Showing posts with label bejtlich. Show all posts
Showing posts with label bejtlich. Show all posts

Professional Xen Virtualization Review

Professional Xen Virtualization
Average Reviews:

(More customer reviews)
Are you looking to buy Professional Xen Virtualization? Here is the right place to find the great deals. we can offer discounts of up to 90% on Professional Xen Virtualization. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Professional Xen Virtualization ReviewI was the first person to post a review for this book, and it appeared on amazon but then it disappeared a week or so later and a 5 star review showed up... makes me wonder... At any rate this "re-review" will not be as complete as my first review.
This book is pretty low quality. The author is overly verbose for many things that are not really directly relevant. Case in point, the first 3 chapters are spent talking about virtualization in general, and then the alternative options to Xen. That would be fine if this book was titled "professional virtualization," but it is not... it is supposed to be about Xen, so why would the author waste a full 1/3 of the book telling us what else we might want to use?
The actual meat of the book, the stuff thats actually useful, is pretty much the exact same information you can get from the Xen handbook/users guide online. The author does not provide much if any further value or insight.
Finally the Author must have been hurting for a page count because the 10-15% (i had it actually calculated in my first review.. i believe it was 11%) is an appendix and command reference for Xen.
All in all, this book is not any thing worth spending money on if you are looking for a serious Xen guide. I would recommend one of the two following books over this one."Running Xen: A Hands-On Guide to the Art of Virtualization" (available 4/08)
or
"The Definitive Guide to the Xen Hypervisor" (currently available)
Professional Xen Virtualization OverviewThis book presents you with a complete foundation on the Xen technology and shows you how Xen virtualization offers faster response times for new server and service requests, a simplified system administration for multiple systems, and better availability for critical computing resources. Packed with detailed examples of Xen configuration files, system configuration files, and system-level configuration information, this book shows you why Xen virtualization is among the leading emerging technologies on the Linux platform and is being integrated into virtually every commercial distribution.

Want to learn more information about Professional Xen Virtualization?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

InfoSec Career Hacking: Sell Your Skillz, Not Your Soul Review

InfoSec Career Hacking: Sell Your Skillz, Not Your Soul
Average Reviews:

(More customer reviews)
Are you looking to buy InfoSec Career Hacking: Sell Your Skillz, Not Your Soul? Here is the right place to find the great deals. we can offer discounts of up to 90% on InfoSec Career Hacking: Sell Your Skillz, Not Your Soul. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

InfoSec Career Hacking: Sell Your Skillz, Not Your Soul ReviewI enjoyed reading this book and I kept thinking to myself, "I wished this book would have existed when I tried to break into Information Security/Information Assurance. So far I've had a pretty successful IA career and as I read each chapter of the book I realized that I basically followed almost all of the books suggestions, some by my own plans and some by accident.
This book is definitely authored by an all-star cast so I was excited to crack the seal. I liked the sections on employment opportunities and who's hiring. The brief IA overview was definitely necessary. I was also fond of the Laws of Security content. I've never thought about those laws and how true they really are.
When I get time my friend and I plan to use the Creating an Attack Lab content. It was a good collection of theory and tool descriptions.
Overall this book is a good read and even though I've been in the Information Assurance field for over 8 years now I plan to use it as a reference and to build me an attack lab ASAP.
All IA/Infosec newbies should read this....it could have saved me some stress when I was just a noob!
Mark Cavey, CISSP-ISSAP, IAM, IEM, CHS
Senior Computer Network Defense Engineer
InfoSec Career Hacking: Sell Your Skillz, Not Your Soul Overview"InfoSec Career Hacking" starts out by describing the many, different InfoSec careers available including Security Engineer, Security Analyst, Penetration Tester, Auditor, Security Administrator, Programmer, and Security Program Manager. The particular skills required by each of these jobs will be described in detail, allowing the reader to identify the most appropriate career choice for them. Next, the book describes how the reader can build his own test laboratory to further enhance his existing skills and begin to learn new skills and techniques. The authors also provide keen insight on how to develop the requisite soft skills to migrate form the hacker to corporate world.* The InfoSec job market will experience explosive growth over the next five years, and many candidates for these positions will come from thriving, hacker communities * Teaches these hackers how to build their own test networks to develop their skills to appeal to corporations and government agencies * Provides specific instructions for developing time, management, and personal skills to build a successful InfoSec career

