Showing posts with label computer security. Show all posts
Showing posts with label computer security. Show all posts

Operating System Security (Synthesis Lectures on Information Security, Privacy, and Trust) Review

Operating System Security (Synthesis Lectures on Information Security, Privacy, and Trust)
Average Reviews:

(More customer reviews)
Are you looking to buy Operating System Security (Synthesis Lectures on Information Security, Privacy, and Trust)? Here is the right place to find the great deals. we can offer discounts of up to 90% on Operating System Security (Synthesis Lectures on Information Security, Privacy, and Trust). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Operating System Security (Synthesis Lectures on Information Security, Privacy, and Trust) ReviewGreat book on the history, fundamentals and current implementations of secure operating systems. I picked this book up due to a mention on the grsecurity homepage and I'm very glad I did, it's very through and provides excellent references if you still have an appetite for more information.Operating System Security (Synthesis Lectures on Information Security, Privacy, and Trust) Overview

Want to learn more information about Operating System Security (Synthesis Lectures on Information Security, Privacy, and Trust)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Voice over Internet Protocol (VoIP) Security Review

Voice over Internet Protocol (VoIP) Security
Average Reviews:

(More customer reviews)
Are you looking to buy Voice over Internet Protocol (VoIP) Security? Here is the right place to find the great deals. we can offer discounts of up to 90% on Voice over Internet Protocol (VoIP) Security. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Voice over Internet Protocol (VoIP) Security Review[note: I am the same reviewer IP_Geek, but Amazon only lets you review once, so this is follow up]
Despite what Dr. Michael G. Mathews may believe, I really wanted to use my real name, and I have never worked for Exodus (although they may have been a customer of one of the companies I worked for, unknown to me). I have worked at 4 networking vendor/manufacturer companies, of which 2 were data vendors (routers/switches) and 2 VoIP companies. I currently work at a vendor who makes VoIP security products, and thus I felt it a bit unfair/dangerous to my employer to critique any book in a public forum. (because you can google my name and find out where I work)
I still feel that way, so I will try to convince you I have no agenda as easily as I can as follows:
1) My argument was simply that you should VERY carefully read the table of contents, including the page numbers. Dr. Mathews is quite right that this type of book will appeal to some people, just that in my humble opinion I hope those people are not put in charge of securing VoIP, because this book doesn't do it. (see below why)
2) I did not slam the authors in person or capabilities - I slammed the book they wrote. This book was published fairly recently (6 months ago), and this book is written from a VoIP perspective of several years ago, in my opinion. It is missing tons, and contains lots of frankly irrelevant content to the subject. If the title of the book "VoIP Security" is not meant to actually mean this is a book about VoIP Security, then I guess I don't understand what book titles are for. The back cover even says "This book will teach you how to plan for and implement VoIP security solutions...". I am taking issue with that statement, not the authors personally.
3) I think some people may like the book, because they are not already experts in VoIP security and thus don't know what they're missing. I believe I am pretty close to an expert. I was looking for a book I could recommend to my customers and colleagues who are not.
4) Dr. Mathews says "It addresses the protocol specifics, the technical issues, and the security options surrounding the protocol." I think that it addresses them if you don't know what they really are. I will tell you what I know is missing from this book:
a) TLS. Much of the VoIP industry believes TLS to be the future panacea for VoIP service security. (it's not used much today, but many are moving that way) That belief is true for eavesdropping protection/privacy, and server-side authentication. It is not true for DoS/DDoS attack protection, or user-side authentication. It is also not true for fraud prevention, and it adds many scalability/performance issues. The reasons for that, how SIP over TLS works at a protocol level, and more interestingly the security issues around it are not addressed in this book. That should be a whole chapter. As a side note, they say TLS requires TCP, which was true until the draft for DTLS came out for TLS over UDP, which has received much publicity in the VoIP security world. It came out in 2003 - long before this book was finished.
b) IPSec. The 3GPP/IMS world and some inter-carrier VoIP peering uses IPSec to secure VoIP, which like TLS only provides some security features/benefits but not others. Used by enterprises it also adds latency to RTP (because they use it in tunnel mode over TCP). I give the authors some credit - they did spend 10 pages on the VPN issues with IPsec (but it's not exactly how 3GPP uses it). I still think this topic should be a whole chapter.
c) SRTP. How SRTP is performed, from a protocol level and hardware/software level, leaves much to be desired. There is in fact much debate in the industry if it is needed at all, how it can be managed, how CALEA can be supported with it, etc. SRTP also does not protect the gateways/phones, and the implementation of it is the critical piece as to whether it's any good at all. The authors spend a couple pages on it - I would probably spend at least half a chapter on it - perhaps by removing the big section on how codecs work (which has virtually no relevance to VoIP security compared to this list). The fact there are different codecs is important, but not the formulas for the plot curves of A-law and u-LAw!
d) S/MIME. Some voip products do it, but most don't, and it breaks some things. Again, the protocol and security issues with S/MIME are not covered in much detail in this book. (although it's covered over at least a few pages, just not enough I think)
e) VoIP Firewalls. One simply cannot lump that into one group. The differences in feature/architecture/functionality between categories of friewalls (not to mention models/brands), and how you use VoIP with them, is so critical I'm literally shocked there isn't a ton more detail on this. Look at other security books for data. There are entire books about just a particular firewall brand. (not that this book should get to that level of detail)
f) STUN/TURN/ICE. They are mentioned briefly, but really these technologies/protocols are another pandora's box of security issues, and should be addressed if crossing NAT's is at all useful for you. Likewise, Session Border Controllers are mentioned briefly in this book, but they are considered by most to be one of the fundamental pieces in VoIP security.
ok, enough time spent. I'm sorry for the length of this reply. Again, this book may appeal to you (to each his own), I just caution you that there is a lot more under the Voip security hood than is mentioned in this book.
I'm sure the authors are good guys - perhaps they wrote this book a long time ago and printing/publishing books is just too much delay to keep up with technology.
(although I'm still struggling to understand how 30 pages of codec waveform detail helps any voip security person)Voice over Internet Protocol (VoIP) Security Overview

