helpful favorable review
The most helpful critical review


15 of 15 people found the following review helpful:
5.0 out of 5 stars Amazing book
This is one of those "essential, have to have" books. I just got through all of the examples and finished building out a 3-tiered snort network for the company where I work as a senior security engineer. We previously had some older, expensive, ISS realsecure equipment in place, and I made the case to managment to replace the RealSecure stuff with open-source Snort. It...
Published on August 4, 2003 by Mark Benson

versus
0 of 2 people found the following review helpful:
2.0 out of 5 stars Not for the security professional...
This book is a bit out of date, dealing with issues from Snort 1.8 and RedHat 7.3. I think I glanced at it for about 1 hour total. Just put it on the bookshelf next to the Snort Intrusion Detection 2.0 book which was (if u ask me) a complete reference.
Published on August 24, 2004 by Throck Morton


‹ Previous | 1 2 | Next ›
Most Helpful First | Newest First

15 of 15 people found the following review helpful:
5.0 out of 5 stars Amazing book, August 4, 2003
By 
This review is from: Intrusion Detection with Snort (Paperback)
This is one of those "essential, have to have" books. I just got through all of the examples and finished building out a 3-tiered snort network for the company where I work as a senior security engineer. We previously had some older, expensive, ISS realsecure equipment in place, and I made the case to managment to replace the RealSecure stuff with open-source Snort. It wasn't that hard, the maintence cost for an upgrade was going to be more than my whole entire Snort-based design. My company had good experiences with apache on red hat, so it wasn't a super hard sell. Times are tough, and managment is looking for ways to cut costs.

This book got me there. I was able to get the meaty technical details I needed, and couldn't find answers to online. Im a highly technical person, Im no (dummy) who gets scared of the command line. Id scoured the snort.org website, mailing lists, newsgroups, securityfocus lists, but they lacked in a lot of areas. Especially, the online articles dont talk about using snort in a corporate or enterprise-size setting. I picked up this book and I was able to put in a very highly effective tuned snort install. I also have moved on to advanced topics, like creating my own custom rules that apply only to my company's network. I use these 20 or so rules to catch traffic that is not supposed to be on my network, but might be normal somewhere else, so there is no offical snort.org rule for them.

In short, this is the best book ive read in a few years, at least for a technical book.

Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


13 of 13 people found the following review helpful:
5.0 out of 5 stars Impressive book, June 30, 2003
By 
This review is from: Intrusion Detection with Snort (Paperback)
I've seen a bunch of reviews for this book on security and open source websites on the internet. I usually don't buy paper books, I prefer to read online howtos and go to the library to check something out. I only buy something if I really think ill be able to get practical skills out of it (such as the Perl Cookbook, etc.) After reading the slashdot review on this book, I figured that it was time I learn snort and intrusion detection.

Let me say first, if you are going to actually implement everything in this book, getting through it is going to take some time. This isn't the kind of thing you can learn totally in one night, or even one week. There are just tons of examples and intrusion detection strategies to work through. I like how the author goes through several real-world examples in each chapter, such as teaching you step by step on how to write a snort signature or rule from a raw packet capture. Nowhere on the internet have I seen this, trust me ive looked hard.

Also, the book goes beyond using snort. There are a bunch of tools you need to use with snort in order for it to work well. Snort doesnt have any real time email alerting features, remote signature update tools, or even a GUI interface!! All of these things are seperate, and you can't really use snort in the real world without them. This is why I bought this book instead of the other 2 that are out there.

Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


8 of 8 people found the following review helpful:
5.0 out of 5 stars Broader in scope, not just snort, July 10, 2003
By 
This review is from: Intrusion Detection with Snort (Paperback)
Unlike the "Snort 2.0 Intrusion Detection", this book talks more on intrusion detection. If you are a planner on intrusion detection, this book is a perfect match. If you are the engineer setting up snort, the "Snort 2.0 Intrusion Detection" might be easier to follow.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


6 of 6 people found the following review helpful:
4.0 out of 5 stars Helpful book, Linux-centric, December 28, 2003
By 
Keith Tokash "twigles" (Laguna Niguel, CA United States) - See all my reviews
(REAL NAME)   
Amazon Verified Purchase(What's this?)
This review is from: Intrusion Detection with Snort (Paperback)
This is a very handy book, if only because it presents a lot of Snort documentation in a friendly, easy-to-read format. Is every chapter a joyous literary experience? No. But it beats reading manpages and after a few hours of reading from my monitor my eyes sting.

So the material.... This book introduces Snort, what it is/does, etc, then moves on to how it works. I really enjoyed chapter 3, which looks into all the preprocessors and a brief desciption of Snort's order of operations and modularity.

I would especially recommend chapters 4 and 5 to new Snorters since design issues comprise a huge part of the questions posed to the Snort mailing list, most of which have easy or standard answers. After that, the installation/configuration chapters demonstrate how to get a running setup using RedHat.