Want to learn more information about InfoSec Career Hacking: Sell Your Skillz, Not Your Soul?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Wireshark & Ethereal Network Protocol Analyzer Toolkit (Jay Beale's Open Source Security) Review

Wireshark and Ethereal Network Protocol Analyzer Toolkit (Jay Beale's Open Source Security)
Average Reviews:

(More customer reviews)
Are you looking to buy Wireshark & Ethereal Network Protocol Analyzer Toolkit (Jay Beale's Open Source Security)? Here is the right place to find the great deals. we can offer discounts of up to 90% on Wireshark & Ethereal Network Protocol Analyzer Toolkit (Jay Beale's Open Source Security). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Wireshark & Ethereal Network Protocol Analyzer Toolkit (Jay Beale's Open Source Security) ReviewFor the most part this book is an updated version of Ethereal Packet Sniffing. The title has been changed to more accurately reflect that it's about using Wireshark and not so much about analyzing traffic (although that's covered some), and also to denote that the project changed the name of the software recently. That said, it's an improvement over Ethereal Packet Sniffing with some new material and some reorganization.
Chapter 1 is an intro to network analysis, specifically with packet sniffing. It's very cursory, and they could do a better job of teaching this subject, but honestly that's a whole book unto itself and years of practice. The chapter is reasonably comprehensive and accurate.
Chapter 2 introduces Wireshark and how to begin using it. This chapter is very short given what it says it will cover, but most of that is brought up in the following chapters. There's a brief bit about Wireshark security, but again it's too cursory (2 paragraphs for a program that ha sa constant stream of security issues). Also, the authors keep calling it Etehreal in places and Wireshark in others. This inconsistency doesn't instill a great amount of trust in me that everything was reviewed well.
Chapter 3 covers getting and installing Wireshark for Windows, Linux, OS X, and how to build it from source. It also covers packet capture drivers (ie on Windows). A very straightforward, direct chapter.
Using Wireshark is the next chapter, and this is where we start the meat of the book. It's about 80 pages long and covers the UI and the command line options. The screen captures are better than the previous version of the book (and they often times use just a portion of the screen), but they could still be improved for legibility and for usefulness. This chapter covers the uncommon graphing and stats sections, and also following streams.
Filters are covered in Chapter 5, and the PCAP and Wireshark filter languages are covered. These are rich languages that allow for complex selectivity, and the chapter is clear and pretty comprehensive.
A new topic is introduced in Chapter 6, specifically wireless sniffing. This is a good addition to the book, and even topics such as decoding EAP and WEP are covered. This is a good, concise overview of the topic of sniffing wireless networks.
Real world packet captures are covered in Chapter 7, which is sadly too short (it could easily be a whole book). Several representative traces are included on the CD ROM that are good to study and review in this chapter. They include Linux worms and Windows malware, and also some coverage of active response packets is given.
Just like the corresponding chapter in Ethereal Packet Sniffing, Chapter 8 covers developing plugins for Wireshark, specifically new protocol decodes. Because Wireshark has a framework to extend, it supports dozens of application and network layer protocols. You can add your favorite new protocol with ease if you follow this chapter. Who knows, you may even get it included. This is a real gem of the book.
Finally, Chapter 9 covers many of the auxiliary programs that are included with Wireshark. These programs let you manage packet traces and marge them or cut them down to size. These are useful even outside of Wireshark if you work with packet traces at all.
This book is a good update to the Ethereal Packet Sniffing book and material. Sadly, in many places the editors didn't do a good job of auditing the book, so there are some mistakes and sometimes even references to the now obsolete name of Ethereal. However, the additions and improvements over the older version make this book worthwhile for anyone who needs to learn how to fully utilize this powerful sniffer.Wireshark & Ethereal Network Protocol Analyzer Toolkit (Jay Beale's Open Source Security) OverviewEthereal is the #2 most popular open source security tool used by system administrators and security professionals. This all new book builds on the success of Syngress' best-selling book Ethereal Packet Sniffing.This book provides complete information and step-by-step Instructions for analyzing protocols and network traffic on Windows, Unix or Mac OS X networks. First, readers will learn about the types of sniffers available today and see the benefits of using Ethereal. Readers will then learn to install Ethereal in multiple environments including Windows, Unix and Mac OS X as well as building Ethereal from source and will also be guided through Ethereal's graphical user interface. The following sections will teach readers to use command-line options of Ethereal as well as using Tethereal to capture live packets from the wire or to read saved capture files. This section also details how to import and export files between Ethereal and WinDump, Snort, Snoop, Microsoft Network Monitor, and EtherPeek. The book then teaches the reader to master advanced tasks such as creating sub-trees, displaying bitfields in a graphical view, tracking requests and reply packet pairs as well as exclusive coverage of MATE, Ethereal's brand new configurable upper level analysis engine. The final section to the book teaches readers to enable Ethereal to read new Data sources, program their own protocol dissectors, and to create and customize Ethereal reports.Ethereal is the #2 most popular open source security tool, according to a recent study conducted by insecure.orgSyngress' first Ethereal book has consistently been one of the best selling security books for the past 2 yearsThe companion Web site for the book provides readers with dozens of open source security tools and working scripts

