Showing posts with label network security. Show all posts
Showing posts with label network security. Show all posts

Voice over Internet Protocol (VoIP) Security Review

Voice over Internet Protocol (VoIP) Security
Average Reviews:

(More customer reviews)
Are you looking to buy Voice over Internet Protocol (VoIP) Security? Here is the right place to find the great deals. we can offer discounts of up to 90% on Voice over Internet Protocol (VoIP) Security. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Voice over Internet Protocol (VoIP) Security Review[note: I am the same reviewer IP_Geek, but Amazon only lets you review once, so this is follow up]
Despite what Dr. Michael G. Mathews may believe, I really wanted to use my real name, and I have never worked for Exodus (although they may have been a customer of one of the companies I worked for, unknown to me). I have worked at 4 networking vendor/manufacturer companies, of which 2 were data vendors (routers/switches) and 2 VoIP companies. I currently work at a vendor who makes VoIP security products, and thus I felt it a bit unfair/dangerous to my employer to critique any book in a public forum. (because you can google my name and find out where I work)
I still feel that way, so I will try to convince you I have no agenda as easily as I can as follows:
1) My argument was simply that you should VERY carefully read the table of contents, including the page numbers. Dr. Mathews is quite right that this type of book will appeal to some people, just that in my humble opinion I hope those people are not put in charge of securing VoIP, because this book doesn't do it. (see below why)
2) I did not slam the authors in person or capabilities - I slammed the book they wrote. This book was published fairly recently (6 months ago), and this book is written from a VoIP perspective of several years ago, in my opinion. It is missing tons, and contains lots of frankly irrelevant content to the subject. If the title of the book "VoIP Security" is not meant to actually mean this is a book about VoIP Security, then I guess I don't understand what book titles are for. The back cover even says "This book will teach you how to plan for and implement VoIP security solutions...". I am taking issue with that statement, not the authors personally.
3) I think some people may like the book, because they are not already experts in VoIP security and thus don't know what they're missing. I believe I am pretty close to an expert. I was looking for a book I could recommend to my customers and colleagues who are not.
4) Dr. Mathews says "It addresses the protocol specifics, the technical issues, and the security options surrounding the protocol." I think that it addresses them if you don't know what they really are. I will tell you what I know is missing from this book:
a) TLS. Much of the VoIP industry believes TLS to be the future panacea for VoIP service security. (it's not used much today, but many are moving that way) That belief is true for eavesdropping protection/privacy, and server-side authentication. It is not true for DoS/DDoS attack protection, or user-side authentication. It is also not true for fraud prevention, and it adds many scalability/performance issues. The reasons for that, how SIP over TLS works at a protocol level, and more interestingly the security issues around it are not addressed in this book. That should be a whole chapter. As a side note, they say TLS requires TCP, which was true until the draft for DTLS came out for TLS over UDP, which has received much publicity in the VoIP security world. It came out in 2003 - long before this book was finished.
b) IPSec. The 3GPP/IMS world and some inter-carrier VoIP peering uses IPSec to secure VoIP, which like TLS only provides some security features/benefits but not others. Used by enterprises it also adds latency to RTP (because they use it in tunnel mode over TCP). I give the authors some credit - they did spend 10 pages on the VPN issues with IPsec (but it's not exactly how 3GPP uses it). I still think this topic should be a whole chapter.
c) SRTP. How SRTP is performed, from a protocol level and hardware/software level, leaves much to be desired. There is in fact much debate in the industry if it is needed at all, how it can be managed, how CALEA can be supported with it, etc. SRTP also does not protect the gateways/phones, and the implementation of it is the critical piece as to whether it's any good at all. The authors spend a couple pages on it - I would probably spend at least half a chapter on it - perhaps by removing the big section on how codecs work (which has virtually no relevance to VoIP security compared to this list). The fact there are different codecs is important, but not the formulas for the plot curves of A-law and u-LAw!
d) S/MIME. Some voip products do it, but most don't, and it breaks some things. Again, the protocol and security issues with S/MIME are not covered in much detail in this book. (although it's covered over at least a few pages, just not enough I think)
e) VoIP Firewalls. One simply cannot lump that into one group. The differences in feature/architecture/functionality between categories of friewalls (not to mention models/brands), and how you use VoIP with them, is so critical I'm literally shocked there isn't a ton more detail on this. Look at other security books for data. There are entire books about just a particular firewall brand. (not that this book should get to that level of detail)
f) STUN/TURN/ICE. They are mentioned briefly, but really these technologies/protocols are another pandora's box of security issues, and should be addressed if crossing NAT's is at all useful for you. Likewise, Session Border Controllers are mentioned briefly in this book, but they are considered by most to be one of the fundamental pieces in VoIP security.
ok, enough time spent. I'm sorry for the length of this reply. Again, this book may appeal to you (to each his own), I just caution you that there is a lot more under the Voip security hood than is mentioned in this book.
I'm sure the authors are good guys - perhaps they wrote this book a long time ago and printing/publishing books is just too much delay to keep up with technology.
(although I'm still struggling to understand how 30 pages of codec waveform detail helps any voip security person)Voice over Internet Protocol (VoIP) Security Overview

