Linux Firewalls: Attack Detection and Response with iptables, psad, and fwsnort

  Author:    Michael Rash
  ISBN:    1593271417
  Sales Rank:    82992
  Published:    2007-09-15
  Publisher:    No Starch Press
  # Pages:    352
  Binding:    Paperback
  Avg. Rating:    5.0 based on 9 reviews
  Used Offers:    6 from $30.97
  Amazon Price:    $42.15
  (Data above last updated:  2008-11-18 08:40:44 EST)
  
  
Sort customer reviews by:
  
Show All Reviews on Page      Hide All Reviews on Page
   
  
Linux Firewalls: Attack Detection and Response with iptables, psad, and fwsnort
  
Linux firewalls provide capabilities that rival commercial firewalls, and are built upon the powerful Netfilter infrastructure in the Linux kernel. Linux Firewalls: Attack Detection and Response explores using Netfilter as an intrusion detection system (IDS) by combining it with Snort rulesets and custom open source software created by the author. Providing concrete examples to illustrate concepts, the book discusses Linux firewall log analysis and policies, passive network authentication and authorization, exploit packet traces and Snort ruleset emulation, and more. Perl and C code snippets are included to help readers maximize the deployment of Linux firewalls as effective mechanisms for the detection and prevention of various network-based attacks.
                  Reader Reviews 1 - 10 of 10                 
  
  
Review
Date
Review
Rating(5 High)
Review
Helpful
to:
Customer Review Reviewer
Info
Permanent
Link
Reader Reviews Below Sorted by Newest First
01-11-08 5 2\2
(Hide Review...)  EXCELLENT on what it's on, but it may not be on what you think.
Reviewer Permalink
Make no mistake, this book is on what it says it's about "Attack Detection and Response with iptables, psad, and fwsnort" it contains very little information about setting up iptables to block unwanted external traffic.

HOWEVER setting up iptables (in the basic sense) doesn't require an entire book. Sure there are whole books on that topic but there is no need for a 300 page book on it, that just seems to be the size computer books have to be in order to get published. Which means other books on iptables are probably going to about 250 pages of fluff.

Incidentally this book actually only spends about the first 35 pages describing that, the remainder is fantastic, useful, well written information about doing the things that make iptables truly useful. "detection and response" ACTIVELY securing your system.

In addition to being comprehensive and useful this book happens to be well written, far better than most technical books.

If you're thinking about buying a book on Linux firewalls, make it this one, but if you're not already familiar with iptables expect to read the first 35 pages, then a couple online tutorials and then come back to this book.
(Review Data Last Updated: 2008-01-31 03:14:42 EST)
01-10-08 5 6\6
(Hide Review...)  EXCELLENT on what it's on, but it may not be on what you think.
Reviewer Permalink
Make no mistake, this book is on what it says it's about "Attack Detection and Response with iptables, psad, and fwsnort" it contains very little information about setting up iptables to block unwanted external traffic.

HOWEVER setting up iptables (in the basic sense) doesn't require an entire book. Sure there are whole books on that topic but there is no need for a 300 page book on it, that just seems to be the size computer books have to be in order to get published. Which means other books on iptables are probably going to about 250 pages of fluff.

Incidentally this book actually only spends about the first 35 pages describing that, the remainder is fantastic, useful, well written information about doing the things that make iptables truly useful. "detection and response" ACTIVELY securing your system.

In addition to being comprehensive and useful this book happens to be well written, far better than most technical books.

If you're thinking about buying a book on Linux firewalls, make it this one, but if you're not already familiar with iptables expect to read the first 35 pages, then a couple online tutorials and then come back to this book.
(Review Data Last Updated: 2008-11-19 05:48:05 EST)
01-06-08 5 (NA)
(Hide Review...)  The result is a fine pick for any programmer's library.
Reviewer Permalink
Libraries catering to system administrators will find LINUX FIREWALLS an essential acquisition, discussing the technical aspects of the iptables firewall and Netfilter built into the Linux application. Examples of firewall log analysis, policies, network authorization processes and more compliment chapters that include Perl and C code pieces to help keep a network secure. The result is a fine pick for any programmer's library.
(Review Data Last Updated: 2008-01-11 08:14:56 EST)
12-21-07 5 2\2
(Hide Review...)  One of the best technical books published in 2007
Reviewer Permalink
Disclaimer: I wrote the foreword for this book, so obviously I am biased. However, I am not financially compensated for this book's success.

