Enter your mobile number or email address below and we'll send you a link to download the free Kindle App. Then you can start reading Kindle books on your smartphone, tablet, or computer - no Kindle device required.

  • Apple
  • Android
  • Windows Phone
  • Android

To get the free app, enter your email address or mobile phone number.

OSSEC Host-Based Intrusion Detection Guide 1st Edition

4.1 out of 5 stars 11 customer reviews
ISBN-13: 978-1597492409
ISBN-10: 159749240X
Why is ISBN important?
ISBN
This bar-code number lets you verify that you're getting exactly the right version or edition of a book. The 13-digit and 10-digit formats both work.
Scan an ISBN with your phone
Use the Amazon App to scan ISBNs and compare prices.
Sell yours for a Gift Card
We'll buy it for $2.00
Learn More
Trade in now
Have one to sell? Sell on Amazon

Sorry, there was a problem.

There was an error retrieving your Wish Lists. Please try again.

Sorry, there was a problem.

List unavailable.
Buy used On clicking this link, a new layer will be open
$12.94 On clicking this link, a new layer will be open
Buy new On clicking this link, a new layer will be open
$45.54 On clicking this link, a new layer will be open
More Buying Choices
24 New from $29.40 27 Used from $8.93
Free Two-Day Shipping for College Students with Amazon Student Free%20Two-Day%20Shipping%20for%20College%20Students%20with%20Amazon%20Student

$45.54 FREE Shipping. Only 3 left in stock (more on the way). Ships from and sold by Amazon.com. Gift-wrap available.

Frequently Bought Together

  • OSSEC Host-Based Intrusion Detection Guide
  • +
  • Instant OSSEC Host-based Intrusion Detection System
  • +
  • Blue Team Handbook: Incident Response Edition: A condensed field guide for the Cyber Security Incident Responder.
Total price: $87.02
Buy the selected items together

NO_CONTENT_IN_FEATURE


Product Details

  • Paperback: 416 pages
  • Publisher: Syngress; 1 edition (March 17, 2008)
  • Language: English
  • ISBN-10: 159749240X
  • ISBN-13: 978-1597492409
  • Product Dimensions: 7.5 x 0.8 x 9.1 inches
  • Shipping Weight: 1.5 pounds (View shipping rates and policies)
  • Average Customer Review: 4.1 out of 5 stars  See all reviews (11 customer reviews)
  • Amazon Best Sellers Rank: #272,514 in Books (See Top 100 in Books)

Customers Viewing This Page May Be Interested In These Sponsored Links

  (What's this?)

Customer Reviews

Top Customer Reviews

Format: Paperback
I'm surprised no one has offered serious commentary on the only book dedicated to OSSEC, an incredible open source host-based intrusion detection system. I first tried OSSEC in early 2007 and wrote in my blog: "OSSEC is really amazing in the sense that you can install it and immediately it starts parsing system logs for interesting activity." Stephen Northcutt of SANS quotes this post in his foreword to the book on p xxv. Once you start using OSSEC, especially with the WebUI, you'll become a log addict. OSSEC HIDS Guide (OHG) is your ticket to taking OSSEC to the next level, even though a basic installation will make you stronger and smarter.

I have to congratulate the author team for OHG. Writing a book for Syngress with many contributors is usually a recipe for disaster. OHG features three lead authors, four contributors, and one foreword author -- and they don't step on each others' toes. Each of the main chapters was coherent and well-written, with solid Frequently Asked Questions sections at the end. The chapters are well-formatted with a mix of tables, figures, clear screen captures, and plenty of configuration examples. The authors even include a DVD with a ready-to-run VMWare image of a Linux system running OSSEC and the WebUI. Please note the .rtf packaged on the DVD mentions visiting a "osui" directory on the Linux Web server in order to view the OSSEC WebUI. The correct URL is "oswui". The Camtasia videos walking viewers through OSSEC installation are a nice touch for the visually-inclined.