Want to learn more information about Voice over Internet Protocol (VoIP) Security?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Deep Packet Inspection (DPI): High-impact Strategies - What You Need to Know: Definitions, Adoptions, Impact, Benefits, Maturity, Vendors Review

Deep Packet Inspection (DPI): High-impact Strategies - What You Need to Know: Definitions, Adoptions, Impact, Benefits, Maturity, Vendors
Average Reviews:

(More customer reviews)
Are you looking to buy Deep Packet Inspection (DPI): High-impact Strategies - What You Need to Know: Definitions, Adoptions, Impact, Benefits, Maturity, Vendors? Here is the right place to find the great deals. we can offer discounts of up to 90% on Deep Packet Inspection (DPI): High-impact Strategies - What You Need to Know: Definitions, Adoptions, Impact, Benefits, Maturity, Vendors. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Deep Packet Inspection (DPI): High-impact Strategies - What You Need to Know: Definitions, Adoptions, Impact, Benefits, Maturity, Vendors ReviewIf you want to support a bogus author and lose your money, then by all means waste your hard-earned money and buy this book. But really, this book is a waste of paper.
This book is nothing but someone going to Wikipedia and doing a big cut and paste.
All the author does is copy from Wikipedia and put in into a digital format. You can do the same thing for free. If you look at the author, he has over 400 titles like this.
The so called author wrote 15 books alone in October 2011. That should tell you about this fraud. All they do it take current topics, go to Wikipedia, cut, paste, and then charge you for it. Any 10-year old could do the same thing.
There is an expose about this author and firm titled 'There's a sucker born every minute - and charlatans to make sure they pay for it' at [...]
The expose writes about how the company published free content and charges you for it.
Not only is this book free, the author uses a lot of filler from other Wiki articles. So you end up with non relevant text.
Do not buy this book. You will just be wasting your cash.
Deep Packet Inspection (DPI): High-impact Strategies - What You Need to Know: Definitions, Adoptions, Impact, Benefits, Maturity, Vendors Overview

Want to learn more information about Deep Packet Inspection (DPI): High-impact Strategies - What You Need to Know: Definitions, Adoptions, Impact, Benefits, Maturity, Vendors?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Single sign-on (Sso): High-impact Strategies - What You Need to Know: Definitions, Adoptions, Impact, Benefits, Maturity, Vendors Review

Single sign-on (Sso): High-impact Strategies - What You Need to Know: Definitions, Adoptions, Impact, Benefits, Maturity, Vendors
Average Reviews:

