Book Review "Managing Security with Snort and IDS Tools"





"Managing Security with Snort and IDS Tools", Kerry Cox/Christopher Gerg, 2004

Kerry Cox
Christopher Gerg
2004

O'Reilly & Associates, Inc.



Chapter one explains what Snort, and network intrusion detection, is.
The basics of network traffic sniffing and analysis, and the operation
of tcpdump and ethereal, are described in chapter two. Installation,
options, and the basic operation of Snort are outlined in chapter
three. Chapter four details the different types of blackhat and
intruder activity in terms of network intrusion. Chapter five details
the confguration file and choices. How, and where, to use and set up
Snort is the topic of chapter six. Snort rules are explained in
chapter seven, which also outlines the system for creating them.
Snort can also be used for intrusion prevention, as chapter eight
points out. Tuning sensitivity, and establishing thresholds and
clipping levels, is discussed in chapter nine. Chapter ten reviews
the use of ACID (Analysis Console for Intrusion Detection) as a
management console. An alternative program is SnortCenter, described
in chapter eleven, and more options are listed in twelve. Chapter
thirteen notes possibilities for the use of Snort in high bandwidth

For those interested in the standard intrusion detection program, here
is a set of useful explanations for its use and operation.