Want to learn more information about Voice over Internet Protocol (VoIP) Security?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Deep Packet Inspection (DPI): High-impact Strategies - What You Need to Know: Definitions, Adoptions, Impact, Benefits, Maturity, Vendors Review

Deep Packet Inspection (DPI): High-impact Strategies - What You Need to Know: Definitions, Adoptions, Impact, Benefits, Maturity, Vendors
Average Reviews:

(More customer reviews)
Are you looking to buy Deep Packet Inspection (DPI): High-impact Strategies - What You Need to Know: Definitions, Adoptions, Impact, Benefits, Maturity, Vendors? Here is the right place to find the great deals. we can offer discounts of up to 90% on Deep Packet Inspection (DPI): High-impact Strategies - What You Need to Know: Definitions, Adoptions, Impact, Benefits, Maturity, Vendors. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Deep Packet Inspection (DPI): High-impact Strategies - What You Need to Know: Definitions, Adoptions, Impact, Benefits, Maturity, Vendors ReviewIf you want to support a bogus author and lose your money, then by all means waste your hard-earned money and buy this book. But really, this book is a waste of paper.
This book is nothing but someone going to Wikipedia and doing a big cut and paste.
All the author does is copy from Wikipedia and put in into a digital format. You can do the same thing for free. If you look at the author, he has over 400 titles like this.
The so called author wrote 15 books alone in October 2011. That should tell you about this fraud. All they do it take current topics, go to Wikipedia, cut, paste, and then charge you for it. Any 10-year old could do the same thing.
There is an expose about this author and firm titled 'There's a sucker born every minute - and charlatans to make sure they pay for it' at [...]
The expose writes about how the company published free content and charges you for it.
Not only is this book free, the author uses a lot of filler from other Wiki articles. So you end up with non relevant text.
Do not buy this book. You will just be wasting your cash.
Deep Packet Inspection (DPI): High-impact Strategies - What You Need to Know: Definitions, Adoptions, Impact, Benefits, Maturity, Vendors Overview

Want to learn more information about Deep Packet Inspection (DPI): High-impact Strategies - What You Need to Know: Definitions, Adoptions, Impact, Benefits, Maturity, Vendors?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Hacking Ubuntu: Serious Hacks Mods and Customizations (ExtremeTech) Review

Hacking Ubuntu: Serious Hacks Mods and Customizations (ExtremeTech)
Average Reviews:

(More customer reviews)
Are you looking to buy Hacking Ubuntu: Serious Hacks Mods and Customizations (ExtremeTech)? Here is the right place to find the great deals. we can offer discounts of up to 90% on Hacking Ubuntu: Serious Hacks Mods and Customizations (ExtremeTech). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Hacking Ubuntu: Serious Hacks Mods and Customizations (ExtremeTech) ReviewI bought this book along with the Ubuntu Linux Bible. While I appreciate the latter, I consult the former regularly. In fact, this is the quickest I've ever consumed a technical book. "Hacking Ubuntu" is a great practical guide with excellent sample commands and scripts which don't just point you to a possible fix but actually resolve the problem. For example, I installed Xubuntu 7.04 on a Vaio laptop. When I went to configure my WLAN connections, my only displayed encryption option was WEP. I have WPA-PSK configured on my router. I flipped thru the book to the wireless network section and quickly saw the solution to getting WPA configured for each of the 2 NICs in my laptop (an integrated Intel and add-on D-Link).
More importantly, Krawetz includes the code you need to enable WPA support each time you boot the PC. While I might have been able to ferret all this out via hours of searching Google and Ubuntu forums, Krawetz's thoughtful presentation provided me with the necessary fix in 5 minutes. I was also able to use the sample code to write a short script to re-establish the LAN connection when I bring the laptop out of hibernation.
The rest of the book is equally helpful; it's chockful of practical tips. This book makes the difference between installing and muddling thru Ubuntu and installing, tweaking and making your Ubuntu install your own. Highly recommend for any Ubuntu user.Hacking Ubuntu: Serious Hacks Mods and Customizations (ExtremeTech) Overview

Want to learn more information about Hacking Ubuntu: Serious Hacks Mods and Customizations (ExtremeTech)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Science and Technology of Terrorism and Counterterrorism, Second Edition (Public Administration and Public Policy) Review

Science and Technology of Terrorism and Counterterrorism, Second Edition (Public Administration and Public Policy)
Average Reviews:

(More customer reviews)
Are you looking to buy Science and Technology of Terrorism and Counterterrorism, Second Edition (Public Administration and Public Policy)? Here is the right place to find the great deals. we can offer discounts of up to 90% on Science and Technology of Terrorism and Counterterrorism, Second Edition (Public Administration and Public Policy). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Science and Technology of Terrorism and Counterterrorism, Second Edition (Public Administration and Public Policy) ReviewThe Science and Technology of Terrorism and Counterterrorism examine some topics that you might find in other texts but in a more understandable format and with greater depth. It goes beyond this in that it covers so much more that is unique in a variety of areas such as the theory of terrorism and technology, the group psychology of terrorism, aerosol science, sensors (one of the most complete works on chem., bio and nuclear sensors that I have seen), medical preparedness, training and homeland security infrastructure. It is concise and timely and is written by a distinguished group of scholars with a broad range of expertise to thoroughly cover all of these complex topics.Science and Technology of Terrorism and Counterterrorism, Second Edition (Public Administration and Public Policy) Overview

Want to learn more information about Science and Technology of Terrorism and Counterterrorism, Second Edition (Public Administration and Public Policy)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Handbook of Digital Forensics and Investigation Review

Handbook of Digital Forensics and Investigation
Average Reviews:

(More customer reviews)
Are you looking to buy Handbook of Digital Forensics and Investigation? Here is the right place to find the great deals. we can offer discounts of up to 90% on Handbook of Digital Forensics and Investigation. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Handbook of Digital Forensics and Investigation ReviewThis book has become one of my three "go to" books when it comes to digital forensics along with Brian Carrier's File System Forensic Analysis and Harlan Carvey's Windows Forensic Analysis DVD Toolkit, Second Edition.
Don't skip Rob Lee's excellent forward to this book. Lee crafts a very concise explanation of how the digital forensics field is growing and evolving.
Eoghan Casey's introduction further expands on the theme with a very thoughtful analysis of the current state of digital forensics and how the scientific method can and should be applied to our field. In this section, Casey begins to bring out one of the primary themes of the first portion of the book which is that there are different aspects to digital forensics that can be summarized in the three main disciplines of traditional forensic analysis, electronic discovery and intrusion investigation.
The first part of the book (chapters two through four) is devoted to exploring the three disciplines by devoting a chapter to each one. These individual chapters are exemplary overviews of each of the disciplines.
Chapter two is one of the finest overviews that I've seen regarding digital forensics. Casey and Curtis Rose provide set what will be a persistent theme in the book which imparting technical information in a very approachable manner, but also in a relatively short amount of space. This chapter builds and expands on Casey's invocation of the scientific method and it's role in forensic analysis via a thorough explanation of forensic analysis that is well illustrated by a sample case scenario created by the authors to help explain their methodology.
Chapter three is a fantastic overview of e-discovery and coupled with chapter two provides an effective answer to the question of what the difference is between electronic discovery and forensic analysis. Chapter three shouldn't be dismissed as an overview, however. The authors put forth quite a bit of effort in explaining some tactical level issues such as how to properly interview an evidence custodian to determine the universe of data that might be relevant to a particular matter and how to use various tools to capture data.
Chapter four provides a detailed overview of intrusion investigations using the incident response life cycle. Similar to chapter three, this chapter not only provides an expert overview of the life cycle, but also provides the reader with tactical level advice such as the use of timeline analysis to assist a responder with an incident handling scenario. Like chapter two, the authors use investigative scenarios to illustrate their points.
The second half of the book is more tactical in nature and will have great appeal to both the experience practitioner and those who are merely curious about digital forensics. As in the first half of this book, the authors and their editor Casey, take great pains to make sometimes very technical information approachable to all audiences.