(More customer reviews)
Are you looking to buy Single sign-on (Sso): High-impact Strategies - What You Need to Know: Definitions, Adoptions, Impact, Benefits, Maturity, Vendors? Here is the right place to find the great deals. we can offer discounts of up to 90% on Single sign-on (Sso): High-impact Strategies - What You Need to Know: Definitions, Adoptions, Impact, Benefits, Maturity, Vendors. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Single sign-on (Sso): High-impact Strategies - What You Need to Know: Definitions, Adoptions, Impact, Benefits, Maturity, Vendors ReviewI was looking on finding a "starter" guide on SSO and found this book. First of all, (Kindle edition) there aren't even a table of contents so I can't even skip around. The 1st page of the book declares that nobody has even reviewed this information for accuracy. It's a bunch of randomly written articles. There is no cohesiveness. There are no "strategies" and even if there were any -- there isn't anything in the book that says they were ever actually implemented anywhere. Absolutely horrible that someone would claim to have even authored and published this. If my review saves anyone from absolutely throwing away $35 on this garbage, then I am glad I wrote it.Single sign-on (Sso): High-impact Strategies - What You Need to Know: Definitions, Adoptions, Impact, Benefits, Maturity, Vendors Overview

Want to learn more information about Single sign-on (Sso): High-impact Strategies - What You Need to Know: Definitions, Adoptions, Impact, Benefits, Maturity, Vendors?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Digital Evidence and Computer Crime, Second Edition Review

Digital Evidence and Computer Crime, Second Edition
Average Reviews:

(More customer reviews)
Are you looking to buy Digital Evidence and Computer Crime, Second Edition? Here is the right place to find the great deals. we can offer discounts of up to 90% on Digital Evidence and Computer Crime, Second Edition. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Digital Evidence and Computer Crime, Second Edition ReviewSometimes, defense attorneys have it easy: one slip-up by the prosecution and evidence is thrown out. Knowing that, law enforcement goes to great lengths to ensure that evidence is appropriately collected and protected. That works well in the physical world, where law enforcement has many generations' worth of experience. But in the modern world of computers and digital networks, where the simple act of rebooting a computer is enough to wipe out large amounts of evidence, law enforcement clearly needs thorough guidance.
Such a resource is here: Digital Evidence and Computer Crime, an excellent book that details the elements of digital crime. Author Eoghan Casey does a superb job of applying forensic science to computers. The information presented here is critical to a diverse audience: law enforcement, attorneys, forensic scientists, and systems administrators, for instance.
While cybercrime law is in some ways similar to other aspects of criminal law, it nonetheless has its own language and categories. For instance, jurisdiction is a key element in both the physical and digital realms, but it is a much trickier concept in the latter. Casey develops this topic and many more. Those new to computers and networks need not worry: the book begins with an explanation of how they function. With the basics out of the way, Casey details how computers can be used in crime and how the evidence created from these activities can be used for later analysis....The accompanying CD-ROM contains simulated cases that integrate many of the topics covered in the text. In all, the book and CD are an excellent introduction to an increasingly important area of law enforcement.Digital Evidence and Computer Crime, Second Edition Overview

Want to learn more information about Digital Evidence and Computer Crime, Second Edition?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Science and Technology of Terrorism and Counterterrorism, Second Edition (Public Administration and Public Policy) Review

Science and Technology of Terrorism and Counterterrorism, Second Edition (Public Administration and Public Policy)
Average Reviews:

(More customer reviews)
Are you looking to buy Science and Technology of Terrorism and Counterterrorism, Second Edition (Public Administration and Public Policy)? Here is the right place to find the great deals. we can offer discounts of up to 90% on Science and Technology of Terrorism and Counterterrorism, Second Edition (Public Administration and Public Policy). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Science and Technology of Terrorism and Counterterrorism, Second Edition (Public Administration and Public Policy) ReviewThe Science and Technology of Terrorism and Counterterrorism examine some topics that you might find in other texts but in a more understandable format and with greater depth. It goes beyond this in that it covers so much more that is unique in a variety of areas such as the theory of terrorism and technology, the group psychology of terrorism, aerosol science, sensors (one of the most complete works on chem., bio and nuclear sensors that I have seen), medical preparedness, training and homeland security infrastructure. It is concise and timely and is written by a distinguished group of scholars with a broad range of expertise to thoroughly cover all of these complex topics.Science and Technology of Terrorism and Counterterrorism, Second Edition (Public Administration and Public Policy) Overview

