Showing posts with label spyware. Show all posts
Showing posts with label spyware. Show all posts

Snort 2.1 Intrusion Detection, Second Edition Review

Snort 2.1 Intrusion Detection, Second Edition
Average Reviews:

(More customer reviews)
Are you looking to buy Snort 2.1 Intrusion Detection, Second Edition? Here is the right place to find the great deals. we can offer discounts of up to 90% on Snort 2.1 Intrusion Detection, Second Edition. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Snort 2.1 Intrusion Detection, Second Edition ReviewSyngress published "Snort 2.0" in Mar 03, and I gave it a four star review in Jul 03. Excerpts from that review appear on the back cover and first page of "Snort 2.1," published only 14 months later. I still think "Snort 2.1" is overall the best Snort book available, but I was disappointed by signs of rushed production and lack of coverage of key Snort features.
The table of contents for "Snort 2.1" is deceiving, as it is almost exactly the same as "Snort 2.0." However, the new book is almost 200 pages larger than its predecessor, with many internal modifications. Chapters 1, 2, 3, 4, 9, 11, 12 and 13 are either completely new or substantially new. Chapters 5, 6, 7, 8, and 10 are either partial rewrites or have some material added or dropped. Despite all of this work, "Snort 2.1" fails to spend time on key subjects, which I will mention during a chapter-by-chapter examination of the book.
First, I recommend skipping ch 1. Aside from some general IDS advice, it is haphazard and contributes nothing to the core Snort discussion. Ch 2 is a quick overview of Snort capabilities, and should have been the lead chapter. Ch 3 describes Snort installation, but suffers apparently swapped figures (3.1 and 3.2) and a wrong figure (3.5). Ch 3 is still a nice upgrade from its counterpart in "Snort 2.0," which gave hints for deploying Snort on Red Hat Linux 8.0. The new ch 3 covers Linux, OpenBSD, and Windows.
Ch 4, "Inner Workings," is one of the reasons "Snort 2.1" has an advantage over the competition. It's tough to go wrong when Snort's developers describe the tool's operation. Still, signs of rough editing appear on p. 170 and 191, and the "-a cmg" switch should be "-A cmg".
Ch 5 covers rules, and is a big disappointment. For most users, rules are the primary means to customize Snort. Like "Snort 2.0," ch 5 fails to help readers with some of the more important new Snort rule options, like byte_test, byte_jump, distance, and within (available since 2.0.rc1 in Mar 03). Ch 5 implies on p. 145 that running Snort with -v is a good idea, despite every other recommendation in the book that verbose mode is a performance killer. Also, the IP "sec" option mentioned on p. 205 is not "IPSec" -- see RFC 791. Overall, ch 5 spends too much time restating rule information found in Snort's manual, and not enough time on features available even in Snort 2.0.
Ch 6's discussion of preprocessors is a solid chapter, with new material on Snort's flow module, http_inspect, and perfmonitor. The telnet preprocessor section is one of the better examples of a "code walkthrough," where the author shows code while explaining what it does.
Ch 7 is really showing its age. "Snort 2.0" was behind the times when it said "Unified logs are the future of Snort reporting," and "Snort 2.1" makes the same mistake. Barnyard, a means to read unified logs, was available in Sep 01! Ch 7 also misses the boat on XML output, calling it "our favorite and relatively new logging format" on p. 322. The XML plug-in spo_xml wasn't even part of snort-2.0.0, never mind snort-2.1.0. Basic research would have revealed Joe McAlerney's announcement of Silicon Defense's snort-idmef XML plug-in in Jun 01, followed by Sandro Poppi's assumption of the project in Aug 03. A mention of Barnyard's "XML formatting capabilities" appears in ch 7 on p. 322, yet Barnyard does not offer this natively.
I was happy to see Sguil addressed in ch 8, but sad to see Sguil's use of session and full content data not appreciated for its true worth. Ch 9 does a good job describing Oinkmaster and gives sound advice on avoiding the "not any" rule negation problem. Ch 10 covers really old testing tools like Sneeze, whose stateless operation cannot fool stream4's stateful inspection.
Ch 11, explaining Barnyard, is clearly the book's shining moment. This is the reason I read "Snort 2.1": Barnyard's author, Andrew Baker, describes Barnyard's history, the format of unified logs, and how best to use his contribution to Snort. Bravo. Ch 12 was also very good, using case studies to compare three different "active response" choices. Ch 13 was new but not exceptionally helpful.
I would enjoy seeing three improvements in the third edition. First, thoroughly scrub the book for old information. Watch out for people writing about "Cerebus" or http_decode or offerings from Silicon Defense, whose Web site disappeared in early 2004. Second, tell people to read the excellent Snort manual before reading the book. There's no need to address topics well-covered in the manual, like all of the IP- and TCP-based rule options. Third, ditch the existing rules chapter in favor of two new ones, one explaining principles via existing rules, and one showing advanced rule development.
I still recommend buying this book, but you might guide your reading choices by the comments in this review.Snort 2.1 Intrusion Detection, Second Edition OverviewCalled "the leader in the Snort IDS book arms race" by Richard Bejtlich, top Amazon reviewer, this brand-new edition of the best-selling Snort book covers all the latest features of a major upgrade to the product and includes a bonus DVD with Snort 2.1 and other utilities.Written by the same lead engineers of the Snort Development team, this will be the first book available on the major upgrade from Snort 2 to Snort 2.1 (in this community, major upgrades are noted by .x and not by full number upgrades as in 2.0 to 3.0). Readers will be given invaluable insight into the code base of Snort, and in depth tutorials of complex installation, configuration, and troubleshooting scenarios. Snort has three primary uses: as a straight packet sniffer, a packet logger, or as a full-blown network intrusion detection system. It can perform protocol analysis, content searching/matching and can be used to detect a variety of attacks and probes. Snort uses a flexible rules language to describe traffic that it should collect or pass, a detection engine that utilizes a modular plug-in architecture, and a real-time alerting capability. A CD containing the latest version of Snort as well as other up-to-date Open Source security utilities will accompany the book.Snort is a powerful Network Intrusion Detection System that can provide enterprise wide sensors to protect your computer assets from both internal and external attack. * Completly updated and comprehensive coverage of snort 2.1* Includes free CD with all the latest popular plug-ins* Provides step-by-step instruction for installing, configuring and troubleshooting

