Practical Intrusion Analysis: Prevention and Detection for the Twenty-First Century Review

Practical Intrusion Analysis: Prevention and Detection for the Twenty-First Century
Average Reviews:

(More customer reviews)
I must start this review by stating the lead author lists me in the Acknowledgments and elsewhere in the book, which I appreciate. I also did consulting work years ago for the lead author's company, and I know the lead author to be a good guy with a unique eye for applying geography to network security data. Addison-Wesley provided me a review copy.
I did not participate in the writing process for Practical Intrusion Analysis (PIA), but after reading it I think I know how it unfolded. The lead author had enough material to write his two main sections: ch 10, Geospatial Intrusion Detection, and ch 11, Visual Data Communications. He realized he couldn't publish a 115-page book, so he enlisted five contributing authors who wrote chapters on loosely related security topics. Finally the lead author wrote two introductory sections: ch 1, Network Overview, and ch 2, Infrastructure Monitoring. This publication-by-amalgamation method seldom yields coherent or helpful material, despite the superior production efforts of a company like Addison-Wesley. To put a point on PIA's trouble, there's only a single intrusion analyzed in the book, and it's in the lead author's core section. The end result is a book you can skip, although it would be good for chapters 4 and 10 to be published separately as digital "Short Cuts" on InformIT.
Chapters 1 and 2 are not needed. Anyone who needs to learn about networking can read a basic book already published. Ch 2 does mention that 802.1AE (if ever implemented) will hamper network traffic inspection, but you could read that online.
Ch 3 is odd because it begins by mentioning well-worn methods to evade network detection, followed by a discussion of the merits of Snort vs Bro. Someone who had to read the material in chapters 1 and 2 is not going to understand the Snort discussion, especially when it mentions byte_test, depth, regex, http_inspect, uricontent, Structured Exception Handlers, and 16 line Snort signatures. I liked seeing Bro mentioned, but the people who are going to be able to follow the sample Bro policy scripts on pages 75-78 are not the ones reading this book.
Ch 4 outlines several examples of writing signatures for Snort. This section is actually interesting, but you have to know Snort and certain advanced topics pretty well to get value from this section. Readers need to compensate for the far-too-small screenshots and lack of supporting details while reading the examples. Readers also need to figure out what the author is doing, such as when he sets up a client-side exploit against FlashGet by starting a malicious FTP server with flashget-overflow.pl. By the second example he's dropping warnings like "Had Core's advisory told you from where the size of the call to memcpy was coming, you might have to refine the signature to check for the appropriate behavior; unfortunately, the disassembly left out that argument:" [cue the ASM]. The bottom line with this chapter is this: know your audience, and write for them -- not your buddies. People who can follow contributions like this "at line speed" aren't going to read this book.
By ch 5 the "practical" aspect of this book has been left behind, with a discussion of "proactive intrusion prevention and response via attack graphs, which is really an academically-derived discussion of "topological vulnerability analysis." No one does this in the operational world, and no one will. Pages 143-144 talk about IDMEF, even though that specification died years ago. (There is still an independently-maintained -- as of Feb 09 -- Snort-IDMEF plugin. I don't know anyone in industry using it.)
Ch 6 is a generic overview of using network flows. The only new material is less than a page on IPFIX, which is just a table comparing that newer format with NetFlow. Ch 7 is called "Web Application Firewalls," but it's just an overview. Read Ivan Ristic's Apache Security or Ryan Barnett's Preventing Web Attacks with Apache if you want to know this topic. Ch 7 is titled "Wireless IDS/IPS," which is an even shallower overview than the previous topic. In none of these chapters do we have anything practical nor any intrusions analyzed. Ch 9 discusses physical security, but I didn't think it fit with the intended theme for the book.
I thought chapter 10 was interesting. Geospatial and visualization techniques do have a role in many operations, and ch 10 had the only example of an intrusion analysis. Unfortunately I don't think readers could take ch 10 and implement their own operational system. Ch 11 seemed irrelevant in light of the excellent visualization books by Raffy Marty and Greg Conti.
The book finishes with ch 12, Return on Investment: Business Justification. It was totally unnecessary: cite some regulations, list some breach costs, then compare ROI, NPV, and IRR. Talk a little about MSSPs and cyber liability insurance, then end. If you really want the best discussion of security costs, read Managing Cybersecurity Resources by Gordon and Loeb.
The subtitle for PIA is "Prevention and Detection for the Twenty-First Century." Readers will not find that in PIA. The lead author started with a kernel of a good idea, but the end result does not deliver enough real value to to readers. The lead author's material, and the chapter on Snort signature writing, could have been published as digital Short Cuts, or including in a compendium of chapters in a "survey" book. If you want to read a book intrusion analysis, you're more likely to be satisfied reading a book on intrusion forensics.

