Security Monitoring
暫譯: 安全監控

Chris Fry, Martin Nystrom

  • 出版商: O'Reilly
  • 出版日期: 2009-03-24
  • 定價: $1,480
  • 售價: 5.0$740
  • 語言: 英文
  • 頁數: 246
  • 裝訂: Paperback
  • ISBN: 0596518161
  • ISBN-13: 9780596518165
  • 相關分類: 資訊安全
  • 立即出貨 (庫存 < 3)

買這商品的人也買了...

相關主題

商品描述

How well does your enterprise stand up against today's sophisticated security threats? In this book, security experts from Cisco Systems demonstrate how to detect damaging security incidents on your global network--first by teaching you which assets you need to monitor closely, and then by helping you develop targeted strategies and pragmatic techniques to protect them.

Security Monitoring is based on the authors' years of experience conducting incident response to keep Cisco's global network secure. It offers six steps to improve network monitoring. These steps will help you:

  • Develop Policies: define rules, regulations, and monitoring criteria
  • Know Your Network: build knowledge of your infrastructure with network telemetry
  • Select Your Targets: define the subset of infrastructure to be monitored
  • Choose Event Sources: identify event types needed to discover policy violations
  • Feed and Tune: collect data, generate alerts, and tune systems using contextual information
  • Maintain Dependable Event Sources: prevent critical gaps in collecting and monitoring events

Security Monitoring illustrates these steps with detailed examples that will help you learn to select and deploy the best techniques for monitoring your own enterprise network.

商品描述(中文翻譯)

如何評估您的企業在當今複雜的安全威脅下的抵抗能力?在這本書中,來自思科系統(Cisco Systems)的安全專家展示了如何在您的全球網絡上檢測有害的安全事件——首先教您需要密切監控哪些資產,然後幫助您制定針對性的策略和務實的技術來保護這些資產。

《安全監控》(Security Monitoring)基於作者多年進行事件響應以保持思科全球網絡安全的經驗。它提供了六個步驟來改善網絡監控。這些步驟將幫助您:

- 制定政策:定義規則、法規和監控標準
- 了解您的網絡:通過網絡遙測建立對基礎設施的了解
- 選擇目標:定義要監控的基礎設施子集
- 選擇事件來源:識別發現政策違規所需的事件類型
- 收集和調整:收集數據、生成警報,並使用上下文信息調整系統
- 維護可靠的事件來源:防止在收集和監控事件時出現關鍵漏洞

《安全監控》通過詳細的示例說明這些步驟,幫助您學習選擇和部署最佳技術來監控您自己的企業網絡。