
Linux Firewalls: Attack Detection and Response with iptables, psad, and fwsnort
Author(s): Michael Rash (Author)
- Publisher: No Starch Press
- Publication Date: September 15, 2007
- Edition: 1st
- Language: English
- Print length: 336 pages
- ISBN-10: 1593271417
- ISBN-13: 9781593271411
Book Description
Concrete examples illustrate concepts such as firewall log analysis and policies, passive network authentication and authorization, exploit packet traces, Snort ruleset emulation, and more with coverage of these topics:
–Passive network authentication and OS fingerprinting
–iptables log analysis and policies
–Application layer attack detection with the iptables string match extension
–Building an iptables ruleset that emulates a Snort ruleset
–Port knocking vs. Single Packet Authorization (SPA)
–Tools for visualizing iptables logs
Perl and C code snippets offer practical examples that will help you to maximize your deployment of Linux firewalls. If you’re responsible for keeping a network secure, you’ll find
Linux Firewalls invaluable in your attempt to understand attacks and use iptables—along with psad and fwsnort—to detect and even prevent compromises.Editorial Reviews
Review
—;login
“This admirable, eminently usable text goes much further than advertised.”
—Linux User and Developer, Issue 77
“If you run one or more Linux based firewalls, this book will not only help you to configure them securely, it will help you understand how they can be monitored to discover evidence of probes, abuse and denial of service attacks. Readers of this book will gain an understanding of firewall log analysis and how the netfilter firewall can be dramatically enhanced with several open source tools.”
—Ron Gula, CTO & Co-Founder of Tenable Network Security
“The book is easy to read, and chock full of attack vectors and subtle (and not so subtle) iptables configuration tips. This well researched book heightens an average system administrator’s awareness to the vulnerabilities in his or her infrastructure, and the potential to find hardening solutions.”
—Free Software Magazine
“Right from the start, the book presented valuable information and pulled me in. Each of the central topics were thoroughly explained in an informative, yet engaging manner. Essentially, I did not want to stop reading. Rating: 9/10”
—Slashdot
“One of the main reasons Linux Firewalls is a great book is that Mike Rash is an excellent writer. I’ve read (or tried to read) plenty of books that seemed to offer helpful content, but the author had no clue how to deliver that content in a readable manner. Linux Firewalls makes learning network security an enjoyable experience.”
—Richard Bejtlich, Tao Security
“What really makes this book different from the others I’ve seen over the years is that the author approaches the subject in a layered method while exposing potential vulnerabilities at each step. (Thank you so VERY much.) So for those that are new to the security game, the book also takes a stab at teaching the basics of network security while teaching you the tools to build a modern firewall.”
—InfoWorld
“Linux Firewalls is a great resource. It provided insight and helpful information into additional tools to get the most out of iptables and to add in additional functionality.”
—tuxmachines.org
“If you or anyone you know is responsible for keeping a secure network, Linux Firewalls is an invaluable resource to have by your side. You will gain a better understanding of attacks, how to use iptables, PSAD, and fwsnort – all in an effort to properly defend and respond to attempted compromises.”
—LinuxSecurity.com
“Michael does a great job of explaining not just how iptables works, but he shows how users gain operational value from using open source tools and techniques, such as visualization, to analyze firewall logs.”
—Raffael Marty, SecViz
Wow! eBook