Click Here to see more reviews about: Practical Intrusion Analysis: Prevention and Detection for the Twenty-First Century

"Practical Intrusion Analysis provides a solid fundamental overview of the art and science of intrusion analysis." –Nate Miller, Cofounder, Stratum SecurityThe Only Definitive Guide to New State-of-the-Art Techniques in Intrusion Detection and PreventionRecently, powerful innovations in intrusion detection and prevention have evolved in response to emerging threats and changing business environments. However, security practitioners have found little reliable, usable information about these new IDS/IPS technologies. In Practical Intrusion Analysis, one of the field's leading experts brings together these innovations for the first time and demonstrates how they can be used to analyze attacks, mitigate damage, and track attackers. Ryan Trost reviews the fundamental techniques and business drivers of intrusion detection and prevention by analyzing today's new vulnerabilities and attack vectors. Next, he presents complete explanations of powerful new IDS/IPS methodologies based on Network Behavioral Analysis (NBA), data visualization, geospatial analysis, and more.Writing for security practitioners and managers at all experience levels, Trost introduces new solutions for virtually every environment. Coverage includesAssessing the strengths and limitations of mainstream monitoring tools and IDS technologies

Buy NowGet 34% OFF

Click here for more information about Practical Intrusion Analysis: Prevention and Detection for the Twenty-First Century

Read More...

Pervasive Computing Handbook Review

Pervasive Computing Handbook
Average Reviews:

(More customer reviews)
This book explains new technologies in a very simple and informative way. It would have been nice to find some more links to business, but this seems not to be the target market. Ideal for engineers that need to get an update on technologies.

Click Here to see more reviews about: Pervasive Computing Handbook

This book is a guide for the world of pervasive computing. It covers a variety of front-end devices and their opening systems as well as the back-end systems which have to integrate the pervasive components into a seamless IT world. A strong emphasis is placed on the underlying technologies and standards applied when building up pervasive solutions. These fundamental topics include commonly used terms such as XML, WAP, transcoding, and cryptography, to mention just a few. The book presents an overview of the different development strategies and tools for different pervasive platforms. In order to ease the planning and development of new solutions, concepts and considerations specific to a variety of different target environments, such as e-Business, private home, finance, and travel, are explained. Case studies of pervasive computing in upcoming real-life solutions are comprehensive

Buy Now

Click here for more information about Pervasive Computing Handbook

Read More...

CompTIA A+ Complete Study Guide: Exams 220-701 (Essentials) and 220-702 (Practical Application) Review

CompTIA A+ Complete Study Guide: Exams 220-701 (Essentials) and 220-702 (Practical Application)
Average Reviews:

(More customer reviews)
This book is really great it has everything you need to pass the A+ 2009 Objectives. I took my A+ Test two days about and passed. This book covers alot of stuff that you would see on the test believe me when I tell you this. Make sure if you are taking the A+ 2009 objectives that you know your port numbers and what they are for because the test is going to ask you about this. This book really set the tone for the exam so if you want to pass get this book.

Click Here to see more reviews about: CompTIA A+ Complete Study Guide: Exams 220-701 (Essentials) and 220-702 (Practical Application)

Two Exams in One Book! A+ Essentials (220-701) and Practical Application (220-702)
Written by a team of industry experts, this unparalleled study guide offers you a systematic approach to preparing for the CompTIA A+ certification, and includes real-world scenarios, hands-on exercises, challenging chapter review questions, plus a CD with Sybex's custom test engine to reinforce all of the concepts you learn.

Get full coverage of all of the exam objectives for both the 220-701 and 220-702 exams, Inside this guide you'll learn how to:

Identify and understand PC system components, including motherboards, processors, memory, and cooling systems.
Identify and understand storage devices, power supplies, display devices, and adapters.
Install, configure, and troubleshoot desktops, laptops, and portable devices.
Install, configure, and troubleshoot printers.
Install and configure operating systems including Windows 2000, XP, Vista, and Windows 7.
General troubleshooting theory and preventive maintenance.
Troubleshooting operating systems, hardware, printers, and laptops.
Install, configure, and troubleshoot networks
Set up and maintain network security
Master essential operational procedures for PC technicians
Communicate professionally with co-workers and clients

Updated Coverage Includes Windows 7 Topics

This study guide includes updated content coveringWindows 7topics which were added to the CompTIA A+ examin January, 2011. The supplemental content includes additional review questions, additional practice exam questions, and an updated objectives map. (Note that theupdated content is also available for download from theResources & Downloads tab on the product page atsybex.com.)

