11 used & new from £1.70

Have one to sell? Sell yours here
 
 
Network Intrusion Detection: An Analyst's Handbook (Landmark)
 
See larger image
 

Network Intrusion Detection: An Analyst's Handbook (Landmark) (Paperback)

by Judy Novak (Author), Stephen Northcutt (Author)
4.0 out of 5 stars  See all reviews (4 customer reviews)

Available from these sellers.


2 new from £69.45 9 used from £1.70

Customers Viewing This Page May Be Interested in These Sponsored Links

  (What is this?)
   Network Intrusion Detection opens new browser window
www.globalspec.com  -  Free Technical Search Engine Search Thousands of Catalogs Today 
   Intrusion detection opens new browser window
www.FindWhitePapers.com  -  Download Free IT White Papers about Intrustion Detection 
   Network Forensic Analysis opens new browser window
www.SoleraNetworks.com  -  You can't stop what you can't find You need Network Forensics 
  
 

Customers Who Bought This Item Also Bought

Intrusion Signatures and Analysis

Intrusion Signatures and Analysis

by Matt Fearnow
4.0 out of 5 stars (2)  £30.99
Intrusion Detection (MacMillan Technology)

Intrusion Detection (MacMillan Technology)

by Rebecca Gurley Bace
£38.99
Intrusion Detection with Snort

Intrusion Detection with Snort

by Jack Koziol
£28.04
Secrets and Lies: Digital Security in a Networked World

Secrets and Lies: Digital Security in a Networked World

by Bruce Schneier
4.7 out of 5 stars (23)  £8.37
Inside Network Perimeter Security

Inside Network Perimeter Security

by Stephen Northcutt
£35.99
Explore similar items

Product details

  • Paperback: 450 pages
  • Publisher: QUE; 2 edition (29 Sep 2000)
  • Language English
  • ISBN-10: 0735710082
  • ISBN-13: 978-0735710085
  • Product Dimensions: 22.6 x 17.8 x 2.8 cm
  • Average Customer Review: 4.0 out of 5 stars  See all reviews (4 customer reviews)
  • Amazon.co.uk Sales Rank: 963,068 in Books (See Bestsellers in Books)
  • See Complete Table of Contents

Product Description

Amazon.co.uk Review

A collection of after-action reports on a variety of network attacks, Network Intrusion Detection enables you to learn from others' mistakes as you endeavour to protect your networks from intrusion. Authors Stephen Northcutt and Judy Novak document real attacks on systems, highlighting characteristics you--you being a network communications analyst or security specialist--can look for on your own machines. The authors mince no words, advising you which detection tools to use (they like and use Snort, as well as Shadow, Tripwire, TCP Wrappers and others) and how to use them. This second edition of the book includes less about Year 2000 preparation and more about the latest in attacks, countermeasures, and the growing community of white-hat hackers who share information to keep systems safe.

In teaching their readers about the attacks that exploit a particular protocol or service, the authors typically present a TCPdump listing that shows an attack, then comment upon it. They tell you what the attackers did, how successful they were, and how the attack might have been detected and shut down. To cite one example, there's a very detailed analysis of Kevin Mitnick's famous attack (a SYN flood combined with TCP hijacking) on one of Tsutomu Shimomura's machines. By following the advice in this book, you will likely do very well in protecting your machines against people the authors call "script kiddies"--small-time hackers who follow published recipes (or run pre-written routines). You will also be about as prepared as you can be against more skilled attackers who make up their attacks on their own. This is great reading for anyone involved in developing filters to ward off attacks or monitoring network communications for suspicious activity. It's also a valuable resource for someone evaluating network countermeasures in preparation for deployment. --David Wall



Amazon.co.uk Review

Network Intrusion Detection: An Analyst's Handbook explains some of what you need to know in order to prevent unauthorised accesses of your networked computers and minimise the damage intruders can do. It emphasises, though, proven techniques of recognising attacks while they're underway. Without placing too much emphasis (or blame, for that matter) on any operating system or other software product, author Stephen Northcutt explains ways to spot suspicious behaviour and deal with it, both automatically and manually.