Want to learn more information about Science and Technology of Terrorism and Counterterrorism, Second Edition (Public Administration and Public Policy)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Cyber Warfare: Techniques, Tactics and Tools for Security Practitioners Review

Cyber Warfare: Techniques, Tactics and Tools for Security  Practitioners
Average Reviews:

(More customer reviews)
Are you looking to buy Cyber Warfare: Techniques, Tactics and Tools for Security Practitioners? Here is the right place to find the great deals. we can offer discounts of up to 90% on Cyber Warfare: Techniques, Tactics and Tools for Security Practitioners. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Cyber Warfare: Techniques, Tactics and Tools for Security Practitioners Review"Cyber Warfare: Techniques, Tactics and Tools for the Security Practitioners" is a consolidation of the current thinking around the topic of cyber warfare; not the way you hear about in the media where everything is a war of some kind (War on drugs, War on Terrorism, etc) but a discussion about what it means to conduct warfare via cyberspace. This is a tough topic because there are so many opinions about what Cyber Warfare is that you could literally spend an entire book just covering the definitions. The authors deftly avoid that trap and manage to provide a coherent line of thinking around Computer Network Operations even when these kinds of activities bump up against other cyber space dangers like Cyber Crime, Cyber Hactavism, Cyber Espionage and Cyber Terrorism. This is a primer; a one stop shop to get you up to speed on the topic if you are new to it or a refresher even if you have been enmeshed in it for years.
'
The authors, Steve Winterfield and Jason Andress, cover everything you will want to consider when thinking about how to use cyberspace to conduct warfare operations. The primary concepts have been bouncing around US military circles for over a decade but they have never been collected into one tome before. Clarke and Knake's book, "Cyber War: The Next Threat to National Security and What to Do about It," discusses how weak the US network defenses are and offers suggestions about how to improve. Carr's book, "Inside Cyber Warfare: Maping the Cyber Underworld," presents threat examples and nation state capabilities. Libicki's book, "Cyberdeterrence and Cybrewar," attacks cyberwar from a policy viewpoint and does not really address operational considerations. Stiennon's book, "Surviving Cyberwar," is a good place to start if you are new to the subject and is almost a prerequisite for this book.
Full Disclosure: One of the authors, Steve Winterfield, used to work for me when he and I were both in the US Army wrestling with all of these ideas right after 9/11. I ran the Army Computer Emergency Response Team (ACERT) and Steve ran the Army's Southern Regional CERT (RCERT South). He and I have been friends ever since and he even quoted me in one of the back chapters.
Although the content has been around for a while, it is striking how little the main concepts have changed. In a world where new innovations completely alter the popular culture every eighteen months, the idea that Cyber Warfare's operational principals remain static year after year is counter-intuitive. After reading through the various issues within though, you begin to understand the glacial pace. These difficult concepts spawn intractable problems and the authors do a good job of explaining them.
I do have a slight issue with the subtitle though: "Techniques, Tactics and Tools for the Security Practitioners." The way I read this book, the general purpose (GP) Security Practitioner will not find this book very useful except as background information. Aside from the chapters on Logical Weapons, Social Networking and Computer Network Defense, most of the material has to do with how a nation state, mostly the US, prepares to fight in cyber space. There is overlap for the GP security practitioner, but this material is covered in more detail in other books.
The book is illustrated. Some of the graphics are right out of military manuals and have that PowerPoint Ranger look about them. Some are screenshots of the various tools presented. Others are pictures of different equipment. One graphic stood out for me in the Cyberspace Challenges chapter (14). The graphic in question is a neat Venn Diagram that encapsulates all of the Cyber Warfare issues mentioned in the book, categorizes the complexity of each issue and shows where they overlap in terms of Policy, Processes, Organization, Tech, People and Skills. My only ding on the diagram is that in the same chapter, the authors discuss how much each issue might cost to overcome. It would have been very easy to represent that information on the Venn diagram and make it more complete.
One last observation about the graphics that I really liked is the author's use of "Tip" and "Note" boxes throughout the book. Scattered throughout the chapters are grayed-out text boxes that talk about some technology or procedure that is related to the chapter information but not directly. For example, in the Social Engineering chapter (7), the authors placed a "Note" describing the various Phishing forms. You do not need the information to understand the chapter but having it nearby provides the reader with a nice example to solidify the main arguments. The book is full of these examples.
The first three chapters are my favorites. Winterfield and Andress do a good job of wrapping their heads around entangled concepts like the definition of cyber warfare, the look of a cyber battle space and the current doctrine's ideas about cyber warfare from the perspective of various nations. It is fascinating.
In the middle of the book, the authors take on the task of describing the Computer Network Operations (CNO) Spectrum; a spectrum that ranges from the very passive form of Computer Network Defense (CND) through the more active forms of Computer Network Exploitation (CNE) and Computer Network Attack (CNA). It is indeed a spectrum too because the delineation between where CND, CNE and CNA start and stop is not always clean and precise. There is overlap. And somewhere along that same spectrum is where law enforcement organizations and counter-intelligence groups operate. You can get lost fairly quickly without a guide and the authors provide that function admirably. The only thing missing from these chapters is a nice diagram that encapsulates the concept.
Along the way the reader gets a nice primer on the legal issues surrounding Cyber Warfare, the ethics that apply, what it takes to be a cyber warrior and a small glimpse over the horizon about what the future of Cyber Warfare might bring. In the end, Winterfield and Andress get high marks for encapsulating this complex material into an easy-to-understand manual; a foundational document that most military cyber warriors should have at their fingertips and a book that should reside on the shelf of anybody interested in the topic.
Cyber Warfare: Techniques, Tactics and Tools for Security Practitioners Overview

