Managing Security with Snort & IDS Tools
By
Kerry J. Cox,
Christopher Gerg
August 2004
Pages: 288
| Table of Contents
| Index
| Sample Chapter
| Colophon
Table of Contents
-
Chapter 1 Introduction
-
Disappearing Perimeters
-
Defense-in-Depth
-
Detecting Intrusions (a Hierarchy of Approaches)
-
What Is NIDS (and What Is an Intrusion)?
-
The Challenges of Network Intrusion Detection
-
Why Snort as an NIDS?
-
Sites of Interest
-
Chapter 2 Network Traffic Analysis
-
The TCP/IP Suite of Protocols
-
Dissecting a Network Packet
-
Packet Sniffing
-
Installing tcpdump
-
tcpdump Basics
-
Examining tcpdump Output
-
Running tcpdump
-
ethereal
-
Sites of Interest
-
Chapter 3 Installing Snort
-
About Snort
-
Installing Snort
-
Command-Line Options
-
Modes of Operation
-
Chapter 4 Know Your Enemy
-
The Bad Guys
-
Anatomy of an Attack: The Five Ps
-
Denial-of-Service
-
IDS Evasion
-
Sites of Interest
-
Chapter 5 The snort.conf File
-
Network and Configuration Variables
-
Snort Decoder and Detection Engine Configuration
-
Preprocessor Configurations
-
Output Configurations
-
File Inclusions
-
Chapter 6 Deploying Snort
-
Deploy NIDS with Your Eyes Open
-
Initial Configuration
-
Sensor Placement
-
Securing the Sensor Itself
-
Using Snort More Effectively
-
Sites of Interest
-
Chapter 7 Creating and Managing Snort Rules
-
Downloading the Rules
-
The Rule Sets
-
Creating Your Own Rules
-
Rule Execution
-
Keeping Things Up-to-Date
-
Sites of Interest
-
Chapter 8 Intrusion Prevention
-
Intrusion Prevention Strategies
-
IPS Deployment Risks
-
Flexible Response with Snort
-
The Snort Inline Patch
-
Controlling Your Border
-
Sites of Interest
-
Chapter 9 Tuning and Thresholding
-
False Positives (False Alarms)
-
False Negatives (Missed Alerts)
-
Initial Configuration and Tuning
-
Pass Rules
-
Thresholding and Suppression
-
Chapter 10 Using ACID as a Snort IDS Management Console
-
Software Installation and Configuration
-
ACID Console Installation
-
Accessing the ACID Console
-
Analyzing the Captured Data
-
Sites of Interest
-
Chapter 11 Using SnortCenter as a Snort IDS Management Console
-
SnortCenter Console Installation
-
SnortCenter Agent Installation
-
SnortCenter Management Console
-
Logging In and Surveying the Layout
-
Adding Sensors to the Console
-
Managing Tasks
-
Chapter 12 Additional Tools for Snort IDS Management
-
Open Source Solutions
-
Commercial Solutions
-
Chapter 13 Strategies for High-Bandwidth Implementations of Snort
-
Barnyard (and Sguil)
-
Commericial IDS Load Balancers
-
The IDS Distribution System (I(DS)2)
-
Appendix A Snort and ACID Database Schema
-
acid_ag
-
Appendix B The Default snort.conf File
-
Appendix C Resources
-
From Chapter 1: Introduction
-
From Chapter 2: Network Traffic Analysis
-
From Chapter 4: Know Your Enemy
-
From Chapter 6: Deploying Snort
-
From Chapter 7: Creating and Managing Snort Rules
-
From Chapter 8: Intrusion Prevention
-
From Chapter 10: Using ACID as a Snort IDS Management Console
-
From Chapter 12: Additional Tools for Snort IDS Management
-
From Chapter 13: Strategies for High-Bandwidth Implementations of Snort
-
Colophon
Return to Managing Security with Snort & IDS Tools