I've read a couple complaints in earlier reviews that these instructions don't work and I must say that it is exceedingly difficult to write an installation procedure that incorporates half a dozen different pieces of software, all of which are under seperate development. I actually know about this because I maintain the FreeBSD install guide on the snort site and the instructions that work one week are slightly off the next week. Use the instructions in this book as a guide and you probably won't have much dirty work to figure out on your own.

The rest of the book gets into the nitty-gritty of using Snort and I think it does a pretty good job. This includes tuning signature sets to use less memory/CPU and to generate more reliable alerts. False positives are the bane of the IDS world. If you're new to Snort/IDS then you'll enjoy learning of several great tools like Swatch and Barnyard that this book explores.

Overall I think this book is well worth the 31 clams I coughed up on Amazon.

Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


6 of 6 people found the following review helpful:
5.0 out of 5 stars The Art of Intrusion Detection and Snort, October 9, 2003
By 
This review is from: Intrusion Detection with Snort (Paperback)
I teach networking and security courses at a local unversity, and I have been using this book for a portion of the courseware this semester. A significant portion of the course is hands-on, and this book helps my students understand how intrusion detection is used in the real world.

The chapter on creating rules from packet captures is invaluable --- as is the Snort internals chapter. I understand how Snort works, how to deploy it, and most importantly, the pragmatic side of using Snort in the real world.

This is by far the best of the Snort books out right now, the others are either low on detail or are extremely poorly written. The Snort 2.0 book was disappointing. I was expecting it to be the best book, it stuffed with filler chapters, and overly wordy.

Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


14 of 17 people found the following review helpful:
5.0 out of 5 stars Thorough guide to Snort, May 29, 2003
By 
This review is from: Intrusion Detection with Snort (Paperback)
This is a book every system administrator or network engineer should have. Snort has always been one of those cool open source applications that I've wanted to use, but got frustrated when I couldnt figure out what is going on. Im a pretty busy person, and don't have time to figure out what ever damn preprocessor option does by trial and error. I could get snort up and and running, but never efficiently and it often took lots of work paging through megs of logfiles. In the end, i just plain gave up and went on to learning other security tools.

This book shows me how to organize alerts, where to put my sensors, and how to build snort. It even has some stuff on intrusion prevention, which seems to be the all the buzz in todays security arena.

Now, only if someone would write a good book on tripwire, id be all set!

Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


4 of 4 people found the following review helpful:
5.0 out of 5 stars Comprehensive, October 6, 2003
By 
Jeff Asherton (Kansas City, MO) - See all my reviews
This review is from: Intrusion Detection with Snort (Paperback)
A comprehensive tutorial on Snort, the open source IDS. I especially like the author's casual, informal, tone, it feels like he is talking with you. I really liked the "enterprise" uses of Snort, not just on the home DSL connection.

I noticed some other reviewers had problems installing MySQL. If you type in the commands exactly as they are in the book, you must the verison of MySQL used in the book, 3.23.52. This version is somewhat burried on the website. If you type these exact commands, without making use of any common sense, the latest version of MySQL the source compile will fail. As most open source applications change rapidly, I didnt find this to be a major stumbling block, and got on to the Snort content quickly.

Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


4 of 4 people found the following review helpful:
5.0 out of 5 stars Intermediate and advanced snort, August 15, 2003
By 
This review is from: Intrusion Detection with Snort (Paperback)
Book covers intermediate and advanced Snort usage. Excellent topics, easy to understand.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


3 of 3 people found the following review helpful:
5.0 out of 5 stars A comprehensive and instructive book, February 18, 2004
By 
akempo "akempo" (Lexington, SC United States) - See all my reviews
This review is from: Intrusion Detection with Snort (Paperback)
When I first got this book, I had little idea what Snort did, other than being used for intrusion detection. And while I'm not an expert in Snort now that I've finished it, the book is simply a comprehensive step by step guide to using this useful tool. I am not an expert in computer security by any stretch, but I've read enough computer books to know intelligent, useful information when I read it. Although I do not have a big enough box to run Snort, I feel confident that using the author's instructions as a guideline along with some common sense I could get it up and running, which I will be doing in the near future. I particularly liked the fact that the author discussed other add ons and software that are essential or ease using Snort, but are not part of Snort itself.
The book is laid out in a logical, easy to understand manner, and I will definitely using this as my reference once I get a box I can put it on.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


3 of 3 people found the following review helpful:
5.0 out of 5 stars Worth It, September 10, 2003
By 
This review is from: Intrusion Detection with Snort (Paperback)
Ive worked with Snort now off and on for over a year. I had pieced together and printed out most of the online freebies into a big 3 ring binder. There were still a number of things that I had heard of people doing, but were never able to figure out on my own, such as configuring snort to send alerts over email or writing my own attack signatures. I purchased this book about 6 weeks ago and now have snort doing everything I want it to.

I highly recommend this book, it really bridged the gap.

Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


‹ Previous | 1 2 | Next ›
Most Helpful First | Newest First

This product

Intrusion Detection with Snort
Intrusion Detection with Snort by Jack Koziol (Paperback - May 30, 2003)
$50.00 $33.19
In Stock
Add to cart Add to wishlist