Chapter five is the section on Windows forensic analysis. Authors Ryan Pittman and David Shaver provide probably the most concise, yet effective overview of Windows forensic analysis that I've read recently especially given the fact that they have just a chapter in which to do their work. At the time the chapter was written, the authors had access to early versions of Windows 7 so the chapter spends a certain amount of time comparing and contrasting the differences between Windows XP compared to Vista\Windows 7. The authors also provide a very effective overview of traditional forensic artifacts such as $MFT artifacts and registry artifacts. While this chapter doesn't serve as a replacement for the Carrier and Carvey books, it's an examplary primer for those just starting in Windows forensic analysis and an excellent "cheat sheet" for more experienced practitioners. This is not to say that the authors are merely rehashing existing data. Far from it. Even an experienced examiner is likely to learn new information by reading their work. They, for example, put a lot of effort into explaining data destruction, file deletion and defragmentation. It's amazing how much content they managed to include in this chapter.
Chapter six continues on the theme of packing a lot of information into a short amount of space, but doing so in an approachable manner. This chapter on UNIX Forensic Analysis includes at it's beginning a very helpful explanation of the Unix and Linux worlds. Like chapter five the authors provide valuable information on the inner workings of file system forensic analysis as well as well as more application level artifacts such as Firefox browser analysis and chat analysis. A nice bonus is that this chapter also covers removable media analysis. Most work that I have seen in this area has been relative to Windows operating systems so it was good to see this content for a non-Windows operating system. The authors also spend quite a few pages on the examination of email artifacts which is also a welcome addition.
Anthony Kokocinski's Macintosh Forensic Analysis makes up Chapter seven. Given that this is a weakness in my individual skill set, I learned an incredible amount from this chapter. Kokocinski continues the overall theme of the book in that he presents his knowledge on the subject in a very approachable manner. Kokocinski also includes a detailed section on popular Mac applications such as Safari, iCal, Mail, etc.
Chapter eight is Ronald van der Knijff's amazing chapter on embedded system analysis. In a book this good, it's hard to pick a chapter that can be considered a highlight, but this chapter would be a top contender. It covers a wide area of devices from traditional technological tools such as cellphones and GPS systems to devices such as parking meters and pacemakers. The chapter provides a solid overview of the various technologies that comprise this wide range of devices, but also delves into tactical matters such as how to preserve and even repair damaged devices that might contain useful data.
Chapter nine is the excellent and extensive network investigation chapter. Like the previous chapters, this is a more tactical treatment of a subject that is introduce earlier in the book and is an excellent overview how to practically apply the themes introduced in chapter four. The chapter includes an overview of TCP/IP networking down that includes an explanation of the structure of an Ethernet frame and TCP/IP packet headers. The authors make extensive use of the Wireshark tool which makes it easy for a student of network investigations to emulate the work being done as part of their overall learning experience. The later portions of the chapter delve into the work of investigating networking technologies such as Cisco routers. The Cisco section includes an overview of how to use Cisco IOS to help facilitate a network investigation.
Chapter ten is an amazing chapter on mobile network investigations put together by Dario Forte and Andrea de Donno. As it's title suggestion, this isn't a chapter on the examination of digital communication devices such as cell phones, but how to understand and investigate the network environments in which they operate. The authors deal with such issues as determining the location of particular devices, what networking data might be available and the interception of data. As one would expect with a chapter such as this, the authors also cover legal issues with an emphasis on relevant EU legislation.
Full Disclosure: While I haven't had the privilege of meeting most of the authors of this excellent book, I'm honored to have connections with some of the authors including, but not limited to, being on a board with Rob Lee and Eoghan Casey.Handbook of Digital Forensics and Investigation Overview

