or
Sign in to turn on 1-Click ordering.
Express Checkout with PayPhrase
What's this? | Create PayPhrase
More Buying Choices
Have one to sell? Sell yours here
or
Get a $3.82 Amazon.com Gift Card
Managing Security with Snort and IDS Tools
 
 
Tell the Publisher!
I’d like to read this book on Kindle

Don’t have a Kindle? Get your Kindle here, or download a FREE Kindle Reading App.

Managing Security with Snort and IDS Tools [Paperback]

Christopher Gerg (Author), Kerry J. Cox (Editor)
4.6 out of 5 stars  See all reviews (9 customer reviews)

List Price: $39.95
Price: $34.15 & this item ships for FREE with Super Saver Shipping. Details
You Save: $5.80 (15%)
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.
Want it delivered Friday, September 10? Choose One-Day Shipping at checkout. Details
16 new from $24.48 13 used from $12.73
Like this book? Find similar titles from O'Reilly and Partners in our O'Reilly Bookstore.

Frequently Bought Together

Managing Security with Snort and IDS Tools + Snort Cookbook + Snort IDS and IPS Toolkit (Jay Beale's Open Source Security)
Price For All Three: $96.28

Show availability and shipping details

Buy the selected items together
  • In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details

  • Snort Cookbook$29.16

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details

  • Snort IDS and IPS Toolkit (Jay Beale's Open Source Security)$32.97

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details


Customers Who Bought This Item Also Bought


Editorial Reviews

Product Description

Intrusion detection is not for the faint at heart. But, if you are a network administrator chances are you're under increasing pressure to ensure that mission-critical systems are safe--in fact impenetrable--from malicious code, buffer overflows, stealth port scans, SMB probes, OS fingerprinting attempts, CGI attacks, and other network intruders.

Designing a reliable way to detect intruders before they get in is a vital but daunting challenge. Because of this, a plethora of complex, sophisticated, and pricy software solutions are now available. In terms of raw power and features, SNORT, the most commonly used Open Source Intrusion Detection System, (IDS) has begun to eclipse many expensive proprietary IDSes. In terms of documentation or ease of use, however, SNORT can seem overwhelming. Which output plugin to use? How do you to email alerts to yourself? Most importantly, how do you sort through the immense amount of information Snort makes available to you?

Many intrusion detection books are long on theory but short on specifics and practical examples. Not Managing Security with Snort and IDS Tools. This new book is a thorough, exceptionally practical guide to managing network security using Snort 2.1 (the latest release) and dozens of other high-quality open source other open source intrusion detection programs.

Managing Security with Snort and IDS Tools covers reliable methods for detecting network intruders, from using simple packet sniffers to more sophisticated IDS (Intrusion Detection Systems) applications and the GUI interfaces for managing them. A comprehensive but concise guide for monitoring illegal entry attempts, this invaluable new book explains how to shut down and secure workstations, servers, firewalls, routers, sensors and other network devices.

Step-by-step instructions are provided to quickly get up and running with Snort. Each chapter includes links for the programs discussed, and additional links at the end of the book give administrators access to numerous web sites for additional information and instructional material that will satisfy even the most serious security enthusiasts.

Managing Security with Snort and IDS Tools maps out a proactive--and effective--approach to keeping your systems safe from attack.

About the Author

Kerry Cox is a knowledgeable and enthusiastic chief administrator/network engineer at Bonneville International/KSL Radio and Television where he manages 40 Red Hat Linux servers, as well as Solaris and FreeBSD, performing installation, patching, hardening, and maintenance. He also handles all Cisco routers, switches, PIX and Checkpoint firewalls, CSS load balancers, IDS sensors and consoles. Kerry has implemented open source solution for monitoring networks, architectures, server processes, and bandwidth. Previously, he worked at network communications companies and ISPs and is the author of two books by Prima: the Linux Productivity Administrator's Guide and Red Hat Linux Administrator's Guide.

