Cargando…

Security Log Management : Identifying Patterns in the Chaos.

This book teaches IT professionals how to analyze, manage, and automate their security log files to generate useful, repeatable information that can be used to make their networks more efficient and secure using primarily open source tools. The book begins by discussing the Top 10 security logs that...

Descripción completa

Detalles Bibliográficos
Clasificación:Libro Electrónico
Formato: Electrónico eBook
Idioma:Inglés
Publicado: Elsevier Science & Technology 2006.
Temas:
Acceso en línea:Texto completo

MARC

LEADER 00000cam a2200000M 4500
001 EBOOKCENTRAL_ocn823108160
003 OCoLC
005 20240329122006.0
006 m o d
007 cr un|---uuuuu
008 121125s2006 xx o 000 0 eng d
040 |a IDEBK  |b eng  |e pn  |c IDEBK  |d OCLCQ  |d EBLCP  |d OCLCQ  |d MERUC  |d ZCU  |d S8J  |d OCLCO  |d OCLCF  |d ICG  |d AU@  |d OCLCQ  |d DKC  |d OCLCQ  |d OCLCO  |d OCLCQ  |d OCLCO 
066 |c (3 
019 |a 742284867  |a 815528824  |a 1058277898 
020 |a 1281035645 
020 |a 9781281035646 
020 |a 9780080489704 
020 |a 0080489702 
029 1 |a AU@  |b 000051859845 
029 1 |a DEBBG  |b BV044082950 
029 1 |a AU@  |b 000062626588 
035 |a (OCoLC)823108160  |z (OCoLC)742284867  |z (OCoLC)815528824  |z (OCoLC)1058277898 
050 4 |a TK5105.59 
072 7 |a UACD  |2 bicssc 
082 0 4 |a 005.8 
049 |a UAMI 
245 0 0 |a Security Log Management :  |b Identifying Patterns in the Chaos. 
260 |b Elsevier Science & Technology  |c 2006. 
300 |a 1 online resource 
336 |a text  |b txt  |2 rdacontent 
337 |a computer  |b c  |2 rdamedia 
338 |a online resource  |b cr  |2 rdacarrier 
520 |a This book teaches IT professionals how to analyze, manage, and automate their security log files to generate useful, repeatable information that can be used to make their networks more efficient and secure using primarily open source tools. The book begins by discussing the Top 10 security logs that every IT professional should be regularly analyzing. These 10 logs cover everything from the top workstations sending/receiving data through a firewall to the top targets of IDS alerts. The book then goes on to discuss the relevancy of all of this information. Next, the book describes how to script open source reporting tools like Tcpdstats to automatically correlate log files from the various network devices to the Top 10 list. By doing so, the IT professional is instantly made aware of any critical vulnerabilities or serious degradation of network performance. All of the scripts presented within the book will be available for download from the Syngress Solutions Web site. Almost every operating system, firewall, router, switch, intrusion detection system, mail server, Web server, and database produces some type of log file.; This is true of both open source tools and commercial software and hardware from every IT manufacturer. Each of these logs is reviewed and analyzed by a system administrator or security professional responsible for that particular piece of hardware or software. As a result, almost everyone involved in the IT industry works with log files in some capacity. It provides turn-key, inexpensive, open source solutions for system administrators to analyze and evaluate the overall performance and security of their network. Dozens of working scripts and tools presented throughout the book are available for download from Syngress Solutions Web site. It will save system administrators countless hours by scripting and automating the most common to the most complex log analysis tasks. 
505 0 |a Cover; Contents; Foreword; Chapter 1 Log Analysis: Overall Issues; IT Budgets and Results: Leveraging OSS Solutions at Little Cost; Reporting Security Information to Management; Combining Resources for an "Eye-in-the-Sky" View; Blended Threats and Reporting; Conclusion; Code Solutions; Commercial Solutions: ArcSight and Netforensics; Chapter 2 IDS Reporting; Session/Flow Logging with Snort; Session/Flow Logging with Argus; Can You Determine When a DDoS/DoS Attack Is Occurring?; Using Snort for Bandwidth Monitoring; Using Bro to Log and Capture Application-Level Protocols. 
505 8 |a Tracking Users' Web Activities with BroUsing Bro to Gather DNS and Web Traffic Data; Using Bro for Blackholing Traffic to Malware-Infested Domains; Using Bro to Identify Top E-Mail Senders/Receivers; Chapter 3 Firewall Reporting; Firewall Reporting: A Reflection of the Effectiveness of Security Policies; The Supporting Infrastructure for Firewall Log Management; Chapter 4 Systems and Network Device Reporting; Web Server Logs; Recon and Attack Information; Correlating Data with the Host System; Chapter 5 Creating a Reporting Infrastructure. 
505 8 |a Creating IDS Reports from Snort Logs-Example Report QueriesCreating IDS Reports from Bro Logs-Application Log Information; Chapter 6 Scalable Enterprise Solutions (ESM Deployments); What Is ESM?; When Deploying ESM Makes Sense; Which Security Reporting Tools to Aggregate into ESM; Special Considerations for Using ESM; Using ESM Reporting for Maximum Performance; Lessons Learned Implementing ESM; Chapter 7 Managing Log Files with Microsoft Log Parser; Log File Conversion; Log Rotation and Archival; Separating Logs; Chapter 8 Investigating Intrusions with Microsoft Log Parser. 
505 8 |a Locating IntrusionsMonitoring IIS; Chapter 9 Managing Snort Alerts with Microsoft Log Parser; Building Snort IDS Reports. 
590 |a ProQuest Ebook Central  |b Ebook Central Academic Complete 
650 0 |a Application logging (Computer science) 
650 0 |a Computer networks  |x Management. 
650 0 |a Computer networks  |x Security measures. 
650 4 |a Application logging (Computer science) 
650 4 |a Computer networks  |x Management. 
650 4 |a Computer networks  |x Security measures. 
650 6 |a Journalisation applicative. 
650 6 |a Réseaux d'ordinateurs  |x Gestion. 
650 6 |a Réseaux d'ordinateurs  |x Sécurité  |x Mesures. 
650 7 |a Application logging (Computer science)  |2 fast 
650 7 |a Computer networks  |x Management  |2 fast 
650 7 |a Computer networks  |x Security measures  |2 fast 
720 |a Babbin, Jacob. 
776 0 8 |i Print version:  |a Babbin, Jacob.  |t Security Log Management : Identifying Patterns in the Chaos.  |d Rockland : Elsevier Science, ©2006  |z 9781597490429 
856 4 0 |u https://ebookcentral.uam.elogim.com/lib/uam-ebooks/detail.action?docID=254833  |z Texto completo 
880 |6 520-00/(3/r  |a This book teaches IT professionals how to analyze, manage, and automate their security log files to generate useful, repeatable information that can be use to make their networks more efficient and secure using primarily open source tools. The book begins by discussing the "Top 10℗ؤ security logs that every IT professional should be regularly analyzing. These 10 logs cover everything from the top workstations sending/receiving data through a firewall to the top targets of IDS alerts. The book then goes on to discuss the relevancy of all of this information. Next, the book describes how to scrip. 
938 |a ProQuest Ebook Central  |b EBLB  |n EBL254833 
938 |a ProQuest MyiLibrary Digital eBook Collection  |b IDEB  |n 103564 
994 |a 92  |b IZTAP