Want to learn more information about Wireshark & Ethereal Network Protocol Analyzer Toolkit (Jay Beale's Open Source Security)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Practical Intrusion Analysis: Prevention and Detection for the Twenty-First Century Review

Practical Intrusion Analysis: Prevention and Detection for the Twenty-First Century
Average Reviews:

(More customer reviews)
Are you looking to buy Practical Intrusion Analysis: Prevention and Detection for the Twenty-First Century? Here is the right place to find the great deals. we can offer discounts of up to 90% on Practical Intrusion Analysis: Prevention and Detection for the Twenty-First Century. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Practical Intrusion Analysis: Prevention and Detection for the Twenty-First Century ReviewI must start this review by stating the lead author lists me in the Acknowledgments and elsewhere in the book, which I appreciate. I also did consulting work years ago for the lead author's company, and I know the lead author to be a good guy with a unique eye for applying geography to network security data. Addison-Wesley provided me a review copy.
I did not participate in the writing process for Practical Intrusion Analysis (PIA), but after reading it I think I know how it unfolded. The lead author had enough material to write his two main sections: ch 10, Geospatial Intrusion Detection, and ch 11, Visual Data Communications. He realized he couldn't publish a 115-page book, so he enlisted five contributing authors who wrote chapters on loosely related security topics. Finally the lead author wrote two introductory sections: ch 1, Network Overview, and ch 2, Infrastructure Monitoring. This publication-by-amalgamation method seldom yields coherent or helpful material, despite the superior production efforts of a company like Addison-Wesley. To put a point on PIA's trouble, there's only a single intrusion analyzed in the book, and it's in the lead author's core section. The end result is a book you can skip, although it would be good for chapters 4 and 10 to be published separately as digital "Short Cuts" on InformIT.
Chapters 1 and 2 are not needed. Anyone who needs to learn about networking can read a basic book already published. Ch 2 does mention that 802.1AE (if ever implemented) will hamper network traffic inspection, but you could read that online.
Ch 3 is odd because it begins by mentioning well-worn methods to evade network detection, followed by a discussion of the merits of Snort vs Bro. Someone who had to read the material in chapters 1 and 2 is not going to understand the Snort discussion, especially when it mentions byte_test, depth, regex, http_inspect, uricontent, Structured Exception Handlers, and 16 line Snort signatures. I liked seeing Bro mentioned, but the people who are going to be able to follow the sample Bro policy scripts on pages 75-78 are not the ones reading this book.
Ch 4 outlines several examples of writing signatures for Snort. This section is actually interesting, but you have to know Snort and certain advanced topics pretty well to get value from this section. Readers need to compensate for the far-too-small screenshots and lack of supporting details while reading the examples. Readers also need to figure out what the author is doing, such as when he sets up a client-side exploit against FlashGet by starting a malicious FTP server with flashget-overflow.pl. By the second example he's dropping warnings like "Had Core's advisory told you from where the size of the call to memcpy was coming, you might have to refine the signature to check for the appropriate behavior; unfortunately, the disassembly left out that argument:" [cue the ASM]. The bottom line with this chapter is this: know your audience, and write for them -- not your buddies. People who can follow contributions like this "at line speed" aren't going to read this book.