In the foreword I note that Linux Firewalls is a "great book." As a FreeBSD user, Linux Firewalls is good enough to make me consider using Linux in certain circumstances! Mike's book is exceptionally clear, organized, concise, and actionable. You should be able to read it and implement everything you find by following his examples. You will not only learn tools and techniques, but you will be able to appreciate Mike's keen defensive insights.

The majority of the world's digital security professionals focus on defense, because offense is left to the bad guys, police, and military. I welcome books like Linux Firewalls that bring real defensive tools and techniques to the masses in a form that can be digested and deployed for minimum cost and effort.

One of the main reasons Linux Firewalls is a great book is that Mike Rash is an excellent writer. I've read (or tried to read) plenty of books that seemed to offer helpful content, but the author had no clue how to deliver that content in a readable manner. Linux Firewalls makes learning network security an enjoyable experience. Mike is exceptionally detail-oriented (see the RST vs RST ACK issue on p 63 and elsewhere) and he often cites sources and additional references. Linux Firewalls very nicely integrates sample network traffic to make numerous points; Ch 11 has several great examples. The sections on Fwsnort even improved my understanding of Snort itself.

The bottom line is that if you are a user of non-Microsoft operating systems (Linux, BSD, etc.) and you want to know how Linux can help defend your network, you will enjoy reading Linux Firewalls.
(Review Data Last Updated: 2008-01-07 08:04:29 EST)
12-05-07 5 2\2
(Hide Review...)  Nice, accurate and interesting. Not like other books about firewalls.
Reviewer Permalink
When I bought "Linux Firewalls" I was expecting a good book because I already knew that the work of Michael Rash is excellent. However, I expected the traditional Iptables handbook that looks more like a "man page". Surprisingly I found that the book was much better than that. Instead of detailing every single feature of the Iptables infrastructure, Michael Rash explains how Iptables can be used as a powerful (and free) Intrusion Detection/Prevention System. To achieve that, Rash presents three open source tools developed by himself: psad, an iptables-based port scan detector, fwsnort, a tool that translates snort rules into iptables sentences, and fwknop, a Port Knocking and SPA authentication system.

The book is very practical. It's amazing how everything is presented so clearly and with such useful examples. The author first introduces the potential threats that are associated with the Network Layer, Transport Layer and Application Layer (I loved those chapters). Then he starts discussing the detection of malicious attackers that try to break into the system. Finally he presents active response mechanisms against attackers and ways to secure the whole system with additional layers of security.

The book is great if what you want is to secure your Linux system using IPtables and the open source tools developed by Rash. Rash is an expert on firewalls and intrusion detection systems. If you follow his suggestions you'll build a very secure system. Firewall enthusiasts and TCP/IP fans will also enjoy reading the book because its written by a geek and its written for geeks. However, if you are looking for an Iptables handbook, you are looking for a theoretical book about Firewalls or you want to use other tools than the ones presented in the book, then "Linux Firewalls" may not be the best option for you.
(Review Data Last Updated: 2007-12-21 02:12:30 EST)
11-20-07 5 (NA)
(Hide Review...)  VERY VERY HIGHLY RECOMMENDED!!
Reviewer Permalink
Do you have any familiarity with TCP/IP networking concepts and Linux system administration? If you do, then this book is for you. Author Michael Rash, has done an outstanding job of writing a book that concentrates on network attacks--detecting them and responding to them.

Rash, begins with an introduction to packet filtering with iptables, including kernal build specifics and iptables administration. Then, the author shows the types of attacks that exist in the network layer and what you can do about them. Next, he illustrates classes of application layer attacks that iptables can be made to detect, and introduces you to the iptables string match extension. The author also discusses installation and configuration of psad, and shows you why it is important to listen to the stories that iptables logs have to tell. He continues by introducing you to advanced psad functionality, including integrated passive OS fingerprinting, Snort signature detection via packet headers, verbose status information, and Dshield reporting. Then, the author discusses the culmination of the attack detection and mitigation strategies that are possible with iptables. Next, he compares and contrasts two passive authorization mechanisms: port knocking and SPA. The author continues by showing you how to install and make use of fwknop together with iptables to maintain a default-drop stance against all unauthenicated and unauthorized attempts to connect to your SSH daemon. Finally, the author wraps up with some graphical representations of iptables log data.

