A HANDS-ON GUIDE EXPLORING OSSEC HIDS FOR OPERATIONAL AND SECURITY
AWARENESS
KEY FEATURES
* Learn something new in an Instant! A short, fast, focused guide
delivering immediate results.
* Install, configure, and customize an OSSEC-HIDS for your
environment
* Manage your OSSEC-HIDS robust and comprehensive security checks
* Write your own rules and decoders to enhance alert accuracy and
expand operational and security intelligence
BOOK DESCRIPTION
Security software is often expensive, restricting, burdensome, and
noisy. OSSEC-HIDS was designed to avoid getting in your way and to
allow you to take control of and extract real value from industry
security requirements. OSSEC-HIDS is a comprehensive, robust solution
to many common security problems faced in organizations of all sizes.
"Instant OSSEC-HIDS" is a practical guide to take you from beginner to
power user through recipes designed based on real- world experiences.
Recipes are designed to provide instant impact while containing enough
detail to allow the reader to further explore the possibilities. Using
real world examples, this book will take you from installing a simple,
local OSSEC-HIDS service to commanding a network of servers running
OSSEC-HIDS with customized checks, alerts, and automatic responses.
You will learn how to maximise the accuracy, effectiveness, and
performance of OSSEC-HIDS' analyser, file integrity monitor, and
malware detection module. You will flip the table on security software
and put OSSEC-HIDS to work validating its own alerts before escalating
them. You will also learn how to write your own rules, decoders, and
active responses. You will rest easy knowing your servers can protect
themselves from most attacks while being intelligent enough to notify
you when they need help! You will learn how to use OSSEC-HIDS to save
time, meet security requirements, provide insight into your network,
and protect your assets.
WHAT YOU WILL LEARN
* Installing OSSEC-HIDS in local, server, and agent mode
* Customizing alerting to increase the signal to noise ratio
* Writing your own rules to extend, enhance, and tailor alerts to
your environment
* Writing your own decoders to add context to alerts and active
responses
* Learning tips for managing large OSSEC-HIDS installs
* Monitoring command output for security and operational awareness
* Auditing systems for compromise with a sensitivity to performance
of those systems
* Configuring Active Response to protect servers from SSH brute force
attacks
WHO THIS BOOK IS FOR
This book is great for anyone concerned about the security of their
servers-whether you are a system administrator, programmer, or
security analyst, this book will provide you with tips to better
utilize OSSEC-HIDS. Whether you're new to OSSEC-HIDS or a seasoned
veteran, you'll find something in this book you can apply today! This
book assumes some knowledge of basic security concepts and rudimentary
scripting experience.
Les mer
Produktdetaljer
ISBN
9781782167655
Publisert
2013
Utgave
1. utgave
Utgiver
Packt Publishing
Språk
Product language
Engelsk
Format
Product format
Digital bok
Antall sider
62
Forfatter