The case studies, large and small, are the best part of this book. Northcutt opens with a technical brief on the methods used by Kevin Mitnick in his attack upon Tsutomu Shimomura's server. In documenting that famous attack, Northcutt explains SYN flooding and TCP hijacking with clarity and detail: Readers get a precise picture of what Mitnick did, and how Shimomura's machine reacted. A former security expert for the US Department of Defense, Northcutt goes on to explain how a system administrator would go about detecting and defeating an attack like Mitnick's. Another case study appears later in the book, this one in the form of a line-by-line analysis of a history file that shows how a bad guy with root privileges attacked a Domain Name System (DNS) server. Reading Northcutt's analysis is like reading a play-by-play account of a football match. Network Intrusion Detection is one of the most readable technical books around. --David Wall, Amazon.com

Topics covered: Catching intruders in the act by recognising the characteristics of various kinds of attacks in real-time, both manually and with the use of filters and other automated systems; techniques for identifying security weaknesses and minimising false security alarms. --This text refers to an out of print or unavailable edition of this title.


Suggested Tags from Similar Products

 (What's this?)
Be the first one to add a relevant tag (keyword that's strongly related to this product)
 
intrusion detection

Your tags: Add your first tag
 

What Do Customers Ultimately Buy After Viewing This Item?

Network Intrusion Detection: An Analyst's Handbook (Landmark)
96% buy the item featured on this page:
Network Intrusion Detection: An Analyst's Handbook (Landmark) 4.0 out of 5 stars (4)
Inside Network Perimeter Security
3% buy
Inside Network Perimeter Security
£35.99
Intrusion Signatures and Analysis
1% buy
Intrusion Signatures and Analysis 4.0 out of 5 stars (2)
£30.99

 

Customer Reviews

4 Reviews
5 star:
 (2)
4 star:
 (1)
3 star:    (0)
2 star:
 (1)
1 star:    (0)
 
 
 
 
 
Average Customer Review
4.0 out of 5 stars (4 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
5 of 5 people found the following review helpful:
5.0 out of 5 stars Northcutt hits the ball out of the park!, 26 Aug 1999
By A Customer
I am the chief of a 15 person intrusion detection team, with responsibility for centralized, around-the-clock monitoring of a global network. I believe I have enough experience to claim Steven's book is first rate and sorely needed. His reconstruction of a Christmas Eve system compromise and his analysis of Kevin Mitnick's TCP hijack of Tsutomu Shimomura's host are excellent case studies. His coverage of reset scans and other non-standard reconnaissance techniques prompted me to scour my traffic for the same events and write a paper on my findings. I do not agree with some of his conclusions on SYN ACK and reset scans, but his work made me investigate those topics. While I would have preferred slightly more explanation and examples of network traces (who wouldn't?), I hope this book begins a trend of sharing (sanitized) packet-level incident details within the IDS community. I recommended Steven's book to every analyst on my flight and every person in my unit, and I plan to build in-house training around it. I guarantee every person with a technical leaning and a position on the front line of intrusion detection will appreciate Steven's book. See you at SANS Network Security 99!
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
1 of 1 people found the following review helpful:
4.0 out of 5 stars Ahh, nothing like the smell of IP in the morning!, 26 April 2001
While this is a book on intrusion detection, I bought it for another reason. A friend refered me to this book when I asked him about "sniffing". The book is a great introduction to network sniffing! I give it "only" four stars because it falls short of its primary goal IDS.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
0 of 2 people found the following review helpful:
2.0 out of 5 stars Poor in in deep technical content.... not meaty enought., 9 Jan 2001
The book provide a good list and overview of most IDS tools out in the market. Unfortunatly if you are looking to go into greater detail about types of intrusion... it comes quite short in content. I found if you are looking to read this kind of subject is because you want to go in deep into the information and not very quick overview as per book.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews

5.0 out of 5 stars Excellent: The missing link in Computer Security
Whilst there are a multitude of books detailing the various computer vulnerabilities, very few give such a thorough description of how they work, more importantly in the IDS field... Read more
Published on 14 Jan 2000 by talisker@technologist.com

Only search this product's reviews



Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 

   


Listmania!


Look for similar items by category


Look for similar items by subject


Feedback

Ad

Your Recent History

 (What's this?)

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.