Want to learn more information about Handbook of Digital Forensics and Investigation?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Cyber Warfare: Techniques, Tactics and Tools for Security Practitioners Review

Cyber Warfare: Techniques, Tactics and Tools for Security  Practitioners
Average Reviews:

(More customer reviews)
Are you looking to buy Cyber Warfare: Techniques, Tactics and Tools for Security Practitioners? Here is the right place to find the great deals. we can offer discounts of up to 90% on Cyber Warfare: Techniques, Tactics and Tools for Security Practitioners. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Cyber Warfare: Techniques, Tactics and Tools for Security Practitioners Review"Cyber Warfare: Techniques, Tactics and Tools for the Security Practitioners" is a consolidation of the current thinking around the topic of cyber warfare; not the way you hear about in the media where everything is a war of some kind (War on drugs, War on Terrorism, etc) but a discussion about what it means to conduct warfare via cyberspace. This is a tough topic because there are so many opinions about what Cyber Warfare is that you could literally spend an entire book just covering the definitions. The authors deftly avoid that trap and manage to provide a coherent line of thinking around Computer Network Operations even when these kinds of activities bump up against other cyber space dangers like Cyber Crime, Cyber Hactavism, Cyber Espionage and Cyber Terrorism. This is a primer; a one stop shop to get you up to speed on the topic if you are new to it or a refresher even if you have been enmeshed in it for years.
'
The authors, Steve Winterfield and Jason Andress, cover everything you will want to consider when thinking about how to use cyberspace to conduct warfare operations. The primary concepts have been bouncing around US military circles for over a decade but they have never been collected into one tome before. Clarke and Knake's book, "Cyber War: The Next Threat to National Security and What to Do about It," discusses how weak the US network defenses are and offers suggestions about how to improve. Carr's book, "Inside Cyber Warfare: Maping the Cyber Underworld," presents threat examples and nation state capabilities. Libicki's book, "Cyberdeterrence and Cybrewar," attacks cyberwar from a policy viewpoint and does not really address operational considerations. Stiennon's book, "Surviving Cyberwar," is a good place to start if you are new to the subject and is almost a prerequisite for this book.
Full Disclosure: One of the authors, Steve Winterfield, used to work for me when he and I were both in the US Army wrestling with all of these ideas right after 9/11. I ran the Army Computer Emergency Response Team (ACERT) and Steve ran the Army's Southern Regional CERT (RCERT South). He and I have been friends ever since and he even quoted me in one of the back chapters.
Although the content has been around for a while, it is striking how little the main concepts have changed. In a world where new innovations completely alter the popular culture every eighteen months, the idea that Cyber Warfare's operational principals remain static year after year is counter-intuitive. After reading through the various issues within though, you begin to understand the glacial pace. These difficult concepts spawn intractable problems and the authors do a good job of explaining them.
I do have a slight issue with the subtitle though: "Techniques, Tactics and Tools for the Security Practitioners." The way I read this book, the general purpose (GP) Security Practitioner will not find this book very useful except as background information. Aside from the chapters on Logical Weapons, Social Networking and Computer Network Defense, most of the material has to do with how a nation state, mostly the US, prepares to fight in cyber space. There is overlap for the GP security practitioner, but this material is covered in more detail in other books.
The book is illustrated. Some of the graphics are right out of military manuals and have that PowerPoint Ranger look about them. Some are screenshots of the various tools presented. Others are pictures of different equipment. One graphic stood out for me in the Cyberspace Challenges chapter (14). The graphic in question is a neat Venn Diagram that encapsulates all of the Cyber Warfare issues mentioned in the book, categorizes the complexity of each issue and shows where they overlap in terms of Policy, Processes, Organization, Tech, People and Skills. My only ding on the diagram is that in the same chapter, the authors discuss how much each issue might cost to overcome. It would have been very easy to represent that information on the Venn diagram and make it more complete.
One last observation about the graphics that I really liked is the author's use of "Tip" and "Note" boxes throughout the book. Scattered throughout the chapters are grayed-out text boxes that talk about some technology or procedure that is related to the chapter information but not directly. For example, in the Social Engineering chapter (7), the authors placed a "Note" describing the various Phishing forms. You do not need the information to understand the chapter but having it nearby provides the reader with a nice example to solidify the main arguments. The book is full of these examples.
The first three chapters are my favorites. Winterfield and Andress do a good job of wrapping their heads around entangled concepts like the definition of cyber warfare, the look of a cyber battle space and the current doctrine's ideas about cyber warfare from the perspective of various nations. It is fascinating.
In the middle of the book, the authors take on the task of describing the Computer Network Operations (CNO) Spectrum; a spectrum that ranges from the very passive form of Computer Network Defense (CND) through the more active forms of Computer Network Exploitation (CNE) and Computer Network Attack (CNA). It is indeed a spectrum too because the delineation between where CND, CNE and CNA start and stop is not always clean and precise. There is overlap. And somewhere along that same spectrum is where law enforcement organizations and counter-intelligence groups operate. You can get lost fairly quickly without a guide and the authors provide that function admirably. The only thing missing from these chapters is a nice diagram that encapsulates the concept.
Along the way the reader gets a nice primer on the legal issues surrounding Cyber Warfare, the ethics that apply, what it takes to be a cyber warrior and a small glimpse over the horizon about what the future of Cyber Warfare might bring. In the end, Winterfield and Andress get high marks for encapsulating this complex material into an easy-to-understand manual; a foundational document that most military cyber warriors should have at their fingertips and a book that should reside on the shelf of anybody interested in the topic.
Cyber Warfare: Techniques, Tactics and Tools for Security Practitioners Overview

