31 used & new from $1.33

Have one to sell? Sell yours here
 
 
Network Intrusion Detection: An Analyst's Handbook (2nd Edition)
 
 

Network Intrusion Detection: An Analyst's Handbook (2nd Edition) (Paperback)

~ (Author), Judy Novak (Author)
4.5 out of 5 stars  See all reviews (49 customer reviews)


Available from these sellers.


5 new from $39.10 26 used from $1.33

Formats

Amazon Price New from Used from
  Paperback, September 5, 2002 $31.50 $27.12 $18.71
  Paperback, September 22, 2000 -- $39.10 $1.33
There is a newer edition of this item:
Network Intrusion Detection (3rd Edition) Network Intrusion Detection (3rd Edition) 4.5 out of 5 stars (49)
$31.50
In Stock.
What Do Customers Ultimately Buy After Viewing This Item?

Customers Who Bought This Item Also Bought

Intrusion Signatures and Analysis

Intrusion Signatures and Analysis

by Matt Fearnow
4.2 out of 5 stars (8)  $29.19
The Tao of Network Security Monitoring: Beyond Intrusion Detection

The Tao of Network Security Monitoring: Beyond Intrusion Detection

by Richard Bejtlich
4.9 out of 5 stars (21)  $44.09
Inside Network Perimeter Security (2nd Edition)

Inside Network Perimeter Security (2nd Edition)

by Stephen Northcutt
4.4 out of 5 stars (7)  $31.49
Snort IDS and IPS Toolkit (Jay Beale's Open Source Security)

Snort IDS and IPS Toolkit (Jay Beale's Open Source Security)

by Jay Beale
4.5 out of 5 stars (4)  $32.97
Counter Hack Reloaded: A Step-by-Step Guide to Computer Attacks and Effective Defenses (2nd Edition)

Counter Hack Reloaded: A Step-by-Step Guide to Computer Attacks and Effective Defenses (2nd Edition)

by Tom Liston
4.8 out of 5 stars (45)  $40.94
Explore similar items

Editorial Reviews

Amazon.com Review

A collection of after-action reports on a variety of network attacks, Network Intrusion Detection enables you to learn from others' mistakes as you endeavor to protect your networks from intrusion. Authors Stephen Northcutt and Judy Novak document real attacks on systems, and highlight characteristics that you--you being a network communications analyst or security specialist--can look for on your own machines. The authors mince no words, and advise you on the detection tools to use (they like and use Snort, as well as Shadow, Tripwire, TCP Wrappers, and others) and how to use them. This second edition of the book includes less about year-2000 preparation and more about the latest in attacks, countermeasures, and the growing community of white-hat hackers who share information to keep systems safe.

In teaching their readers about the attacks that exploit a particular protocol or service, the authors typically present a TCPdump listing that shows an attack, and then comment upon it. They tell you what the attackers did, how successful they were, and how the attack might have been detected and shut down. To cite one example, there's a very detailed analysis of Kevin Mitnick's famous attack (a SYN flood, combined with TCP hijacking) on one of Tsutomu Shimomura's machines. By following the advice in this book, you'll likely do well in protecting your machines against people whom the authors call "script kiddies" --small-time hackers who follow published recipes (or run prewritten routines). Also, you'll be about as prepared as you can be against more skilled attackers who make up their attacks on their own. This is great reading for anyone who's involved in developing filters to ward off attacks or monitoring network communications for suspicious activity. It's also a valuable resource for someone who's evaluating network countermeasures in preparation for deployment. --David Wall

Topics covered: Analysis of TCP/IP traffic, with an eye toward detecting and halting malicious activity, both manually and automatically. Subjects include tools for finding weaknesses and initiating attacks, and the signatures that identify these tools. There's discussion of the vulnerabilities that exist in services, such as IMAP and Domain Name System (DNS).



Product Description

Intrusion detection is one of the hottest growing areas of network security. As the number of corporate, government, and educational networks grow and as they become more and more interconnected through the Internet, there is a correlating increase in the types and numbers of attacks to penetrate those networks. Intrusion Detection, Second Edition is a training aid and reference for intrusion detection analysts. This book is meant to be practical. The authors are literally the most recognized names in this specialized field, with unparalleled experience in defending our country's government and military computer networks. People travel from all over the world to hear them speak, and this book will be a distillation of that experience. The book's approach is to introduce and ground topics through actual traffic patterns. The authors have been through the trenches and give you access to unusual and unique data.

Product Details

  • Paperback: 450 pages
  • Publisher: New Riders Publishing; 2nd edition (September 22, 2000)
  • Language: English
  • ISBN-10: 0735710082
  • ISBN-13: 978-0735710085
  • Product Dimensions: 8.9 x 7 x 1.1 inches
  • Shipping Weight: 1.6 pounds
  • Average Customer Review: 4.5 out of 5 stars  See all reviews (49 customer reviews)
  • Amazon.com Sales Rank: #306,264 in Books (See Bestsellers in Books)

    Popular in this category: (What's this?)

    #2 in  Books > Computers & Internet > Certification Central > Publisher > New Riders

More About the Author

Stephen Northcutt
Discover books, learn about writers, read author blogs, and more.

Visit Amazon's Stephen Northcutt Page

Look Inside This Book


Tags Customers Associate with This Product

 (What's this?)
Click on a tag to find related items, discussions, and people.
 