I had very few issues with OHG. I think two of the references to "/tmp" on p 203 should really be "tmp/", i.e., references to the tmp/ directory in the WebUI directory.
Read more ›
Comment 9 people found this helpful. Was this review helpful to you? Yes No Sending feedback...
Thank you for your feedback.
Sorry, we failed to record your vote. Please try again
Report abuse
By Tracy R. Reed on September 1, 2012
Format: Paperback Verified Purchase
The book explains how to use OSSEC reasonably well. It's got the facts you need. I did find the occasional typo in the prose but none in the config examples. A few things that annoyed me:

1. They almost seem to be going for page count. Plenty of redundancy. I know some people like the introduce, tell, revisit, style of learning. I prefer something more succinct. They start each chapter with a fictional story, they cover the nitty-gritty (most useful part), then they summarize, then they have a "Solutions Fast Track" which is checklist style summary of the main points, then they have a Frequently Asked Questions section which covers a lot of what came before. They do this pattern for each chapter

2. The little story at the beg involving the odd made-up names seemed unnecessary and contrived.

3. The chapter on Data Mining was surprisingly light. No code, no useful examples, just a general discussion of what it is and what it is good for. Barely anything on using OSSEC to facilitate it.

I was a bit disappointed that OSSEC didn't contain any fancy heuristics for rootkit detection. It's just checking for signatures like the existence of certain files etc. This seems pointless as there are no signature updates available as far as I know and I'm relatively unlikely to be hit by an old rootkit.

The file integrity monitoring I've decided to do with AIDE which is bundled with CentOS. There's nothing special about OSSEC's.

The log monitoring/parsing/analysis I've decided to do with Splunk in one installation (the client has tons of money) and logstash in another (the client is a small business and very frugal).

Overall I guess I'm glad I read this book because now I have a more complete appreciation for what OSSEC can do and can be reasonably happy that I'm not really missing anything in not using OSSEC.
1 Comment 3 people found this helpful. Was this review helpful to you? Yes No Sending feedback...
Thank you for your feedback.
Sorry, we failed to record your vote. Please try again
Report abuse
Format: Paperback Verified Purchase
I should have read the other reviews before purchasing - there is no free ebook download as expected. I had to find out the hard way by emailing Syngress, who was extremely unwilling to do anything about this. What a disappointment.

Otherwise, the book itself is a handy reference to have. But, you probably could get more takeaways from just learning OSSEC on your own and using the OSSEC users list as a point of reference.

Good book but it needs to be updated (especially the cover!). I expected more of this - like the granular details within each topic (active response, rules, decoders, etc). This is a very good book to get a quick overview and understanding, but for those who are well-experienced or familiar with OSSEC, it's not much of a huge help.

*EDIT/UPDATE*
Oddly enough, I received a follow-up email from Syngress not long after posting this review. Seems they read up on things ;) Anyway, they sent me a temporary link to download the PDF so I was pretty satisfied. But that doesn't excuse the fact that they need to update the product information in terms of indicating that there is no ebook. Either way, thank you Syngress. Updating my review to 4-stars rather than 3.
Comment One person found this helpful. Was this review helpful to you? Yes No Sending feedback...
Thank you for your feedback.
Sorry, we failed to record your vote. Please try again
Report abuse
Format: Paperback Verified Purchase
This is exactly what it says it is. A guide to how to use OSSEC. (more or less). It's written as a story which is sort of strange but pretty much everything you need to get off the ground is in the book.
Comment Was this review helpful to you? Yes No Sending feedback...
Thank you for your feedback.
Sorry, we failed to record your vote. Please try again
Report abuse
Format: Paperback
In these days of tight and/or frozen budgets, utilizing open source applications has become a must for many of us in the security realm. OSSEC is one such "must have" application that will give you visibility and insight into Windows, Mac and Linux machines on your network through the use of this Host Intrusion Detection application. There are many options, architectures and configuration variables and this book is an excellent resource that will guide you whether you are a seasoned professional or just starting to think about deploying host based intrusion detection in your environment. This book is a must have for any security engineer's bookshelf and a quick way to get you on the road to compliance using powerful and FREE software.
Comment Was this review helpful to you? Yes No Sending feedback...
Thank you for your feedback.
Sorry, we failed to record your vote. Please try again
Report abuse

Set up an Amazon Giveaway

OSSEC Host-Based Intrusion Detection Guide
Amazon Giveaway allows you to run promotional giveaways in order to create buzz, reward your audience, and attract new followers and customers. Learn more
This item: OSSEC Host-Based Intrusion Detection Guide