By ch 5 the "practical" aspect of this book has been left behind, with a discussion of "proactive intrusion prevention and response via attack graphs, which is really an academically-derived discussion of "topological vulnerability analysis." No one does this in the operational world, and no one will. Pages 143-144 talk about IDMEF, even though that specification died years ago. (There is still an independently-maintained -- as of Feb 09 -- Snort-IDMEF plugin. I don't know anyone in industry using it.)
Ch 6 is a generic overview of using network flows. The only new material is less than a page on IPFIX, which is just a table comparing that newer format with NetFlow. Ch 7 is called "Web Application Firewalls," but it's just an overview. Read Ivan Ristic's Apache Security or Ryan Barnett's Preventing Web Attacks with Apache if you want to know this topic. Ch 7 is titled "Wireless IDS/IPS," which is an even shallower overview than the previous topic. In none of these chapters do we have anything practical nor any intrusions analyzed. Ch 9 discusses physical security, but I didn't think it fit with the intended theme for the book.
I thought chapter 10 was interesting. Geospatial and visualization techniques do have a role in many operations, and ch 10 had the only example of an intrusion analysis. Unfortunately I don't think readers could take ch 10 and implement their own operational system. Ch 11 seemed irrelevant in light of the excellent visualization books by Raffy Marty and Greg Conti.
The book finishes with ch 12, Return on Investment: Business Justification. It was totally unnecessary: cite some regulations, list some breach costs, then compare ROI, NPV, and IRR. Talk a little about MSSPs and cyber liability insurance, then end. If you really want the best discussion of security costs, read Managing Cybersecurity Resources by Gordon and Loeb.
The subtitle for PIA is "Prevention and Detection for the Twenty-First Century." Readers will not find that in PIA. The lead author started with a kernel of a good idea, but the end result does not deliver enough real value to to readers. The lead author's material, and the chapter on Snort signature writing, could have been published as digital Short Cuts, or including in a compendium of chapters in a "survey" book. If you want to read a book intrusion analysis, you're more likely to be satisfied reading a book on intrusion forensics.Practical Intrusion Analysis: Prevention and Detection for the Twenty-First Century Overview"Practical Intrusion Analysis provides a solid fundamental overview of the art and science of intrusion analysis." –Nate Miller, Cofounder, Stratum SecurityThe Only Definitive Guide to New State-of-the-Art Techniques in Intrusion Detection and PreventionRecently, powerful innovations in intrusion detection and prevention have evolved in response to emerging threats and changing business environments. However, security practitioners have found little reliable, usable information about these new IDS/IPS technologies. In Practical Intrusion Analysis, one of the field's leading experts brings together these innovations for the first time and demonstrates how they can be used to analyze attacks, mitigate damage, and track attackers. Ryan Trost reviews the fundamental techniques and business drivers of intrusion detection and prevention by analyzing today's new vulnerabilities and attack vectors. Next, he presents complete explanations of powerful new IDS/IPS methodologies based on Network Behavioral Analysis (NBA), data visualization, geospatial analysis, and more.Writing for security practitioners and managers at all experience levels, Trost introduces new solutions for virtually every environment. Coverage includesAssessing the strengths and limitations of mainstream monitoring tools and IDS technologies

Want to learn more information about Practical Intrusion Analysis: Prevention and Detection for the Twenty-First Century?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Security Log Management: Identifying Patterns in the Chaos Review

Security Log Management: Identifying Patterns in the Chaos
Average Reviews:

