Intrusion Signatures and Analysis
Matt Fearnow
Stephen Northcutt
Karen Frederick
Mark Cooper

ISBN-10: 0735710635
ISBN-13: 9780735710634

Publisher: Sams Publishing
Copyright: 2001
Format: Paper; 448 pp
Published: 01/19/2001

Suggested retail price: $39.99
Buy from myPearsonStore

For advanced courses in network security.

Intrusion Signatures and Analysis is ideal for courses looking to teach students about the concepts of intrusion detection and network security. The book opens with an introduction into the format of some of the more common detection sensors and then begins a tutorial into the unique format of the signatures and analyses used in the book. After a challenging four-chapter review, the student finds page after page of signatures, in order by categories. Then the content digs right into reaction and responses covering how sometimes what you see isn't always what is happening. The book also covers how students and analysts can spend time chasing after false positives. Also included is a section on how attacks have shut down the networks and web sites of Yahoo, and E-bay and what those attacks looked like. Students will also find review questions with answers throughout the book, to be sure they comprehend the traces and material that has been covered.

  • Already in use in professional training organizations.
    • Used by the SANS Institute to train their intrusion analysts, this book is ideal for self-study, containing end of chapter review questions that cover the traces and signatures. Ex.___

  • Web extensible.
    • Companion Website component of trace and signature updates keeps the life of the book long, truly a resource students can use after the course. Ex.___

  • Written by industry experts.
    • Stephen Northcutt has served as the leader of the Department of Defenses Shadow Intrusion Detection Team for two years and was the Chief for Information Warfare at the Ballistic Missile Defense Organization. Ex.___



 1. Reading Log Formats.


 2. Introduction to the Practicals.


 3. The Ten Most Critical Internet Security Threats, Part 1.


 4. The Ten Most Critical Internet Security Threats, Part 2.


 5. Reactions and Responses.


 6. Perimeter Logs.


 7. Non-Malicious Traffic.


 8. Network Mapping.


 9. Scans that Probe Systems for Information.


10. Denial Of Service (DoS)—Resource Starvation.


11. Denial Of Service (DoS)—Bandwidth Consumption.


12. Trojans.


13. Exploits.


14. Buffer Overflows with Content.


15. Fragmentation.


16. False Positives.


17. Out of Spec Packets.

Stephen Northcutt is the author of several books including: Incident Handling Step-by-Step, Intrusion Detection: Shadow Style (both by the SANS Institute) and Network Intrusion Detection: An Analyst's Handbook (New Riders) as well as a contributing editor for Securing NT Step-by-Step (The SANS Institute.) He was the original developer of the Shadow intrusion detection system and served as the leader of the Department of Defenses Shadow Intrusion Detection Team for two years. Mr. Northcutt was the Chief for Information Warfare at the Ballistic Missile Defense Organization and currently serves as the Director for GIAC Training and Certification for the SANS Institute. Mark Cooper graduated from UMIST in 1991 with a BS in Microelectronic Systems Engineering. Currently working as a security consultant, he reached his current position after spending many years as a software engineer and then as a UNIX Systems Administrator. He is now a SANS GIAC Certified Intrusion Analyst. Matt Fearnow is a Network/ Security Administrator for Macmillan USA. Before working at Macmillan, he served in the US Navy as a Sonar Technician aboard submarines. In his current duties he constantly utilizes his SANS GIAC certification and is a frequent contributor to the SANS GIAC website. Matt was the first to establish categories for the traces from completed GIAC practicals. Karen Frederick is an Infosec Engineer for Sun Tzu Security in Milwaukee, Wisconsin. She earned her bachelor's degree in computer science from the University of Wisconsin-Parkside, and she is currently completing her master's degree thesis in intrusion detection from the University of Idaho's Engineering Outreach program. Karen holds several certifications, including Microsoft Certified Systems Engineer + Internet, Check Point Certified Security Administrator and GIAC Certified Intrusion Analyst.

Intrusion Signatures and Analysis opens with an introduction into the format of some of the more common sensors and then begins a tutorial into the unique format of the signatures and analyses used in the book. After a challenging four-chapter review, the reader finds page after page of signatures, in order by categories. Then the content digs right into reaction and responses covering how sometimes what you see isn�t always what is happening. The book also covers how analysts can spend time chasing after false positives. Also included is a section on how attacks have shut down the networks and web sites of Yahoo, and E-bay and what those attacks looked like. Readers will also find review questions with answers throughout the book, to be sure they comprehend the traces and material that has been covered.