Want to learn more information about Cyber Warfare: Techniques, Tactics and Tools for Security Practitioners?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Cyberpower and National Security (National Defense University) Review

Cyberpower and National Security (National Defense University)
Average Reviews:

(More customer reviews)
Are you looking to buy Cyberpower and National Security (National Defense University)? Here is the right place to find the great deals. we can offer discounts of up to 90% on Cyberpower and National Security (National Defense University). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Cyberpower and National Security (National Defense University) ReviewLast week at the InfowarCon Dan Kuehl handed me a copy of "Cyberpower and National Security." This has been a topic Dan has been exploring in some detail for quite a while. I first met Dan in 1996 when I was a student at the USMC Command and Staff College. Dan was already writing and exploring concepts related to cyber power and information warfare, and his deep focus and insights into this still emerging mission area continues today.
About the book, it is big. Not just in pages (it weighs in at 642 pages). It is big in info. Chapters are written by some of the greatest thinkers of the Cyber War mission area. Folks like Dan Kuehl, Edward Skoudis, Greg Rattray, Martin Libicki, Irving Lachow, Tim Thomas, Tom Wingfield and of course the editors Franklin Kramer, Stuart Starr and Larry Wentz. These and the other contributors are all well respected thought leaders and each provide insights I believe will be of use to today's strategic planners.
As for the content, it starts with a great foundation and overview of what is meant by Cyberspace (building on Dan Kuelh's well articulated definition) and also spells out key issues that policy makers and national security strategists must tackle. It then spells out changes in cyberspace including projections into the near future, and ends with an analysis of the impact of all these changes- including the considerations we must think through in our strategic deliberations.
I now consider this book a critical foundational work that should be studied by anyone who seeks to dialog on modern national security issues. This book does for the strategic domain what the Common Audit Guidelines did for the operational cyber domain. Cyberpower and National Security (National Defense University)Cyberpower and National Security (National Defense University) Overview

Want to learn more information about Cyberpower and National Security (National Defense University)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Windows Forensic Analysis DVD Toolkit, Second Edition Review

Windows Forensic Analysis DVD Toolkit, Second Edition
Average Reviews:

(More customer reviews)
Are you looking to buy Windows Forensic Analysis DVD Toolkit, Second Edition? Here is the right place to find the great deals. we can offer discounts of up to 90% on Windows Forensic Analysis DVD Toolkit, Second Edition. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Windows Forensic Analysis DVD Toolkit, Second Edition ReviewThe second edition of Harlan's book nicely complements the first and is essential reading for practitioners at all levels. For those of us who primarily engage in exams of acquired images, the chapters on Registry Analysis, File Analysis, Executable Analysis, and Rootkit Detection provide and build upon basic concepts that go beyond what is taught in beginning and intermediate computer forensics courses.
The registry analysis chapter is particularly valuable and one that I draw on repeatedly. The accompanying DVD, with its scripts, not only provides tools to gather the data that Harlan describes, but provides a means to learn while you read by taking a hands on approach to registry analysis.
The chapter on file analysis teaches fundamentals of system files and logs that can provide key evidence in an exam. It explains not only what may be found, but how to get it and why it got there. These are the types of issues that can aid immeasurably when it comes to report writing and courtroom testimony. Similarly, the discussions on malware, rootkits, and executables provide guidance and solutions to considerations of whether an uninvited influence played a role in data arriving on, or departing from, a system.
For those who don't engage in incident or live response at the moment, the time is fast approaching when that aspect forensics is going to be vital to us all. Harlan explains what information is available, and he describes the methods and tools with which we can acquire volatile data and access information that's gone once the plug is pulled. Harlan brings together this area of his book with a discussion of analyzing the data.
In sum, this is a great work that is suited to those who have had basic computer forensics training as well as examiners who have been practicing for a long time. Things change every day, and WFA II provides a means to keep pace.
Windows Forensic Analysis DVD Toolkit, Second Edition Overview