Christopher Gerg CISSP, CHSP is the Network Security Manager for Berbee Information Networks. His IT career started with phone technical support for Microsoft s launch of Windows 95 and his MCSE dates back to NT 3.51. He s worked as a system and network administrator and has traveled extensively installing WANs and infrastructure for a variety of clients. Five years ago things changed Christopher discovered open-source operating systems (FreeBSD, Debian, and Suse are his favorites) and he s spent three years as a penetration tester with Berbee and then transitioned from attack to defend for the last two years. Christopher is responsible for the network security of two Enterprise-class datacenters, the customers located in them, and the network infrastructure that connects it all (Multiple OC-48 SONET rings and multiple OC-3 s to the Internet). He uses Snort to watch it all.

In his free time, Christopher raises rugged mountain alpacas in the wind-swept mountains of South-Central Wisconsin.


Product Details

  • Paperback: 304 pages
  • Publisher: O'Reilly Media (August 2004)
  • Language: English
  • ISBN-10: 0596006616
  • ISBN-13: 978-0596006617
  • Product Dimensions: 9.1 x 7 x 0.8 inches
  • Shipping Weight: 15.5 ounces (View shipping rates and policies)
  • Average Customer Review: 4.6 out of 5 stars  See all reviews (9 customer reviews)
  • Amazon Bestsellers Rank: #327,827 in Books (See Top 100 in Books)
    #97 in  Books > Computers & Internet > Networking > Intranets & Extranets
    #18 in  Books > Computers & Internet > Security & Encryption > Viruses

More About the Author

Kerry Cox
Discover books, learn about writers, read author blogs, and more.

Visit Amazon's Kerry Cox Page

Inside This Book (learn more)

What Do Customers Ultimately Buy After Viewing This Item?

Managing Security with Snort and IDS Tools
69% buy the item featured on this page:
Managing Security with Snort and IDS Tools 4.6 out of 5 stars (9)
$34.15
Snort IDS and IPS Toolkit (Jay Beale's Open Source Security)
14% buy
Snort IDS and IPS Toolkit (Jay Beale's Open Source Security) 4.5 out of 5 stars (4)
$32.97
Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning
6% buy
Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning 4.9 out of 5 stars (23)
$32.97
SnortFor Dummies
5% buy
SnortFor Dummies 3.8 out of 5 stars (4)
$11.70

Tags Customers Associate with This Product

 (What's this?)
Click on a tag to find related items, discussions, and people.
 
(2)

Your tags: Add your first tag
 

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

 

Customer Reviews

9 Reviews
5 star:
 (5)
4 star:
 (4)
3 star:    (0)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
4.6 out of 5 stars (9 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
12 of 13 people found the following review helpful:
5.0 out of 5 stars One of the better discourses on Snort, December 27, 2004
This review is from: Managing Security with Snort and IDS Tools (Paperback)
This is basically a book about intrusion detection using all open source tools. It starts with an introductory chapter that explains the problem of defining an intrusion and why it is becoming more and more of a problem. It follows up with a chapter on network traffic analysis including packet sniffing and using tcpdump and ethereal. Then comes the meat of the text - installing Snort. Of course to really understand how to use Snort you have to understand how attacks occur and the common methods used. The authors provide a really nice chapter on this subject. After that come five chapters on configuring, deploying, and managing Snort rules, intrusion prevention strategies, and tuning. Once Snort is up and running the authors examine the use of ACID and SnortCenter as Snort IDS management consoles. Either of these products drastically decreases the burden of analyzing what has happened and is happening on the intrusion detection forefront. The book ends with additional tools for Snort IDS management and implementation strategies for high-bandwidth situations.