Featured on the CD

Over 600 Practice questions
Six practice tests (3 for the 220-701, and 3 for 220-702)
Electronic flashcards
Entire book as a searchable PDF

Note:CD-ROM/DVD and other supplementary materials are not included as part of eBook file.

For Instructors:Teaching supplements are available for this title.


Buy NowGet 41% OFF

Click here for more information about CompTIA A+ Complete Study Guide: Exams 220-701 (Essentials) and 220-702 (Practical Application)

Read More...

Laptops For Dummies Review

Laptops For Dummies
Average Reviews:

(More customer reviews)
I have a few favorite topics to look up when thinking about laptops.
User Guide: Does the book describe how to find information (such as a user guide) from the manufacturer? No.
Main Battery: Does the book advise checking with the manufacturer on recalibrating or reconditioning the battery before replacing it? No. However, it does give plenty of helpful information on taking care of your battery.
Cleaning the screen: This book does well. I'd feel better if it mentioned a microfiber cloth.
Protecting the screen from keyboard rubbing: Has good advice.
Matte screens: Does the book mention matte screens and how to find them? No.
Netbooks: Gives netbooks an honorable mention. Does not mention the difficult of seeing the bottom of a windows (including the OK and Cancel buttons(!!) on netbooks with screens only 600-pixels high.
Macs: Apple computers are not indexed.
Antivirus: This book gives an adequate description of antivirus programs.
Theft protection: Good overview of avoiding theft. Mentions the security slot. No mention of LoJack for Laptops, Prey Project, or similar.
Fn key: Not indexed.
Windows Update: His recommendation for automatic updating is based on an update occurring while traveling and forcing a delay while the machine laboriously installed the update. Windows 7 allows you to postpone a restart. Also, note that Microsoft Update (which I always turn on) is not mentioned. Neither is Secunia PSI or Cnet's Techtracker.
Assumes you started with client-based email (such as Windows Mail).
Administrative user account vs. standard user accounts: No mention of the desirability of using standard user accounts for everyday use.
This book comes close. I appreciate that the author spent time describing things in a useful way. But it leaves out some essentials, things I would mention in a first-day class on laptops.
Recommended with reservations.

Click Here to see more reviews about: Laptops For Dummies

The latest edition of the bestselling guide to getting started with a laptop
No one knows computers like veteran author Dan Gookin. With this new edition of his bestseller, he shares his wealth of knowledge and once again finesses even the most complex of topics and presents it in such a way that makes it simple, entertaining, and easy to understand.
You'll explore the latest hardware and technology updates and delve into the most updated information on Windows 7. You'll review the many issues that are unique to laptops, including synchronizing with the desktop, coordinating e-mail between two machines, working on the road, and more.
Beloved and popular author Dan Gookin returns with a new edition that makes understanding laptops simpler than you ever thought possible
Shares the latest information concerning laptops: new technology, current processors available, and steps to update memory and hard drive capabilities
Includes coverage of connectivity between a laptop and desktop, interfaces between laptops, add-ons, networking procedures, and more
Reviews the perks of newer laptops, including larger displays, longer battery power, and speeds equal to desktops to name a few
Examines the benefits of mobility for students, employees, and anyone who needs to work on the go

This fun and friendly guide will get you up and running with your laptop in no time!

Buy NowGet 38% OFF

Click here for more information about Laptops For Dummies

Read More...

Security Cottage: a Secure Environment for IEEE 802.15.4 Devices (Volume 1) Review

Security Cottage: a Secure Environment for IEEE 802.15.4 Devices (Volume 1)
Average Reviews:

(More customer reviews)
Perhaps not, but at $365 for 108 pages, Usman's "book" is a completely ridiculous product. Normally, such publications (generally called "theses" by PhD candidates) are published by the school at cost, or barely above (perhaps $20 for a binding and distribution fee).
With the advent of on-demand printing services, certainly that cost has come down to the point of being comparable to the cost of manually photocopying pages and then stapling them together.
Skip Usman's book, and instead read any of a host of other, far less expensive and more in-depth, books available.

