The Practice of Network Security Monitoring: Understanding Incident Detection and Response (Paperback)
暫譯: 網路安全監控實務:理解事件偵測與回應 (平裝本)

Richard Bejtlich

買這商品的人也買了...

商品描述

Network security is not simply about building impenetrable walls — determined attackers will eventually overcome traditional defenses. The most effective computer security strategies integrate network security monitoring (NSM): the collection and analysis of data to help you detect and respond to intrusions.

In The Practice of Network Security Monitoring, Mandiant CSO Richard Bejtlich shows you how to use NSM to add a robust layer of protection around your networks — no prior experience required. To help you avoid costly and inflexible solutions, he teaches you how to deploy, build, and run an NSM operation using open source software and vendor-neutral tools.

You'll learn how to:

  • Determine where to deploy NSM platforms, and size them for the monitored networks
  • Deploy stand-alone or distributed NSM installations
  • Use command line and graphical packet analysis tools, and NSM consoles
  • Interpret network evidence from server-side and client-side intrusions
  • Integrate threat intelligence into NSM software to identify sophisticated adversaries

There's no foolproof way to keep attackers out of your network. But when they get in, you'll be prepared. The Practice of Network Security Monitoring will show you how to build a security net to detect, contain, and control them. Attacks are inevitable, but losing sensitive data shouldn't be.

商品描述(中文翻譯)

網路安全不僅僅是建立不可穿透的防護牆——堅定的攻擊者最終會克服傳統的防禦措施。最有效的電腦安全策略整合了網路安全監控(NSM):收集和分析數據以幫助您檢測和應對入侵。

在《網路安全監控實務》中,Mandiant 的首席安全官 Richard Bejtlich 向您展示如何使用 NSM 為您的網路增添一層強大的保護——不需要任何先前的經驗。為了幫助您避免昂貴且不靈活的解決方案,他教您如何使用開源軟體和廠商中立的工具來部署、建設和運行 NSM 操作。

您將學會如何:

- 確定在哪裡部署 NSM 平台,並根據被監控的網路進行規模調整
- 部署獨立或分散式的 NSM 安裝
- 使用命令行和圖形化的封包分析工具,以及 NSM 控制台
- 解釋來自伺服器端和客戶端入侵的網路證據
- 將威脅情報整合到 NSM 軟體中,以識別複雜的對手

沒有萬無一失的方法可以將攻擊者拒之門外。但當他們進入時,您將做好準備。《網路安全監控實務》將向您展示如何建立一個安全網,以檢測、遏制和控制他們。攻擊是不可避免的,但失去敏感數據則不應該。