There are other very good books on Snort but one of the things that makes this one particularly valuable is that it also looks at other open source tools and provides a good basic background on intrusion detection theory. Managing Security with Snort and IDS Tools is highly recommended for those in charge of intrusion detection and prevention in a network environment and planning to implement a system their self.
Help other customers find the most helpful reviews  
Was this review helpful to you? Yes No


 
12 of 14 people found the following review helpful:
4.0 out of 5 stars educate yourself in IDS, August 31, 2004
This review is from: Managing Security with Snort and IDS Tools (Paperback)
Welcome to Snort! More broadly, this book works well as a practical explanation of the general field of Intrusion Detection Systems. Key affiliated tools are covered, like tcpdump and Ethereal. Which are also free and open source, just like Snort. There is a general and I think understandable bias in this book towards such tools. The authors claim, and you must have heard this before, that such tools are often more likely to be bug free and mature than proprietary tools.

If you work your way through the chapters, then you can get a good education in the main ideas like setting up prevention strategies and how to look for evidence of attacks. Instantiated via using Snort. But if you're smart, you can generalise this. Plus, keep an eye out for any useful techniques that Snort currently lacks. If you find these, perhaps you can build a high value tool off them? Don't take Snort as the last word in these matters.
Help other customers find the most helpful reviews  
Was this review helpful to you? Yes No


 
9 of 10 people found the following review helpful:
5.0 out of 5 stars Excellent description of Snort, October 9, 2004
By E. Wuehler (Portland, OR) - See all my reviews
(REAL NAME)   
This review is from: Managing Security with Snort and IDS Tools (Paperback)
Up to this point, I've only use simple firewalls for my home network. Not that I think there's anything really worth hacking on my home network, but I thought I'd spend a little time learning about intrusion detection. This book is great for several reasons. First, it is well put together and easy to follow. Second, it describes in detail the open source project Snort. Finally, it satisfied my curiosity about IDS (Intrusion detection systems) - I'm not an expert, but I now understand the concepts.

Even though the book did not mention OS X specifically, it was easy to get snort compiled and installed on my Mac. There were a few tweaks I had to do, but if you're familiar with "configure; make; make install", it should be a snap. (Likewise, fink or darwinports can get you going with Snort as well). Any other flavor of Unix/Linux would be that much easier to install.

Beyond just describing how to install and configure Snort, the book does go into some detail about how networks are attacked and how Snort goes about alerting you to possible intrusive behavior. There are also numerous reference to web sites and other books to find more information. It also goes into detail on various other tools that augment and complement Snort.

Very well done.
Help other customers find the most helpful reviews  
Was this review helpful to you? Yes No

Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews

4.0 out of 5 stars Great info on how to use SNORT properly
O'reilly's books are awesome... and this is no different. Anything and everything on how to use SNORT properly is listed here. Rules and syntax are easy to implement. Read more
Published 21 months ago by J. Page

5.0 out of 5 stars Excellent coverage of a complex topic

A well-rounded treatment of Snort and IDS in general. The refresher on packet structure is welcome and necessary. Read more
Published on January 5, 2008 by J. Loupe

5.0 out of 5 stars Intrusion Detection for Professionals
This book is more than a great overview of Intrusion Detection and Defense in Depth using Snort. The authors provide details on packet inspection, configuring Snort, rulesets, and... Read more
Published on November 9, 2007 by Robert Abuhoff

4.0 out of 5 stars Just what I needed
The information I wanted when I bought this book is there. This book will be like my Unix in a Nut Shell book. Read more
Published on August 31, 2007 by Daniel L. Miller

4.0 out of 5 stars Snort made easy!
O'Reilly's "Managing Security with Snort and IDS Tools" by Cox and Greg is a practical book that succinctly describes the basic functionality and utility of implanting Snort. Read more
Published on March 9, 2006 by Sean E. Connelly

5.0 out of 5 stars Excellent!
Managing Security with Snort and IDS Tools is just a great book.

Don't even try to use Snort without reading this book first.
Published on February 28, 2005 by Eric Kent

Only search this product's reviews



Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 


Active discussions in related forums
Search Customer Discussions
Search all Amazon discussions
   





Look for Similar Items by Category


Look for Similar Items by Subject

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.


Your Recent History

 (What's this?)

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.