Want to learn more information about Windows Forensic Analysis DVD Toolkit, Second Edition?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Gray Hat Hacking The Ethical Hackers Handbook, 3rd Edition Review

Gray Hat Hacking The Ethical Hackers Handbook, 3rd Edition
Average Reviews:

(More customer reviews)
Are you looking to buy Gray Hat Hacking The Ethical Hackers Handbook, 3rd Edition? Here is the right place to find the great deals. we can offer discounts of up to 90% on Gray Hat Hacking The Ethical Hackers Handbook, 3rd Edition. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Gray Hat Hacking The Ethical Hackers Handbook, 3rd Edition ReviewCritical reviews are my least favorite aspect of my Amazon experience, but I believe readers expect me to be honest with them. Gray Hat Hacking, 3rd Ed (GHH3E) has a lot of potential, but it needs a reboot and a ruthless editor. I read and reviewed the original edition 6 1/2 years ago but skipped the 2nd Ed. This 3rd Ed (published in Jan 2011) features several exceptionally talented authors (such as Allen Harper and Chris Eagle), so my expectations remained high. Unfortunately, after finishing the book I had collected a pile of notes that I will try to transform into constructive commentary for a 4th Ed, which I would enjoy seeing!
The GHH team needs to revisit first principles and decide just what it is trying to accomplish. I recommend the authors ditch the first three chapters, or radically concentrate on the ethical disclosure debate. The rest of the so-called legal material reads like a brain dump, almost like a blog post that never finishes. In some cases the authors of the sections stray from their topic, such as the "Vendors Paying More Attention" section on p 71. Cut it out! Be ruthless! Similarly, the section on social engineering (ch 4) needs a major overhaul if it is to survive into the next edition.
Other chapters have issues. Ch 7, on BackTrack, is basically just installation instructions. Ch 17 only devotes 17 pages to Web app security; either remove it or add substantially to the material. Ch 18 is supposed to be about VoIP, but it's mainly a discussion of the VoIPER tool. Ch 19 is supposed to be about SCADA attacks, but it's really just talk of the Autodafe and TFTPFuzz tools. In ch 28, the author doesn't explain how Nepenthes acquires a malware sample, besides letting it run on a cable network for a few weeks. Having deployed Nepenthes I know how it works, but I expect a reader who wants to learn about Nepenthes would want to understand it based on the text he or she bought.
The organization of the book needs an overhaul too. It seems to promote a progress of less complicated to more complicated, but at this point it needs to be reconstructed in a fourth edition. Why does Part IV, Vulnerability Analysis, follow Part III, Exploiting? Doesn't exploiting require doing vulnerability analysis? In other cases, material seems redundant. Ch 28 and ch 29 cover similar material but are likely by different authors; I recommend combining them and dropping duplicate material.
For me, some of the chapters are on the right track and could lead the fourth edition to a more solid foundation. I recommend expanding Ch 16 (featuring nice coverage of a .pdf exploit). I would really like to see a chapter or more on Javascript for malicious purposes. Overall, I think the GHH team could be very successful if they looked for topics not covered in other books, and addressed those issues in GHH4E. Why try to summarize coding in C, assembly, Python, etc., into a chapter, when other subjects (like Javascript for the hacker/analyst) aren't really explained in any other book? Similarly, it's probably not necessary to cover social engineering, BackTrack, or Metasploit now that individual books are devoted to those concepts.
There's a lot of good technical information in GHH3E, but I don't see myself recommending it to analysts in a CIRT or similar group. I think if the book rebooted with a focus on specialized material not found elsewhere, leveraging the talents of people like Harper and Allen, GHH4E would be THE book to buy on those topics.Gray Hat Hacking The Ethical Hackers Handbook, 3rd Edition Overview