(More customer reviews)
Are you looking to buy Security Log Management: Identifying Patterns in the Chaos? Here is the right place to find the great deals. we can offer discounts of up to 90% on Security Log Management: Identifying Patterns in the Chaos. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Security Log Management: Identifying Patterns in the Chaos ReviewWhen I received a review copy of Security Log Management (SLM) last month, I was eager to read it. I saw two very powerful but seldom discussed tools -- Argus and Bro -- mentioned in the table of contents. This indicated some original thinking, which I appreciate. Unfortunately, SLM did not live up to my expectations. When you strip out the pages of scripts and code and the three reprinted chapters, you're left with a series of examples of output from the author's deployment of several tools. Aside from a few examples mentioned in this review, I don't think readers will learn much from SLM.
The first problem with SLM is a lack of competent editing. Prior to publication, someone should have read the book from the reader's perspective, asking "what is the reader expected to learn from this section/chapter/book?" In other words, the editor should have asked "how is the reader supposed to implement these recommendations?" For example, Ch 2 mentions using the Bro IDS. Nothing about setting up Bro is included, which would be acceptable if a reference to an online guide or another book was given. That is not the case; the author just assumes readers know about Bro and have it running. The number of Bro users is probably less than 100. If you're one of them, you don't need to read this book!
Bro's DNS and SMTP logging modules are casually demonstrated with no regard for showing the reader how to deploy them. The Web module at least shows a sample mt.bro file, if the reader can figure out what that is or how it fits into the picture. The situation gets worse on p 101 when the author says "the SMTP module can be very powerful in helping to identify several of the 'Marcus Ranum' top mail-related statistics (Chapter 1)." Marcus Ranum is not mentioned at all in Ch 1.
SLM demonstrates two other features that are becoming increasingly common and frustrating in Syngress books, for which I detracted stars from the review. First, the editing is rough. I am perplexed by the inability to standardize on references to tools; e.g., is it bro, Bro, or BRO? Second, and far more worrisome, the last three chapters (7, 8, and 9) of SLM are reprints of chapters 6, 7, and 5 from the Feb 2005 Syngress book Microsoft Log Parser Toolkit. On the positive side, SLM did not have as many fuzzy screen shots as sometimes appear in recent Syngress books. The unexplained small, fuzzy, NetForensics screen shot on p 31 is one unwelcome exception.
In terms of stating a clear purpose and delivering material in a coherent manner, the best chapter in SLM is Ch 6 -- Scalable Enterprise Solutions. I thought the author of this chapter stated his purpose, and then delivered material that readers could use. My only problem with the chapter was reading the definition of ESM 5 times -- on pp 195, 196, 205, 237, and 238!
My favorite part of SLM was the material showing how to put Argus records into a MySQL database. This is not that common, so I was glad to see how the author implements that function.
I'm sorry I can't recommend reading SLM in its current form. Three stars means there is some value, but you could get what you need browsing in the book store. I would like to see a second edition of SLM cut out the reprinted chapters. That cuts the book down to 241 pages. If the 70 or so pages of code are moved online, that reduces the book to 171 pages. That leaves plenty of room to add material that meets readers' needs. An example of a very strong Syngress book on a related (host-based) topic is Host Integrity Monitoring Using Osiris and Samhain by Brian Wotring.Security Log Management: Identifying Patterns in the Chaos OverviewThis book teaches IT professionals how to analyze, manage, and automate their security log files to generate useful, repeatable information that can be use to make their networks more efficient and secure using primarily open source tools. The book begins by discussing the "Top 10" security logs that every IT professional should be regularly analyzing. These 10 logs cover everything from the top workstations sending/receiving data through a firewall to the top targets of IDS alerts. The book then goes on to discuss the relevancy of all of this information. Next, the book describes how to script open source reporting tools like Tcpdstats to automatically correlate log files from the various network devices to the "Top 10" list. By doing so, the IT professional is instantly made aware of any critical vulnerabilities or serious degradation of network performance. All of the scripts presented within the book will be available for download from the Syngress Solutions Web site.Almost every operating system, firewall, router, switch, intrusion detection system, mail server, Web server, and database produces some type of "log file." This is true of both open source tools and commercial software and hardware from every IT manufacturer. Each of these logs is reviewed and analyzed by a system administrator or security professional responsible for that particular piece of hardware or software. As a result, almost everyone involved in the IT industry works with log files in some capacity.* Provides turn-key, inexpensive, open source solutions for system administrators to analyze and evaluate the overall performance and security of their network* Dozens of working scripts and tools presented throughout the book are available for download from Syngress Solutions Web site. * Will save system administrators countless hours by scripting and automating the most common to the most complex log analysis tasks