Want to learn more information about Snort 2.1 Intrusion Detection, Second Edition?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

PC Magazine Fighting Spyware, Viruses, and Malware Review

PC Magazine Fighting Spyware, Viruses, and Malware
Average Reviews:

(More customer reviews)
Are you looking to buy PC Magazine Fighting Spyware, Viruses, and Malware? Here is the right place to find the great deals. we can offer discounts of up to 90% on PC Magazine Fighting Spyware, Viruses, and Malware. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

PC Magazine Fighting Spyware, Viruses, and Malware ReviewTittel can certainly unsettle the reader! He warns of the increasing encroachments against your computer. The biggest single danger is that this might be your home computer. Not a computer at your workplace, for which you might be able to ask a sysadmin for help.
So it's you and Tittel against the 3 menaces. Be aware that the terminology in the text and title may vary from what others use. Often, malware is taken to include viruses. I think he chose to break viruses out separately from malware so that the title would outreach to more people. Malware is still somewhat of a techie term, while spyware and viruses have broader recognition.
Naturally, since we're discussing personal computers, the text tends to focus on those running a Microsoft operating system. But in fact, much of his advice applies to Macs and linux/unix machines. Though users of the former 2 types might take heart in knowing that most viruses or worms won't go after their machines.
Tittel explains that increasingly, it's harder to draw clear lines between malware, spyware and adware. But he shows how to use existing anti-malware products that can scan for these and remove them. These products use combinations of signatures of known malware, and also search for "strange" activity that is typical of malware. However, since new variants of malware are continually being developed and found, you should always download the latest sets of signatures from your vendor, before running the tests.
Tittel also gives a succinct description of phishing. A particularly virulent type of malware that has increased enormously in the last 2 years. He suggests that you scrutinise the links and be very wary of any message that asks for personal information; either in a reply, or in a web page pointed to from that message. Unfortunately, the phishers continue to refine their tactics and many users simply aren't savvy enough to follow Tittel's suggestions. These users may be a minority, but there are enough of them to make this worthwhile for the phishers.PC Magazine Fighting Spyware, Viruses, and Malware OverviewThink there's no malicious software on your computer? PC Magazine thinks you should think again.Scans by ISPs have revealed as many as twenty-eight spyware programs running on the average home computer--like yours. That's a lot of people prying into what's on your PC, and a DSL or cable connection is a virtual welcome mat. But by following Ed Tittel's advice, you can learn how invasions occur, spot an infestation, repair damage that's already done, and slam the door on those who want to hijack your PC--along with your wallet.Here's how you can* Learn to recognize when a Trojan horse, a virus, adware, or spyware has invaded your PC* Get the tools that can cure an infection* Dig into the Windows Registry to remove the nastiest of bugs* Prevent a recurrence with personal firewalls and protective software* Deal with the onslaught of spam* Keep your defenses up-to-dateGive it the bootIf you believe you've caught something and you're willing to kiss everything goodbye that you've added to or changed ... since the last time you booted up your computer ... try this. While Windows is first booting up, hit the F8 key .... Choose the Last Known Good Configuration option, and Windows should boot running the version of the Registry that existed the last time your system booted--that is, before you got infected.-- From Chapter 4

Want to learn more information about PC Magazine Fighting Spyware, Viruses, and Malware?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...