VERY VERY HIGHLY RECOMMENDED!!
Reviewed by
an Amazon user,
November 20, 2007
Do you have any familiarity with TCP/IP networking concepts and Linux system administration? If you do, then this book is for you. Author Michael Rash, has done an outstanding job of writing a book that concentrates on network attacks--detecting them and responding to them.
Rash, begins with an introduction to packet filtering with iptables, including kernal build specifics and iptables administration. Then, the author shows the types of attacks that exist in the network layer and what you can do about them. Next, he illustrates classes of application layer attacks that iptables can be made to detect, and introduces you to the iptables string match extension. The author also discusses installation and configuration of psad, and shows you why it is important to listen to the stories that iptables logs have to tell. He continues by introducing you to advanced psad functionality, including integrated passive OS fingerprinting, Snort signature detection via packet headers, verbose status information, and Dshield reporting. Then, the author discusses the culmination of the attack detection and mitigation strategies that are possible with iptables. Next, he compares and contrasts two passive authorization mechanisms: port knocking and SPA. The author continues by showing you how to install and make use of fwknop together with iptables to maintain a default-drop stance against all unauthenicated and unauthorized attempts to connect to your SSH daemon. Finally, the author wraps up with some graphical representations of iptables log data.
This most excellent book takes on a highly applied approach. In other words, after reading this book, you will be armed with a strong working knowledge of how network attacks are detected and dealth with via iptables.
|
A bit techy but good book
Reviewed by
an Amazon user,
November 2, 2007
|
Ready to Increase Your Personal Computing Security at LOW Cost?
Reviewed by
an Amazon user,
November 1, 2007
If so, this gem will walk you through the process of implementing three low-footprint applications which will create an additional ring of security, decreasing an attackers chances of penetrating through your online connection.
Although this is written for network security professionals, the average linux user can take this information and apply it to their desktop. (Ubuntu, Debian, Redhat, Gentoo, Suse, etc.) The book is full of information, examples, and testing procedures.
If you are looking to build a personal security "toolbox" for linux, then I recommend you consider this book. And for those of you that use ulog with iptables, don't forget to modify ULOG_DATA_FILE to /var/log/ulog/syslogemu.log.
|
A great book
Reviewed by
an Amazon user,
October 15, 2007
I have been looking forward to getting this book into my hands, since the other projects Michael Rash has led so far look quite impressive to me. Looking at his website [...], I discovered Single Packet Authorization (SPA) with Fwknop, and therefore put port-knocking aside, to give us a more secure and more reliable solution to access services such as SSH. He covers this point (SPA), and talks about psad and fwsnort as well to show how to enhance security and understand attacks using the famous iptables project from Netfilter.
It is not a cook book to build iptables rules from scratch, and make something quite static, this book gives you the ablilities to create something dynamic, strong, and help you to monitor instrusions since the outside does not lack of imagination.
Along this book, we follow a logic which leads us through the OSI reference model layers and M. Rash's projects to help us to harden our security system. I have been surprised on how everything is well-explained, and well-documented. Thus, this book provides us with technical explanations and references, code snippets, attack descriptions, and useful links on related topics. You will find in this book the answer on how to use active responses to attacks, how to gather data and get a visual representation of an attack..., as a matter of fact, everything you need or wanted to know.
That's a great book.
F. Joncourt
Hardware/Software Engineer
|
An obligatory reference for everyone involved with firewalls.
Reviewed by
an Amazon user,
October 8, 2007
Es uno de los mejores libros escritos en este tema que todo profesional en seguridad debería leer y una referencia obligatoria para todo aquel involucrado con los cortafuegos.
Describe el Quien, Como y Cuando se deben de mitigar los principales problemas asociados con la seguridad en el anfitrión. Cuando la ejecución de esfuerzos en las capas bajas del modelo OSI han sido rebasadas el uso de herramientas como psad, fwsnort e iptables nos dan un recurso simple, poderoso y efectivo en costos para asegurar un servicio crítico y fortalecer un anfitrión expuesto a las inclemencias de un ambiente cada vez más hostil.
Este libro es diferente a otros que hablan del mismo tema en su esfuerzo didáctico con ejemplos claros y apegados a los vectores de ataque comunes que uno debe de enfrentar cada día si se está inmerso en el campo de la seguridad informática.
Carlos A. Ayala
Oficial de Seguridad de la Información
Grupo Profuturo GNP
This is one of the best books in its subject that every security practitioner should read and obligatory reference for everyone involved with firewalls.
Describe the Who, How and When of the way in which the main issues related with host security should be mitigated.
When the execution of efforts in the lower layers of the OSI model has been exceeded the use of tools like psad, fwsnort and iptables give us a simple, powerful and cost effective resource to secure a critical service and harden a host exposed to the harshness of an environment every time more hostile.
This book is different to others who speak about the same subject in its didactic effort with clear examples and real life vector attacks that everyone immersed in the information security field must face every single day.
Carlos A. Ayala
Information Security Officer
Profuturo GNP Group
|