Join Amazon Prime and ship Two-Day for free and Overnight for $3.99. Already a member? Sign in.
OSSEC Host-Based Intrusion Detection Guide and over 300,000 other books are available for Amazon Kindle – Amazon’s new wireless reading device. Learn more

 

or
Sign in to turn on 1-Click ordering.
 
 
More Buying Choices
29 used & new from $45.00

Have one to sell? Sell yours here
 
   
OSSEC Host-Based Intrusion Detection Guide
 
 
Start reading OSSEC Host-Based Intrusion Detection Guide on your Kindle in under a minute.

Don’t have a Kindle? Get yours here.
 
  

OSSEC Host-Based Intrusion Detection Guide (Paperback)

by Andrew Hay (Author), Daniel Cid (Author), Rory Bray (Author)
Key Phrases: web user interface, integrity checking, decoder example, Getting Started, Microsoft Windows, Application Found (more...)
4.6 out of 5 stars See all reviews (5 customer reviews)

List Price: $59.95
Price: $53.95 & this item ships for FREE with Super Saver Shipping. Details
You Save: $6.00 (10%)
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.

Want it delivered Thursday, July 16? Choose One-Day Shipping at checkout. Details
21 new from $46.46 8 used from $45.00
Also Available in: List Price: Our Price: Other Offers:
Kindle Edition (Kindle Book) $47.96

Frequently Bought Together

OSSEC Host-Based Intrusion Detection Guide + Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning + Penetration Tester's Open Source Toolkit, Volume 2
Price For All Three: $124.69

Show availability and shipping details


Customers Who Bought This Item Also Bought

Penetration Tester's Open Source Toolkit, Volume 2

Penetration Tester's Open Source Toolkit, Volume 2

by Chris Hurley
4.5 out of 5 stars (2)  $37.77
Applied Security Visualization

Applied Security Visualization

by Raffael Marty
4.8 out of 5 stars (8)  $40.63
Security Monitoring

Security Monitoring

by Chris Fry
4.8 out of 5 stars (6)  $40.49
Malware Forensics: Investigating and Analyzing Malicious Code

Malware Forensics: Investigating and Analyzing Malicious Code

by Cameron H. Malin
4.9 out of 5 stars (11)  $62.95
Nessus Network Auditing, Second Edition

Nessus Network Auditing, Second Edition

by Russ Rogers
5.0 out of 5 stars (1)  $37.77
Explore similar items

Editorial Reviews

Book Description
OSSEC (Open Source Security) is the most commonly used intrusion detection software used to detect unauthorized activity on a particular computer. This is the only book specifically devoted to this product and it is co-authored by Daniel Cid who is the founder and lead developer of OSSEC.

Product Description
This book is the definitive guide on the OSSEC Host-based Intrusion Detection system and frankly, to really use OSSEC you are going to need a definitive guide. Documentation has been available since the start of the OSSEC project but, due to time constraints, no formal book has been created to outline the various features and functions of the OSSEC product. This has left very important and powerful features of the product undocumented...until now! The book you are holding will show you how to install and configure OSSEC on the operating system of your choice and provide detailed examples to help prevent and mitigate attacks on your systems.
-- Stephen Northcutt
OSSEC determines if a host has been compromised in this manner by taking the equivalent of a picture of the host machine in its original, unaltered state. This ?picture? captures the most relevant information about that machine?s configuration. OSSEC saves this ?picture? and then constantly compares it to the current state of that machine to identify anything that may have changed from the original configuration. Now, many of these changes are necessary, harmless, and authorized, such as a system administrator installing a new software upgrade, patch, or application. But, then there are the not-so-harmless changes, like the installation of a rootkit, trojan horse, or virus. Differentiating between the harmless and the not-so-harmless changes determines whether the system administrator or security professional is managing a secure, efficient network or a compromised network which might be funneling credit card numbers out to phishing gangs or storing massive amounts of pornography creating significant liability for that organization.
Separating the wheat from the chaff is by no means an easy task. Hence the need for this book. The book is co-authored by Daniel Cid, who is the founder and lead developer of the freely available OSSEC host-based IDS. As such, readers can be certain they are reading the most accurate, timely, and insightful information on OSSEC.

