Start reading Network Security Through Data Analysis on your Kindle in under a minute. Don't have a Kindle? Get your Kindle here or start reading now with a free Kindle Reading App.

Deliver to your Kindle or other device


Try it free

Sample the beginning of this book for free

Deliver to your Kindle or other device

Sorry, this item is not available in
Image not available for
Image not available

Network Security Through Data Analysis: Building Situational Awareness [Kindle Edition]

Michael S Collins

Print List Price: £33.50
Kindle Price: £22.23 includes VAT* & free wireless delivery via Amazon Whispernet
You Save: £11.27 (34%)
* Unlike print books, digital books are subject to VAT.

Free Kindle Reading App Anybody can read Kindle books—even without a Kindle device—with the FREE Kindle app for smartphones, tablets and computers.

To get the free app, enter your e-mail address or mobile phone number.


Amazon Price New from Used from
Kindle Edition £22.23  
Paperback £33.50  
Kindle Daily Deal
Kindle Daily Deal: Up to 70% off
Each day we unveil a new book deal at a specially discounted price--for that day only. Learn more about the Kindle Daily Deal or sign up for the Kindle Daily Deal Newsletter to receive free e-mail notifications about each day's deal.

Book Description

Traditional intrusion detection and logfile analysis are no longer enough to protect today’s complex networks. In this practical guide, security researcher Michael Collins shows you several techniques and tools for collecting and analyzing network traffic datasets. You’ll understand how your network is used, and what actions are necessary to protect and improve it.

Divided into three sections, this book examines the process of collecting and organizing data, various tools for analysis, and several different analytic scenarios and techniques. It’s ideal for network administrators and operational security analysts familiar with scripting.

  • Explore network, host, and service sensors for capturing security data
  • Store data traffic with relational databases, graph databases, Redis, and Hadoop
  • Use SiLK, the R language, and other tools for analysis and visualization
  • Detect unusual phenomena through Exploratory Data Analysis (EDA)
  • Identify significant structures in networks with graph analysis
  • Determine the traffic that’s crossing service ports in a network
  • Examine traffic volume and behavior to spot DDoS and database raids
  • Get a step-by-step process for network mapping and inventory

Product Description

Book Description

Building Situational Awareness

About the Author

Michael Collins is the chief scientist for RedJack, LLC., a NetworkSecurity and Data Analysis company located in the WashingtonD.C. area. Prior to his work at RedJack, Dr. Collins was a member ofthe technical staff at the CERT/Network Situational Awareness group at Carnegie Mellon University. His primary focus is on networkinstrumentation and traffic analysis, in particular on the analysis oflarge traffic datasets.Dr. Collins graduated with a PhD in Electrical Engineering fromCarnegie Mellon University in 2008, he holds Master's and Bachelor'sDegrees from the same institution.

Product details

  • Format: Kindle Edition
  • File Size: 7088 KB
  • Print Length: 348 pages
  • Simultaneous Device Usage: Unlimited
  • Publisher: O'Reilly Media; 1 edition (10 Feb. 2014)
  • Sold by: Amazon Media EU S.à r.l.
  • Language: English
  • ASIN: B00IB126JI
  • Text-to-Speech: Enabled
  • X-Ray:
  • Word Wise: Not Enabled
  • Amazon Bestsellers Rank: #332,962 Paid in Kindle Store (See Top 100 Paid in Kindle Store)
  •  Would you like to give feedback on images?

More About the Author

Discover books, learn about writers, and more.

What Other Items Do Customers Buy After Viewing This Item?

Customer Reviews

There are no customer reviews yet on
5 star
4 star
3 star
2 star
1 star
Most Helpful Customer Reviews on (beta) 4.4 out of 5 stars  5 reviews
6 of 7 people found the following review helpful
4.0 out of 5 stars Network Security Through Data Analysis review 6 July 2014
By Javier - Published on
One of the goals of this book is achieving situational awareness or, to put it another way, an understanding of the environment you are operating in. This book is about collecting data and looking at networks in order to understand how the network is used.

The author mentions the target for this book are network administrators and operational security analyts. I would add networking students and hackers on the top of this target. The content is very easy to follow though.