Want to learn more information about Security Log Management: Identifying Patterns in the Chaos?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

SQL Injection Attacks and Defense Review

SQL Injection Attacks and Defense
Average Reviews:

(More customer reviews)
Are you looking to buy SQL Injection Attacks and Defense? Here is the right place to find the great deals. we can offer discounts of up to 90% on SQL Injection Attacks and Defense. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

SQL Injection Attacks and Defense ReviewI'm giving "SQL Injection Attacks and Defenses" five stars for a few reasons.
First, the book is extremely comprehensive, covering everything from basic "What is SQL Injection?" information to advanced exploit development and static analysis tools (including open source tools).
Second, this book was obviously written very recently. The content is fresh and cutting-edge.
Finally, the book is advanced. Though the reader doesn't necessarily need to know much about SQL Injection in order to start reading it, the book covers as much as anyone would need to know about the subject.
SQL Injection Attacks and Defenses is a well written, comprehensive book that can be extremely useful to security professionals, developers, and database administrators interested in writing or maintaining secure code. It could easily be called the "bible" of SQL Injection.SQL Injection Attacks and Defense Overview
Winner of the Best Book Bejtlich Read in 2009 award!

"SQL injection is probably the number one problem for any server-side application, and this book is unequaled in its coverage." Richard Bejtlich, http://taosecurity.blogspot.com/

SQL injection represents one of the most dangerous and well-known, yet misunderstood, security vulnerabilities on the Internet, largely because there is no central repository of information to turn to for help. This is the only book devoted exclusively to this long-established but recently growing threat. It includes all the currently known information about these attacks and significant insight from its contributing team of SQL injection experts.

What is SQL injection?-Understand what it is and how it works
Find, confirm, and automate SQL injection discovery
Discover tips and tricks for finding SQL injection within the code
Create exploits using SQL injection
Design to avoid the dangers of these attacks

Want to learn more information about SQL Injection Attacks and Defense?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Security Metrics: Replacing Fear, Uncertainty, and Doubt Review

Security Metrics: Replacing Fear, Uncertainty, and Doubt
Average Reviews:

(More customer reviews)
Are you looking to buy Security Metrics: Replacing Fear, Uncertainty, and Doubt? Here is the right place to find the great deals. we can offer discounts of up to 90% on Security Metrics: Replacing Fear, Uncertainty, and Doubt. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Security Metrics: Replacing Fear, Uncertainty, and Doubt ReviewI read Security Metrics right after finishing Managing Cybersecurity Resources, a book by economists arguing that security decisions should be made using cost-benefit analysis. On the face of it, cost-benefit analysis makes perfect sense, especially given the authors' analysis. However, Security Metrics author Andy Jaquith quickly demolishes that approach (confirming the problem I had with the MCR plan). While attacking the implementation (but not the idea) of Annual Loss Expectancy for security events, Jaquith writes on p 33 "[P]ractitioners of ALE suffer from a near-complete inability to reliably estimate probabilities [of occurrence] or losses." Bingo, game over for ALE and cost-benefit analysis. It turns out the reason security managers "herd" (as mentioned in MCR) is that they have no clue what else to do; they seek safety in numbers by emulating peers and then claim that as a defense when they are breached.
Fortunately, Security Metrics offers another solution. The book gives readers three sets of information: theory, metrics, and tools (concepts, not programs). The theory chapters (1 and 2) were so concise yet insightful I was tempted to underline every sentence. (I am not kidding.) Even the Preface made me glad to be reading the book when it associated "security ROI" with "the Macarena" and called it a "needless distraction." I laughed in agreement when I saw Andy call "security enablement" the "Abominable Snowman: it is rarely spotted, but legions of people swear it exists. After all, as my friend Dan geer puts it, 'You don't usually see airlines advertising how their planes fall out of the sky less often than their competitors.'" Why is that? My answer is simple: security is assumed and expected. Advertising anything else has no effect or makes people suspicious. I knew this book would be good.
The metrics chapters probably list hundreds of metrics you can extract verbatim and apply to your own environment. To the reviewer who wanted to reprint them in an appendix: they're called chapters 3 and 4. My main concern with the metrics was the focus on input-centric measurements instead of results. I would have liked to read more metrics on measuring whether security programs are working, rather than what techniques and tools are applied up front.
The tools chapters were helpful to anyone needing a statistics refresher. The visualization sections were especially helpful. (Feel free to dismiss yet another ignorant review from WB, who thinks a "review" means writing a few paragraphs after flipping through the pages of five books a day.) Andy's examples of turning lousy graphs and charts into information visualization vehicles should be followed by all managers.
Security Metrics is strengthened by the many stories from the author's consulting experience. I sensed that his techniques work and are not the product of the thought laboratory alone. I found his "Balanced Scorecard" approach to be interesting, especially to the degree it ties real metrics to business operations.
I had a few issues with terminology, such as using the term "threats" on p 231 when "attacks" is more accurate. (The football analogy is correct, however.) I semi-agreed with the author's suggestion to abandon "risk management" in favor of metrics-based approaches, but I didn't think two pages (4-5) were really enough to make the case. On p 264, threats are not risks, but they help instantiate risks. On pp 78-7, "risk of exploit" should be "ease of exploitation."
These are minor concerns, given the overwhelming concentration of practical and implementation-worthy pieces of information in Security Metrics. You must read this book if you care to measure security progress. Now we need Dan Geer to extend beyond writing wise forewords and articles into the world of his own book!Security Metrics: Replacing Fear, Uncertainty, and Doubt OverviewThe Definitive Guide to Quantifying, Classifying, and Measuring Enterprise IT Security Operations