* Nominee for Best Book Bejtlich read in 2008!
* http://taosecurity.blogspot.com/2008/12/best-book-bejtlich-read-in-2008.html


. Get Started with OSSEC
Get an overview of the features of OSSEC including commonly used terminology, pre-install preparation, and deployment considerations.
. Follow Steb-by-Step Installation Instructions
Walk through the installation process for the "local", "agent", and "server" install types on some of the most popular operating systems available.
. Master Configuration
Learn the basic configuration options for your install type and learn how to monitor log files, receive remote messages, configure email notification, and configure alert levels.
. Work With Rules
Extract key information from logs using decoders and how you can leverage rules to alert you of strange occurrences on your network.
. Understand System Integrity Check and Rootkit Detection
Monitor binary executable files, system configuration files, and the Microsoft Windows registry.
. Configure Active Response
Configure the active response actions you want and bind the actions to specific rules and sequence of events.
. Use the OSSEC Web User Interface
Install, configure, and use the community-developed, open source web interface available for OSSEC.
. Play in the OSSEC VMware Environment Sandbox
Use the OSSEC HIDS VMware Guest image on the companion DVD to implement what you have learned in a sandbox-style environment.
. Dig Deep into Data Log Mining
Take the "high art" of log analysis to the next level by breaking the dependence on the lists of strings or patterns to look for in the logs.

See all Editorial Reviews

Product Details

  • Paperback: 416 pages
  • Publisher: Syngress (February 18, 2008)
  • Language: English
  • ISBN-10: 159749240X
  • ISBN-13: 978-1597492409
  • Product Dimensions: 9.1 x 7.5 x 0.9 inches
  • Shipping Weight: 1.5 pounds (View shipping rates and policies)
  • Average Customer Review: 4.6 out of 5 stars See all reviews (5 customer reviews)
  • Amazon.com Sales Rank: #31,650 in Books (See Bestsellers in Books)

    Popular in these categories: (What's this?)

    #40 in  Books > Computers & Internet > Business & Culture > Privacy
    #55 in  Books > Computers & Internet > Networking > Network Security

Inside This Book (learn more)


Tags Customers Associate with This Product

 (What's this?)
Click on a tag to find related items, discussions, and people.
Check the boxes next to the tags you consider relevant or enter your own tags in the field below.
(2)

Your tags: Add your first tag
 
Help others find this product — tag it for Amazon search
No one has tagged this product for Amazon search yet. Why not be the first to suggest a search for which it should appear?

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

 

Customer Reviews

5 Reviews
5 star:
 (4)
4 star:    (0)
3 star:
 (1)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
4.6 out of 5 stars (5 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
4 of 4 people found the following review helpful:
5.0 out of 5 stars Excellent book on a very powerful open source tool, October 26, 2008
I'm surprised no one has offered serious commentary on the only book dedicated to OSSEC, an incredible open source host-based intrusion detection system. I first tried OSSEC in early 2007 and wrote in my blog: "OSSEC is really amazing in the sense that you can install it and immediately it starts parsing system logs for interesting activity." Stephen Northcutt of SANS quotes this post in his foreword to the book on p xxv. Once you start using OSSEC, especially with the WebUI, you'll become a log addict. OSSEC HIDS Guide (OHG) is your ticket to taking OSSEC to the next level, even though a basic installation will make you stronger and smarter.

I have to congratulate the author team for OHG. Writing a book for Syngress with many contributors is usually a recipe for disaster. OHG features three lead authors, four contributors, and one foreword author -- and they don't step on each others' toes. Each of the main chapters was coherent and well-written, with solid Frequently Asked Questions sections at the end. The chapters are well-formatted with a mix of tables, figures, clear screen captures, and plenty of configuration examples. The authors even include a DVD with a ready-to-run VMWare image of a Linux system running OSSEC and the WebUI. Please note the .rtf packaged on the DVD mentions visiting a "osui" directory on the Linux Web server in order to view the OSSEC WebUI. The correct URL is "oswui". The Camtasia videos walking viewers through OSSEC installation are a nice touch for the visually-inclined.

