Book description
Traditional intrusion detection and logfile analysis are no longer enough to protect today’s complex networks. In the updated second edition of this practical guide, security researcher Michael Collins shows InfoSec personnel the latest techniques and tools for collecting and analyzing network traffic datasets. You’ll understand how your network is used, and what actions are necessary to harden and defend the systems within it.
In three sections, this book examines the process of collecting and organizing data, various tools for analysis, and several different analytic scenarios and techniques. New chapters focus on active monitoring and traffic manipulation, insider threat detection, data mining, regression and machine learning, and other topics.
You’ll learn how to:
- Use sensors to collect network, service, host, and active domain data
- Work with the SiLK toolset, Python, and other tools and techniques for manipulating data you collect
- Detect unusual phenomena through exploratory data analysis (EDA), using visualization and mathematical techniques
- Analyze text data, traffic behavior, and communications mistakes
- Identify significant structures in your network with graph analysis
- Examine insider threat data and acquire threat intelligence
- Map your network and identify significant hosts within it
- Work with operations to develop defenses and analysis techniques
Publisher resources
Table of contents
- Preface
- I. Data
- 1. Organizing Data: Vantage, Domain, Action, and Validity
- 2. Vantage: Understanding Sensor Placement in Networks
- 3. Sensors in the Network Domain
- 4. Data in the Service Domain
- 5. Sensors in the Service Domain
- 6. Data and Sensors in the Host Domain
- 7. Data and Sensors in the Active Domain
- II. Tools
- 8. Getting Data in One Place
-
9. The SiLK Suite
- What Is SiLK and How Does It Work?
- Acquiring and Installing SiLK
- Choosing and Formatting Output Field Manipulation: rwcut
- Basic Field Manipulation: rwfilter
- rwfileinfo and Provenance
- Combining Information Flows: rwcount
- rwset and IP Sets
- rwuniq
- rwbag
- Advanced SiLK Facilities
- Collecting SiLK Data
- Further Reading
- 10. Reference and Lookup: Tools for Figuring Out Who Someone Is
- III. Analytics
- 11. Exploratory Data Analysis and Visualization
- 12. On Analyzing Text
- 13. On Fumbling
- 14. On Volume and Time
- 15. On Graphs
- 16. On Insider Threat
- 17. On Threat Intelligence
- 18. Application Identification
- 19. On Network Mapping
- 20. On Working with Ops
- 21. Conclusions
- Index
Product information
- Title: Network Security Through Data Analysis, 2nd Edition
- Author(s):
- Release date: September 2017
- Publisher(s): O'Reilly Media, Inc.
- ISBN: 9781491962794
You might also like
book
Network Security Through Data Analysis
In this practical guide, security researcher Michael Collins shows you several techniques and tools for collecting …
book
Network Security Strategies
Build a resilient network and prevent advanced cyber attacks and breaches Key Features Explore modern cybersecurity …
book
Network Security Assessment, 3rd Edition
How secure is your network? The best way to find out is to attack it, using …
book
Computer Network Security
Developed in collaboration with a training and certification team from Cisco, Computer Network Security is an …