Security Metrics is the first comprehensive best-practice guide to defining, creating, and utilizing security metrics in the enterprise.

Usingsample charts, graphics, case studies, and war stories, Yankee GroupSecurity Expert Andrew Jaquith demonstrates exactly how to establisheffective metrics based on your organization's unique requirements.You'll discover how to quantify hard-to-measure security activities,compile and analyze all relevant data, identify strengths andweaknesses, set cost-effective priorities for improvement, and craftcompelling messages for senior management.

Security Metrics successfullybridges management's quantitative viewpoint with the nuts-and-boltsapproach typically taken by security professionals. It brings togetherexpert solutions drawn from Jaquith's extensive consulting work in thesoftware, aerospace, and financial services industries, including newmetrics presented nowhere else. You'll learn how to:

• Replace nonstop crisis response with a systematic approach to security improvement
• Understand the differences between "good" and "bad" metrics
•Measure coverage and control, vulnerability management, passwordquality, patch latency, benchmark scoring, and business-adjusted risk
• Quantify the effectiveness of security acquisition, implementation, and other program activities
• Organize, aggregate, and analyze your data to bring out key insights
• Use visualization to understand and communicate security issues more clearly
• Capture valuable data from firewalls and antivirus logs, third-party auditor reports, and other resources
• Implement balanced scorecards that present compact, holistic views of organizational security effectiveness

Whetheryou're an engineer or consultant responsible for security and reportingto management–or an executive who needs better information fordecision-making–Security Metrics is the resource you have been searching for.

Andrew Jaquith, programmanager for Yankee Group's Security Solutions and Services DecisionService, advises enterprise clients on prioritizing and managingsecurity resources. He also helps security vendors develop product,service, and go-to-market strategies for reaching enterprise customers.He co-founded @stake, Inc., a security consulting pioneer acquired bySymantec Corporation in 2004. His application security and metricsresearch has been featured in CIO, CSO, InformationWeek, IEEE Security and Privacy, and The Economist.

