practice_of_network_security_monitoring.pdf

(29419 KB) Pobierz
NET WORK SECURIT Y
MONITORING
U N D E R S T A N D I N G
THE PR ACTICE OF
INCIDENT DETECTION
A N D
RESPONSE
RICHARD BEJTLICH
“An invaluable resource for anyone detecting
and responding to security breaches.”
—Kevin Mandia, FireEye President,
former Mandiant CEO
The PracTice of
NeTwork SecuriTy MoNiToriNg
The PracTice of
NeTwork SecuriTy
MoNiToriNg
understanding
incident Detection
and response
by R ich ard B ejtlich
San Francisco
The PracTice of NeTwork SecuriTy MoNiToriNg.
Copyright © 2013 by Richard Bejtlich.
All rights reserved. No part of this work may be reproduced or transmitted in any form or by any means,
electronic or mechanical, including photocopying, recording, or by any information storage or retrieval
system, without the prior written permission of the copyright owner and the publisher.
Printed in USA
First printing
17 16 15 14 13
123456789
ISBN-10: 1-59327-509-9
ISBN-13: 978-1-59327-509-9
Publisher: William Pollock
Production Editor: Serena Yang
Cover Ilustration: Tina Salameh
Developmental Editor: William Pollock
Technical Reviewers: David Bianco, Doug Burks, and Brad Shoop
Copyeditors: Marilyn Smith and Julianne Jigour
Compositor: Susan Glinert Stevens
Proofreader: Ward Webber
For information on distribution, translations, or bulk sales, please contact No Starch Press, Inc. directly:
No Starch Press, Inc.
38 Ringold Street, San Francisco, CA 94103
phone: 415.863.9900; fax: 415.863.9950; info@nostarch.com; www.nostarch.com
Library of Congress Cataloging-in-Publication Data
Bejtlich, Richard.
The practice of network security monitoring : understanding incident detection and response / by
Richard Bejtlich.
pages cm
Includes index.
ISBN-13: 978-1-59327-509-9
ISBN-10: 1-59327-509-9
1. Computer networks--Security measures. 2. Electronic countermeasures. I. Title.
TK5105.59.B436 2013
004.6--dc23
2013017966
No Starch Press and the No Starch Press logo are registered trademarks of No Starch Press, Inc. Other
product and company names mentioned herein may be the trademarks of their respective owners. Rather
than use a trademark symbol with every occurrence of a trademarked name, we are using the names only
in an editorial fashion and to the benefit of the trademark owner, with no intention of infringement of the
trademark.
The information in this book is distributed on an “As Is” basis, without warranty. While every precaution
has been taken in the preparation of this work, neither the author nor No Starch Press, Inc. shall have any
liability to any person or entity with respect to any loss or damage caused or alleged to be caused directly or
indirectly by the information contained in it.
Zgłoś jeśli naruszono regulamin