The book is divided into three sections (data, tools and analytics). It contains a total of 15 self-contained chapters.

The data section (chapters 1-4) covers the way to collect, storage and organize data. This part discuss about sensors, the best place to set them, the tooling to interface them and the issues/solutions related to the vast amount of data generated.

The tool section (chatpers 5-9) keeps the focus on tools. It covers analysis, visualization and reporting aspects. Some of these tools are SiLK, R, Graphviz, nmap, Wireshark or netcat.

The analytics section (chapters 10-15) studies the nature of the networking traffic and how some mathematical and statistical models can be used to examine data. Among the different analysis you can find useful information related to DDoS attacks, scanning patterns or port correlations approaches.

This book is interesting. It is a great update in this topic and it faces the recent issue of ‘big data’ and massive analysis from a network security perspective.

At the same time, I found the jargon of the author a bit thick along some chapters. I guess it is the result of trying to generalize some concepts and techniques while he introduces concrete examples.

As mentioned, I think this book contains good stuff. It covers a broad spectrum of topics so it could be a great book to jump in this area too. The author makes a good job and he talks from experience.
9 of 11 people found the following review helpful
4.0 out of 5 stars A guide to finding new threats in any secure operations center 7 Mar. 2014
By KEVIN M NOBLE - Published on
Format:Kindle Edition|Verified Purchase
The book takes considerable time to explain traffic in general, sensing traffic and the logistics around making sense of network data both at the simplistic and the next level of analysis. Anyone who has a solid understanding or working in network monitoring can skip ahead to the more interesting analysis techniques at each layer of traffic, using fundamental principals and visualization to find potential threats.

The exploration of volume and time analysis was particularly interesting to me as I do similar work however, only goes far enough to give the reader or anyone willing to try the code presented in the book an idea of what is to be expected. Probably wise of the author not to go too deep and demonstrate a wide range of analysis missing in data centers and security operations.

I found the book to insightful and useful and good for anyone looking to make the leap to the higher echelons of detection.
4 of 5 people found the following review helpful
5.0 out of 5 stars Informative at all career levels 17 Jun. 2014
By Jason A Rafail - Published on
To be upfront and open, I've known Michael for a number of years and worked with him at the CERT/CC. He is a brilliant analyst and has always been on the cutting edge of Network Analysis. His book is a nice blend of the basic principles and more advanced research techniques that few security analysts pursue. As people have said already, this is a comprehensive book that takes a look at Network Security from the basics into some of the often not thought about aspects. There are the basics of flow analysis and monitoring to start the reader off with a solid foundation, then the later chapters delve into true analysis. Most security professionals grasp the basics for interpretation of the flows to see trends and attacks, but few go further into the techniques for analysis of the packets to gain deeper intelligence into potential motives and attempts made against systems. This books takes the readers from their comfortable basics and introduces these thought processes and techniques in an understandable and easy to follow way. With examples and explanations to help develop this knowledge.

This isn't another user guide for existing monitor and alerting software, it is a tool for security analysts to use when actively trying to understand the overwhelming and generalized information they gather through such tools. With the examples and details provided, network engineers can dig deeper to better understand the source of threats and desired targets on their network. There's more to Network Security than just responding to software alerts and this book provides a good foothold into the more advanced analysis.
4 of 6 people found the following review helpful
5.0 out of 5 stars Great guide 2 May 2014
By Timm McShane - Published on
Format:Paperback|Verified Purchase
Should be considered a gold standard for learning network security.
Breaks down the analysis problem effectively, clearly and simply. Starts from the beginning, allow new comers to get the full background needed to come up to speed rapidly.
2 of 4 people found the following review helpful
4.0 out of 5 stars good read 31 Aug. 2014
By Drivel - Published on
Format:Kindle Edition|Verified Purchase
I learned quite a bit. I feel like I need to take a course on statistical analysis in order to get the most out of the book, however.
Were these reviews helpful?   Let us know

Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
First post:
Prompts for sign-in

Search Customer Discussions
Search all Amazon discussions

Look for similar items by category