Click Here to see more reviews about: Security Cottage: a Secure Environment for IEEE 802.15.4 Devices (Volume 1)

Ubiquitous wireless sensor networks are networks consisting of several small computers operational with sensors to discover events like human movement with infrared sensors or resolve the existing state of certain parameters like temperature. These sensor nodes are assembled with a radio to commune with each other and to broadcast data to a central computer where this data can be analyzed. These new sensing computing machines come with new challenges. To eliminate the limitations imposed by wires, sensors possess limited energy sources and correspond with neighboring nodes using wireless networks. Due to critical nature of applications, securing data generated in sensor field by sensors is important. While data security is necessary, the functionality cost in terms of routing and energy needs to be assessed carefully. Limited bandwidth and memory pull the trigger to make more sophisticated and light weight cryptography models. Moreover, deployment of tiny devices like sensor nodes in hostile environment, make it easier for intruder to budge in, plant attack node or control over the legitimate node to launch an attack. In this book, we have analyzed the basic threat model in ubiquitous wireless sensor network (USWN), and presented a quad tree based network portioning scheme, which ensure data accuracy at primary level. Each sensor node maintains neighboring table which stores the node information, our neighbor voting based defense solution helps to authenticate clear text broadcast of control packets. Once we have identified malicious node, our localization scheme can highlight the vulnerable node locality, even most of anchors are compromised. Localization scheme also helped us to strengthen defense against Sybil attack and wormhole attack. We analyze security of proposed scheme against Hello flood, data authentication attacks, node cloning attack and routing attacks.In the existing scenarios, where diverse security services are independent from each other, each service adds an additive communication overhead. By incorporating energy-concentrated security services that are regularly required in sensor network applications, we considerably decrease the energy.

Buy Now

Click here for more information about Security Cottage: a Secure Environment for IEEE 802.15.4 Devices (Volume 1)

Read More...

Todd Lammle's CCNA IOS Commands Survival Guide Review

Todd Lammle's CCNA IOS Commands Survival Guide
Average Reviews:

(More customer reviews)
Lammle's stated objective is to help the reader prepare for and pass the difficult CCNA exam. This book expands a bit on that objective. He states in the introduction that this is supplementary material. It's written to assist the student in understanding the line of thought behind the technology.
I found that quite useful. The CCNA is a rigorous exam; those who pass it have a pretty good understanding of the concepts and protocols. But "real world" practice is a trickier thing, especially NAT, and Lammle's book concisely tackles those issues of keeping a network running. He clearly discusses the "why". I'm keeping the book on my desk as a reference work beyond just exam prep. It's money well-spent.



Click Here to see more reviews about: Todd Lammle's CCNA IOS Commands Survival Guide

To become a Cisco Certified Network Associate (CCNA), you must learn the hundreds of IOS commands used by Cisco routers and switches. This handy reference from Cisco networking authority Todd Lammle is just what you need to master those commands. From a thorough introduction to Cisco's basic operating system to making the transition to IPv6, Todd Lammle walks you through hundreds of commands with short, to-the-point explanations and plenty of figures and real-world examples.

Buy NowGet 41% OFF

Click here for more information about Todd Lammle's CCNA IOS Commands Survival Guide

Read More...

Android Programming Tutorials, 2nd Edition Review

Android Programming Tutorials, 2nd Edition
Average Reviews:

(More customer reviews)
My only complaint is the page numbers are in the center and makes it harder when searching for a specific page.
Otherwise the book has some good code examples in it that helps fill in the gaps on the SDK examples. It has already helped answer a couple of questions I had without having to go write code to test things out to see how they work.

Click Here to see more reviews about: Android Programming Tutorials, 2nd Edition

Android Programming Tutorials show you what you can do with Android, through a series of 40 individual exercises. Android Programming Tutorials gives you hands-on instruction in how to build sophisticated Android applications, using many of the technologies outlined in CommonsWare's other Android books.These exercises lead you through the basics of creating Android applications, all the way through many fun Android features like Internet access, location tracking, maps, integrated WebKit browsers, cameras, accelerometers, home screen widgets, and much more. Full source code to all the exercise answers is available, to help you if you get stuck. Android Programming Tutorials makes an excellent companion volume to more traditional Android books that merely tell you what is possible.

Buy Now

Click here for more information about Android Programming Tutorials, 2nd Edition

Read More...