Foreword
Preface
Acknowledgments
About the Author
Chapter1 Introduction:Escaping the Hamster Wheel ofPain
Chapter2 Defining SecurityMetrics
Chapter 3 Diagnosing Problems and Measuring Technical Security
Chapter4 Measuring ProgramEffectiveness
Chapter 5 Analysis Techniques
Chapter 6 Visualization
Chapter 7 Automating Metrics Calculations
Chapter 8 Designing Security Scorecards
Index




Want to learn more information about Security Metrics: Replacing Fear, Uncertainty, and Doubt?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

The Book of Xen: A Practical Guide for the System Administrator Review

The Book of Xen: A Practical Guide for the System Administrator
Average Reviews:

(More customer reviews)
Are you looking to buy The Book of Xen: A Practical Guide for the System Administrator? Here is the right place to find the great deals. we can offer discounts of up to 90% on The Book of Xen: A Practical Guide for the System Administrator. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

The Book of Xen: A Practical Guide for the System Administrator ReviewI've read this book as well, and I can say I absolutely LOVE it. I'm not sure if I agree with the other reviewer's analysis of the book, it seems like he comes from a non-technical background and prefers to want to know all the reasoning behind certain ways to do a proper Xen setup. I've been using Xen for the last 1.5 years and I can say this book is absolutely essential for anyone using Xen on 2 or more computers. I own a mini cloud with my own miniature cluster of Xen instances (roughly 60 virtual machines), and it's hard to get things right if you're unfamiliar with all the tools that Xen offers. For example, "The Book of Xen" makes it easy and straightforward for doing backups using LVM, with everything down to the exact command needed to run at the prompt.
It also has a great chapter on running Xen on alternative operating systems like Solaris. It took me about 10 hours of searching through tutorials on the net to figure out how to get Solaris to properly install on a Xen instance. I'm using OpenSolaris on Xen for my personal home backups so that they can run on the popular ZFS filesystem using raidz. The tutorials on the internet are mostly wrong and incomplete, but the step by step instructions in the book made it quite easy.
I also loved the chapter on Xen migration, something I've been doing pretty poorly and haphazardly using various scripts of my own. Although I'm pretty confident at the Linux command line, there are a few things I didn't know about how to run a proper Xen migration. I especially liked the section about live migration -- most of my friends running Xen on their colocated servers don't know this subject well and could probably learn a thing or two by reading this chapter.
There's also a cool chapter on running Windows XP on Xen. I've been trying to get multiple XP instances running under my Xen infrastructure so that I could run my Selenium integration test suite under a native IE8 web browser, but so far it has been really hard. I'm really happy the book distills the painful parts of the set up process in just one chapter.
Most of the time Xen "just works", but I'm glad the book has a good chapter on troubleshooting Xen issues. I've run into a bunch of these issues when trying to boot my OpenSolaris instance under Xen and without the book's troubleshooting recommendations, I probably would have been stuck for hours on the problem.
This book is great for anyone who just wants to get things done, it's not a book to learn about the internals of Xen. I'd recommend Mr R. Kolodziej to buy a book about basic Linux system administration before reading "The Book of Xen". Anyone installing xen-tools on Debian will probably know what their doing and will be the perfect reader for this book. If you don't know Linux well enough, I would recommend reading Mr Nemeth's well regarded "Linux Administration Handbook" before reading this one.The Book of Xen: A Practical Guide for the System Administrator Overview
Xen, the open source virtualization tool, is a system administrator's dream. Xen is a free, high-performance virtual machine monitor that lets you consolidate your hardware and finally put those unused cycles to use—without sacrificing reliability, performance, or scalability.

The Book of Xen explains everything you need to know in order to use Xen effectively, including installation, networking, memory management, and virtualized storage. You'll also learn how to use Xen and standard Linux tools to take snapshot backups, perform QoS operations on network traffic, and limit over-aggressive disk users.

Authors Chris Takemura and Luke S. Crawford show you how to:

Provide virtual hosting for dozens of users, each with their own individual needs
Install and manage multiple guests, including various flavors of Linux, NetBSD, Solaris, and Windows
Choose the right virtual storage options for your needs
Migrate your systems seamlessly and create new images
Tune and benchmark your systems to make them as fast as possible
Troubleshoot Xen's most common problems like network and memory management

Expert advice is priceless when it comes to running a complicated open source virtualization technology like Xen. You'll get the advice you need in The Book of Xen.


Want to learn more information about The Book of Xen: A Practical Guide for the System Administrator?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...