REVIEW

Book Review: Snort Cookbook

Written by John Bambenek
Published June 25, 2005

Anyone in information security knows the de facto standard for network intrusion detection is Snort. The problem is that while the documentation for Snort is ok, many of tha add-on functions, plugins, and associated applications are lacking or non-existent. This book tries to bring into one place all the things one could want to do with Snort and put it in one place. In a large part, it succeeds.

It does miss a few things along the way, such as management tools like BASE (the replacement for ACID which is not being developed anymore), and sguil. It also tends more to explain how to do things than why to do things, and I believe the section on sensor placement could be expanded. Lastly, I think the portion on legal aspects of intrusion detection and evidence can be expanded, but that might need to be taken with a grain of salt, because I am a legal wonk. To be fair, a book of this type can't cover everything in great detail.

As someone who does run Snort and has been working on ways to expand some of the data I get to it, it has proven to be a valuable resource which far outweighs the few things I found lacking. It is the only resource of its kind I know to exist. It brings to light some tools which I haven't thought of using the way it suggests, like perfmonitor and clamav. I came away from reading this book with solid ideas and tools which I plan to add into Snort. If you are looking for solid documentation on Snort and the tools and tricks you can use with it, this is your book.


Crossposted at Ravings of John C. A. Bambenek.

John Bambenek is the Assistant Politics Editor for BC Magazine and is an academic professional for the University of Illinois. He is author of the book, Illinois Deserves Better: The Ironclad Case for an Illinois Constitutional Convention and is an information security professional, part of the Internet Storm Center and a courseware author and certification grader for the GIAC family of security certifications. He is a syndicated columnist who blogs at Part-Time Pundit and the executive director of The Tumaini Foundation which helps AIDS orphans and other children in Tanzania to get an education.
Keep reading for information and comments on this article, and add some feedback of your own!
Buy from Amazon.com
Snort Cookbook Snort Cookbook
Jacob Babbin
Book,

Book Review: Snort Cookbook
Published: June 25, 2005
Type: Review
Section: Books
Filed Under: Books: Computers and Internet, Books: Reference
Writer: John Bambenek
John Bambenek's BC Writer page
John Bambenek's personal site
Spread the Word
Like this article?
Email this
Submit to del.icio.us Save to del.icio.us
RSS Feeds
All RSS Feeds (240+)
Comments on this article
BC articles by John Bambenek
Books: Computers and Internet
Books: Reference
All Books Articles
John Bambenek's personal weblog
All Review articles
All BC articles
All BC Comments

Comments

#1 — June 25, 2005 @ 14:09PM — Aaman [URL]

You should check out "Hacking Exposed" )3-5240-01700-7965) - pretty comprehensive intrusion detection, exploit track, etc. book

Want comments emailed to you? No spam, promise! Address:

Add your comment, speak your mind

(Or ping: http://blogcritics.org/mt/tb/31585)

Personal attacks are not allowed. Please read our comment policy.





Remember Name/URL?

Please preview your comment!

Fresh
Articles
Fresh
Comments