This most excellent book takes on a highly applied approach. In other words, after reading this book, you will be armed with a strong working knowledge of how network attacks are detected and dealth with via iptables.
(Review Data Last Updated: 2007-12-06 01:07:00 EST)
11-02-07 5 1\1
(Hide Review...)  A bit techy but good book
Reviewer Permalink
Watch Video Here: http://www.amazon.com/review/R26NFLQZ9DTFJI Not for beginners, you need some tech background to get much out of this.

( Full text review at http://aplawrence.com/6004 )
(Review Data Last Updated: 2007-11-21 02:51:39 EST)
11-01-07 5 (NA)
(Hide Review...)  Ready to Increase Your Personal Computing Security at LOW Cost?
Reviewer Permalink
If so, this gem will walk you through the process of implementing three low-footprint applications which will create an additional ring of security, decreasing an attackers chances of penetrating through your online connection.

Although this is written for network security professionals, the average linux user can take this information and apply it to their desktop. (Ubuntu, Debian, Redhat, Gentoo, Suse, etc.) The book is full of information, examples, and testing procedures.

If you are looking to build a personal security "toolbox" for linux, then I recommend you consider this book. And for those of you that use ulog with iptables, don't forget to modify ULOG_DATA_FILE to /var/log/ulog/syslogemu.log.
(Review Data Last Updated: 2007-11-21 02:51:39 EST)
10-15-07 5 (NA)
(Hide Review...)  A great book
Reviewer Permalink
I have been looking forward to getting this book into my hands, since the other projects Michael Rash has led so far look quite impressive to me. Looking at his website [...], I discovered Single Packet Authorization (SPA) with Fwknop, and therefore put port-knocking aside, to give us a more secure and more reliable solution to access services such as SSH. He covers this point (SPA), and talks about psad and fwsnort as well to show how to enhance security and understand attacks using the famous iptables project from Netfilter.

It is not a cook book to build iptables rules from scratch, and make something quite static, this book gives you the ablilities to create something dynamic, strong, and help you to monitor instrusions since the outside does not lack of imagination.

Along this book, we follow a logic which leads us through the OSI reference model layers and M. Rash's projects to help us to harden our security system. I have been surprised on how everything is well-explained, and well-documented. Thus, this book provides us with technical explanations and references, code snippets, attack descriptions, and useful links on related topics. You will find in this book the answer on how to use active responses to attacks, how to gather data and get a visual representation of an attack..., as a matter of fact, everything you need or wanted to know.

That's a great book.

F. Joncourt
Hardware/Software Engineer



(Review Data Last Updated: 2007-10-31 22:05:03 EST)
10-08-07 5 (NA)
(Hide Review...)  An obligatory reference for everyone involved with firewalls.
Reviewer Permalink
Es uno de los mejores libros escritos en este tema que todo profesional en seguridad debería leer y una referencia obligatoria para todo aquel involucrado con los cortafuegos.

Describe el Quien, Como y Cuando se deben de mitigar los principales problemas asociados con la seguridad en el anfitrión. Cuando la ejecución de esfuerzos en las capas bajas del modelo OSI han sido rebasadas el uso de herramientas como psad, fwsnort e iptables nos dan un recurso simple, poderoso y efectivo en costos para asegurar un servicio crítico y fortalecer un anfitrión expuesto a las inclemencias de un ambiente cada vez más hostil.

Este libro es diferente a otros que hablan del mismo tema en su esfuerzo didáctico con ejemplos claros y apegados a los vectores de ataque comunes que uno debe de enfrentar cada día si se está inmerso en el campo de la seguridad informática.

Carlos A. Ayala
Oficial de Seguridad de la Información
Grupo Profuturo GNP


This is one of the best books in its subject that every security practitioner should read and obligatory reference for everyone involved with firewalls.

Describe the Who, How and When of the way in which the main issues related with host security should be mitigated.
When the execution of efforts in the lower layers of the OSI model has been exceeded the use of tools like psad, fwsnort and iptables give us a simple, powerful and cost effective resource to secure a critical service and harden a host exposed to the harshness of an environment every time more hostile.

This book is different to others who speak about the same subject in its didactic effort with clear examples and real life vector attacks that everyone immersed in the information security field must face every single day.