Want to learn more information about Gray Hat Hacking The Ethical Hackers Handbook, 3rd Edition?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Malware Analyst's Cookbook and DVD: Tools and Techniques for Fighting Malicious Code Review

Malware Analyst's Cookbook and DVD: Tools and Techniques for Fighting Malicious Code
Average Reviews:

(More customer reviews)
Are you looking to buy Malware Analyst's Cookbook and DVD: Tools and Techniques for Fighting Malicious Code? Here is the right place to find the great deals. we can offer discounts of up to 90% on Malware Analyst's Cookbook and DVD: Tools and Techniques for Fighting Malicious Code. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Malware Analyst's Cookbook and DVD: Tools and Techniques for Fighting Malicious Code ReviewI have just received this book and have not yet worked my way through all the chapters, but I have reviewed the contents and tool DVD. I teach college classes on Network and Computer forensics from a survey level through a hard-core programming level. I have likely purchased or been sent most of the books in this area, and this book does stand out for the following reasons.
1. The material is up-to-date. Tools and malware resources change on an almost daily basis and you need to get books that reflect current resources and best practices. This book does a very good job covering the current tools and resources. It provides the web addresses for the various tools and resources discussed in each chapter. It also refers to current research, articles, and conference material in the areas covered in the chapters.
2. The topics covered are comprehensive. The book includes topics on anonymizing (the first chapter), classifying malware, shellcode, DLL code injection, debugging, how to safely run malware in a virtual environment, dumping memory and memory forensics, debugging kernel code, etc. The topics are collected into 18 chapters and are very complete.
3. The focus of this book is performing analysis of malware (which includes a wide variety of exploit types) and creating/using the tools to perform this analysis. Numerous examples are given showing how the analysis can be done, and some background information is presented as needed.
4. The book assumes the reader has brains. Too many "Computer Forensics" books are a waste of time for someone that already has a background in programming, networking, etc. They (the other Forensics books) often start their discussion of Network Forensics with a definition of what a network is ("A network sends packets between computers..."). Give me a break. This book assumes the reader already has a level of knowledge that is appropriate to anyone really working in this field. However, the authors do a good job explaining what needs to be explained in the course of presenting the topics. They don't talk down to the reader.
5. The book has a wealth of examples. Each chapter presents the topics by showing examples as well as showing how to get and install the necessary tools.
6. The book balances using pre-written tools with create-your-own tools. The latter include scripts in Python and programs in C/C++. The authors indicate where to get various relevant libraries which can be used to create or customize tools. This book is not just a collection of tools, but shows how to use the tools, analysis techniques, etc.
7. The book is very reasonably priced for the quality of content and the extra DVD. The price from Amazon is under $40 and the retail price is about $60. However, even at $60 this book is a bargain. Even if you just used the web addresses for the lists of tools presented in each chapter, the amount of time would take to locate and document the huge number of forensics/hacking tools presented in this book, is worth more than the book's price.
8. The book presents a huge amount of material. Almost every page is crammed with information and examples. Frankly, this book presents more information in one chapter than most other books do in their entirety, and this book has 18 chapters. The chapters are written so they are independent of each other and you can select the chapter you want to work through without reading previous chapters.
9. The tool focus is open-source and platform independent. The authors stay with open-source tools and try to reference tools that can run on both Linux and Windows. However, they also use the best tools available for a specific task, even if the tool only runs under Linux or only under Windows.
Reader Background:
There are enough varied topics in this book that readers with different levels of knowledge can benefit. The authors assume the reader has a background in basic networking, understands operating systems (both Windows and Unix), understands programming (Python, C/C++, Assembly), and understand processor basics (registers, the stack, etc). However, these assumptions are not barriers to getting something out of this book. Beginners will find the book too difficult, but would profit by just downloading the various tools referenced in the chapters.
Bottom line:
* If you are doing forensic analysis on Malware you should purchase this book (for the chapters on debugging, memory forensics, and malware forensics)
* If you are working in the network/computer security area you should purchase this book (for the chapters on setting up a malware lab, classifying malware, and setting up a malware sandbox)
* If you are interested in the programming aspects of malware you should purchase this book (for the chapters on DLLs and debugging malware code and on code injection)
* If (and I hesitate to include this) you want to be a hacker you should purchase this book and read the entire thing.
Malware Analyst's Cookbook and DVD: Tools and Techniques for Fighting Malicious Code Overview

Want to learn more information about Malware Analyst's Cookbook and DVD: Tools and Techniques for Fighting Malicious Code?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...