View a Sample Chapter PDF:

Pearson Higher Education offers special pricing when you choose to package your text with other student resources. If you're interested in creating a cost-saving package for your students, contact your Pearson Higher Education representative for pricing and ordering information.

This title is a member of the Landmark, which also contains the titles below . You can also visit the Landmark page.

  • 0735700214Developing Linux Applications
    Harlow
    © 1999 | Sams Publishing | Paper; 512 pages | Instock
    ISBN-10: 0735700214 | ISBN-13: 9780735700215
    Brief Description | Buy from myPearsonStore

  • 0735700222Internet Information Services Administration
    Adam & Stevens
    © 2000 | Sams Publishing | Paper; 192 pages | Instock
    ISBN-10: 0735700222 | ISBN-13: 9780735700222
    Brief Description | Buy from myPearsonStore

  • 0735710635Intrusion Signatures and Analysis
    Fearnow, Northcutt, Frederick & Cooper
    © 2001 | Sams Publishing | Paper; 448 pages | Instock
    ISBN-10: 0735710635 | ISBN-13: 9780735710634
    Brief Description | Buy from myPearsonStore

  • 073571195XJava for the Web with Servlets, JSP, and EJB: A Developer's Guide to J2EE Solutions
    Kurniawan
    © 2002 | Sams Publishing | Paper Bound w/CD-ROM; 992 pages | Instock
    ISBN-10: 073571195X | ISBN-13: 9780735711952
    Buy from myPearsonStore

  • 0735710546MySQL and Perl for the Web
    DuBois
    © 2002 | Sams Publishing | Paper; 552 pages | Instock
    ISBN-10: 0735710546 | ISBN-13: 9780735710542
    Brief Description | Buy from myPearsonStore

  • 0735700826SMS 2 Administration
    Doshi & Lubanski
    © 2000 | Sams Publishing | Paper; 448 pages | Instock
    ISBN-10: 0735700826 | ISBN-13: 9780735700826
    Brief Description | Buy from myPearsonStore

  • 0735709777Understanding the Network
    Martin
    © 2000 | Sams Publishing | Paper; 720 pages | Instock
    ISBN-10: 0735709777 | ISBN-13: 9780735709775
    Brief Description | Buy from myPearsonStore

  • 0735710015Vi iMproved (VIM)
    Oualline
    © 2001 | Sams Publishing | Paper; 624 pages | Instock
    ISBN-10: 0735710015 | ISBN-13: 9780735710016
    Brief Description | Buy from myPearsonStore

  • 0735709971Web Application Development with PHP 4.0
    Ratschiller & Gerken
    © 2000 | Sams Publishing | Paper Bound w/CD-ROM; 416 pages | Instock
    ISBN-10: 0735709971 | ISBN-13: 9780735709973
    Brief Description | Buy from myPearsonStore

  • 0735708703Windows 2000 Active Directory
    Hauger, Wade & Brovick
    © 2000 | Sams Publishing | Paper; 416 pages | Instock
    ISBN-10: 0735708703 | ISBN-13: 9780735708709
    Brief Description | Buy from myPearsonStore

  • 0735709513Windows 2000 Routing and Remote Access Service
    Charles
    © 2000 | Sams Publishing | Paper; 400 pages | Instock
    ISBN-10: 0735709513 | ISBN-13: 9780735709515
    Brief Description | Buy from myPearsonStore

  • 1562059416Windows NT Registry
    Osborne
    © 1998 | Sams Publishing | Paper; 576 pages | Instock
    ISBN-10: 1562059416 | ISBN-13: 9781562059415
    Brief Description | Buy from myPearsonStore

  • 157870264XWriting Information Security Policies
    Barman
    © 2002 | Sams Publishing | Paper; 240 pages | Estimated Availability: 11/02/2001
    ISBN-10: 157870264X | ISBN-13: 9781578702640
    Buy from myPearsonStore

  • 0735712271XML and PHP
    Vaswani
    © 2003 | Sams Publishing | Paper; 384 pages | Instock
    ISBN-10: 0735712271 | ISBN-13: 9780735712270
    Buy from myPearsonStore

Pearson Higher Education offers special pricing when you choose to package your text with other student resources. If you're interested in creating a cost-saving package for your students contact your Pearson Higher Education representative.


Copyright ©2008 Pearson Education. All rights reserved. Legal Notice | Privacy Policy | Permissions