Your tags: Add your first tag
 

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

 

Customer Reviews

49 Reviews
5 star:
 (33)
4 star:
 (10)
3 star:
 (4)
2 star:
 (1)
1 star:
 (1)
 
 
 
 
 
Average Customer Review
4.5 out of 5 stars (49 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
59 of 60 people found the following review helpful:
4.0 out of 5 stars Best IDS book for hands-on implementors, January 29, 2000
By J. G. Heiser (Sunninghill, Berks) - See all my reviews
(REAL NAME)   
Of the 3 available intrusion detection texts, this is by far the best for someone who actually wants to do intrusion detection. It is breezy & chatty--like sitting down with a good friend (unfortunately, one who doesn't organize his thoughts very well and whose editor was apparently in a hurry).

This is a bits & bytes book; it assumes some knowledge of TCP/IP and security concepts, but it accomodates non-specialists. It is useful for readers of varying levels of familiarity with Internet protocols. Northcutt provides an excellent introduction to the specific mechanisms of the most common network attacks, and offers the most cogent description I've seen of the [purported] Mitnick attack on Shimomura.

I especially enjoyed his efforts at providing neophyte intrusion analysts with political advice. His insight that host-based IDS is technically superior to network-based, but politically impractical is a gem of organizational wisdom.

Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
47 of 47 people found the following review helpful:
5.0 out of 5 stars Readable, intelligent, down-to-earth., October 1, 1999
By Greg Broiles (San Jose, CA United States) - See all my reviews
(REAL NAME)   
Network Intrusion Detection is rare among technical books - it's comprehensive, accurate, interesting, and intelligent; it's got none of the "filler" chapters which seem to be prevalent in the genre. It's well worth the relatively small investment of time and money required to read and understand it.

The author has "been there, done that" which gives him a perspective unavailable to professional technical authors who write about Java one month, CORBA the next, will be assigned a firewall book next.

This book will be useful to people responsible for intrusion detection, people who manage them, and to people who need to understand attack techniques and the forensic tools needed to detect and document them. Highly recommended; it's in the same class as Cheswick & Bellovin's classic _Firewalls and Internet Security_.

Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
34 of 34 people found the following review helpful:
5.0 out of 5 stars Northcutt hits the ball out of the park!, August 25, 1999
I am the chief of a 15 person intrusion detection team, with responsibility for centralized, around-the-clock monitoring of a global network. I believe I have enough experience to claim Steven's book is first rate and sorely needed. His reconstruction of a Christmas Eve system compromise and his analysis of Kevin Mitnick's TCP hijack of Tsutomu Shimomura's host are excellent case studies. His coverage of reset scans and other non-standard reconnaissance techniques prompted me to scour my traffic for the same events and write a paper on my findings. I do not agree with some of his conclusions on SYN ACK and reset scans, but his work made me investigate those topics. While I would have preferred slightly more explanation and examples of network traces (who wouldn't?), I hope this book begins a trend of sharing (sanitized) packet-level incident details within the IDS community. I recommended Steven's book to every analyst on my flight and every person in my unit, and I plan to build in-house training around it. I guarantee every person with a technical leaning and a position on the front line of intrusion detection will appreciate Steven's book. See you at SANS Network Security 99
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews

5.0 out of 5 stars Great book!
This is a great book for both someone new to intrusion detection and people who already have familiarity with the field. Read more
Published 11 months ago by DanG

5.0 out of 5 stars Best for Practicing Professionals
This book is written for professionals who are practicing intrusion detection. If you need a graduate level presentation that contains theory and references, then see Intrusion... Read more
Published 16 months ago by C. Langin

5.0 out of 5 stars A well done work
The book's very good,it's very helpful for those who work with network,specially in security field.The authors are very experienced in networking. Read more
Published on June 27, 2007 by Danilo A. V. Lara

4.0 out of 5 stars Lots of good info here!
Very nice! Wow this book gets into detail, down to sequence numbers anomalies, I mean after reading this you can read tcpdumps and just be able to see whats going on - kind of... Read more
Published on April 10, 2007 by Angelo Bovis

1.0 out of 5 stars a classic case of lack of objectivity in review
If you read through the reviews, you would think that there is no other better book on the exposition of IDS systems than this one. Read more
Published on May 26, 2006 by Alan Turing

3.0 out of 5 stars Many elements are valid for beginners, but are othewise outdated
A book like this is always aiming at a moving target. I work at a company that focuses on up-to-the-minute IDS and IPS technologies, based substantially on the same code and... Read more
Published on May 15, 2006 by Rich Grace

4.0 out of 5 stars Excellent book at TCP/IP analysis
"Network Intrusion Detection" 3rd Edition, by Northcutt and Novak does an excellent job at teaching the protocols, tools and analysis required to become a network analysis. Read more
Published on February 5, 2006 by Sean E. Connelly

5.0 out of 5 stars Excellent book for the IDS manager
Network Intrusion Detection picks up where Implementing Intrusion Detection Systems by Tim Crothers leaves off. Read more
Published on November 27, 2005 by Daniel Owen

5.0 out of 5 stars Great Network Intrusion Book
The book takes you from the basics of network intrusion and takes you trough all the topics. The topics are interesting and the book is easy to read and understand. Read more
Published on October 5, 2005 by David Arana

4.0 out of 5 stars Very Good and Useful
This book is an excellent addition to any network administrator's library. Network Intrusion Detection will show you how some of the known and less known network intrusion attacks... Read more
Published on April 9, 2005 by D. Gough

Only search this product's reviews



Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 


Active discussions in related forums
Search Customer Discussions
Search all Amazon discussions
   




Product Information from the Amapedia Community

Beta (What's this?)


Look for Similar Items by Category


Look for Similar Items by Subject

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.



Your Recent History

 (What's this?)

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.