Carlos A. Ayala
Information Security Officer
Profuturo GNP Group
(Review Data Last Updated: 2007-10-16 02:26:24 EST)
  
                  Reader Reviews 1 - 10 of 10                 
  
  
  
  
  
  

Because the data used to generate this site come from outside sources, VeryWellSaid.com cannot guarantee the completeness or accuracy of the data.
Search VeryWellSaid™
Google
Web VeryWellSaid™
New subjects are added every week.
View Subjects Below by:
* Top Selling
 (click category name, left)
* Top-Rated Top Sellers
 (click 'Top Rated', right)
In the news...  
Dubai\UAE Top Rated
Influenza\Bird Flu Top Rated
Iraq Top Rated
Supreme Court Top Rated
All Books Top Rated
Arts Top Rated
Photography Top Rated
Digital Photography Top Rated
Digital Cameras Top Rated
Biography Top Rated
Business Top Rated
Management Top Rated
Marketing Top Rated
Sales Top Rated
Stocks Top Rated
Bonds Top Rated
Real Estate Top Rated
Trading Top Rated
Commodities Trading Top Rated
Time Management Top Rated
Starting A Business Top Rated
Children's Top Rated
Comics Top Rated
Computers Top Rated
PC Top Rated
Mac Top Rated
Programming Top Rated
Design Patterns Top Rated
.Net Top Rated
C# Top Rated
Vb.Net Top Rated
Asp.Net Top Rated
Java Top Rated
Python Top Rated
PHP Top Rated
Perl Top Rated
Javascript Top Rated
Ajax Top Rated
CSS Top Rated
Open Source Top Rated
SQL Top Rated
Databases Top Rated
Oracle Top Rated
MySql Top Rated
Sql Server Top Rated
IIS Top Rated
Apache Top Rated
Linux Top Rated
Windows Server Top Rated
Project Management Top Rated
HTML Top Rated
UML Top Rated
IT Certifications Top Rated
Cisco Certifications Top Rated
MCSE Top Rated
MCSD Top Rated
Cooking Top Rated
Italian Cooking Top Rated
Vegetarian Cooking Top Rated
Wine Top Rated
Engineering Top Rated
Entertainment Top Rated
Health Top Rated
Nutrition Top Rated
Dieting Top Rated
Sex Top Rated
History Top Rated
Military History Top Rated
British History Top Rated
Middle East History Top Rated
Land Battles Top Rated
Naval Warfare Top Rated
Air Warfare Top Rated
9/11 Top Rated
Terrorism Top Rated
Home Top Rated
Mortgage\Home Equity Loan Top Rated
Cars Top Rated
Car Buying Top Rated
Sports Cars Top Rated
Cat Top Rated
Humor Top Rated
Horror Top Rated
Law Top Rated
IP Law Top Rated
Legal History Top Rated
Fiction Top Rated
Oprah's Book Club Top Rated
Medicine Top Rated
Cancer Top Rated
Stroke Top Rated
Heart Disease Top Rated
Fertility Top Rated
Diabetes Top Rated
Pharmacology Top Rated
Back Problems Top Rated
Menopause Top Rated
Thyroid Top Rated
Pain Top Rated
Organic Chemistry Top Rated
Immune System Top Rated
Mystery Top Rated
Nonfiction Top Rated
Outdoors Top Rated
Running Top Rated
Radio Control Models Top Rated
Guns Top Rated
Parenting Top Rated
Divorce Top Rated
Professional Top Rated
Reference Top Rated
Religion Top Rated
Romance Top Rated
Science Top Rated
Physics Top Rated
Chemistry Top Rated
Astronomy Top Rated
Psychology Top Rated
Science Fiction Top Rated
Sports Top Rated
Teens Top Rated
Travel Top Rated
USA Top Rated
Europe Top Rated
France Top Rated
Italy Top Rated
England Top Rated
China Top Rated
All Books Arts Biography Click Here For An A-Z Index Of All 213 Best-Seller Subjects Business Children's Comics
Computers Cooking Engineering Entertainment Health History Home Horror Humor Law Fiction Medicine Mystery
Nonfiction Outdoors Parenting Professional Reference Religion Romance Science Sci-Fi Sports Teens Travel
In Association with Amazon.com

Cache miss
(not cached)