I had very few issues with OHG. I think two of the references to "/tmp" on p 203 should really be "tmp/", i.e., references to the tmp/ directory in the WebUI directory. Upgrading OSSEC is trivial (it detects a previous installation and asks the user how to proceed), but I would have liked to see that process mentioned explicitly in the book.

I appreciated the citation for my first book on p 256, but I think the author (hi Anton) missed a crucial point about Network Security Monitoring (NSM): data makes the expert. A ninja with no data isn't very effective. A newbie with data may not be a ninja, but he/she will be more likely to detect and respond to intrusions than the data-less ninja.

This is a simple review to write. If you use OSSEC, you should buy OHG. You'll learn how everything works, how to move beyond the simple (yet still powerful) out-of-the-free-box OSSEC feature set, and find more suspicious and malicious activity in your enterprise. In a future edition I would like to see discussions of integrating OSSEC with other log tools like Splunk.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
3.0 out of 5 stars Good book. No Free download, May 3, 2009
The book reviews listed here are all accurate. I purchased the book to get the Free eBook download. Unfortunately, it doesn't appear to be true anymore. The links to the solution registration do not work, and their customer service is clueless.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
5.0 out of 5 stars Worth the price, excellent book, indepth guide plus more, April 27, 2009
By Goofy Foot "Goofyfoot" (If I told you where I was, would you really visit me? :-() - See all my reviews
I bought this book for 2 reasons. One was as a main reference for a term paper I am writing in the Masters program I am taking at ECU and the other was to learn more about this open source HIDS for my own personal use. The book, I feel, goes into great detail about the software from the download to writing a policy. Most books will not say anything about a policy, they just talk about the software and leave you at that. If you are using, thinking about using or want to learn about HIDS then I suggest buying this book. A big bonus is that Daniel Cid is one of the authors. Most books may only reference the creator of the software, few actually have the creator as an author. Awesome book.
Comment Comment (1) | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews

5.0 out of 5 stars The Guide to Doing More with Less
In these days of tight and/or frozen budgets, utilizing open source applications has become a must for many of us in the security realm. Read more
Published 8 months ago by Kurt R. Hinson

5.0 out of 5 stars Best book about Intrusion Detection!!
It is a great book. It is very important for system, and security administrators who are responsable for protecting assets in their infrastructure.
Published 15 months ago by Mauro Cesar B. Cid

Only search this product's reviews



Customer Discussions

 Beta (What's this?)
New! See all customer communities, and bookmark your communities to keep track of them.
This product's forum (0 discussions)
  Discussion Replies Latest Post
  No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
  [Cancel]


Active discussions in related forums
  Discussion Replies Latest Post
Textbooks for Kindle DX? 40 15 hours ago
Does anyone use Discovering Geometry: An Investigative Approach? 5 19 hours ago
   


Product Information from the Amapedia Community

Beta (What's this?)


So You'd Like to...


Look for Similar Items by Category


Shop Tool Storage in Home Improvement

Shop tool storage in Home Improvement
Check out the huge selection of tool storage and organization products offered by Amazon.com.

See more in the Power & Hand Tools Store

 

Best Books of 2008

Best of 2008
Find our top 100 editors' picks as well as customers' favorites in dozens of categories in our Best Books of 2008 Store.
 

Buy Three Books, Get a Fourth Free

4-for-3 Books
Order any four eligible books under $10 and get the lowest-price book free in our 4-for-3 Books Store. See more details.
 
Shop for Power and Hand Tools
Shop for Power and Hand ToolsFind your favorite brands in the Power & Hand Tools Store.
 

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.


Where's My Stuff?

Shipping & Returns

Need Help?

Your Recent History

  (What's this?)
You have no recently viewed items or searches.

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.

Look to the right column to find helpful suggestions for your shopping session.

Continue shopping: Top Sellers
Paranoia
Paranoia by Joseph Finder
My Soul to Lose
My Soul to Lose by Rachel Vincent
Glenn Beck's Common Sense
Glenn Beck's Common Sense

Conditions of Use | Privacy Notice © 1996-2009, Amazon.com, Inc. or its affiliates