Want to learn more information about Cyber Warfare: Techniques, Tactics and Tools for Security Practitioners?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Cyberpower and National Security (National Defense University) Review

Cyberpower and National Security (National Defense University)
Average Reviews:

(More customer reviews)
Are you looking to buy Cyberpower and National Security (National Defense University)? Here is the right place to find the great deals. we can offer discounts of up to 90% on Cyberpower and National Security (National Defense University). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Cyberpower and National Security (National Defense University) ReviewLast week at the InfowarCon Dan Kuehl handed me a copy of "Cyberpower and National Security." This has been a topic Dan has been exploring in some detail for quite a while. I first met Dan in 1996 when I was a student at the USMC Command and Staff College. Dan was already writing and exploring concepts related to cyber power and information warfare, and his deep focus and insights into this still emerging mission area continues today.
About the book, it is big. Not just in pages (it weighs in at 642 pages). It is big in info. Chapters are written by some of the greatest thinkers of the Cyber War mission area. Folks like Dan Kuehl, Edward Skoudis, Greg Rattray, Martin Libicki, Irving Lachow, Tim Thomas, Tom Wingfield and of course the editors Franklin Kramer, Stuart Starr and Larry Wentz. These and the other contributors are all well respected thought leaders and each provide insights I believe will be of use to today's strategic planners.
As for the content, it starts with a great foundation and overview of what is meant by Cyberspace (building on Dan Kuelh's well articulated definition) and also spells out key issues that policy makers and national security strategists must tackle. It then spells out changes in cyberspace including projections into the near future, and ends with an analysis of the impact of all these changes- including the considerations we must think through in our strategic deliberations.
I now consider this book a critical foundational work that should be studied by anyone who seeks to dialog on modern national security issues. This book does for the strategic domain what the Common Audit Guidelines did for the operational cyber domain. Cyberpower and National Security (National Defense University)Cyberpower and National Security (National Defense University) Overview

Want to learn more information about Cyberpower and National Security (National Defense University)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Gray Hat Hacking The Ethical Hackers Handbook, 3rd Edition Review

Gray Hat Hacking The Ethical Hackers Handbook, 3rd Edition
Average Reviews:

(More customer reviews)
Are you looking to buy Gray Hat Hacking The Ethical Hackers Handbook, 3rd Edition? Here is the right place to find the great deals. we can offer discounts of up to 90% on Gray Hat Hacking The Ethical Hackers Handbook, 3rd Edition. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Gray Hat Hacking The Ethical Hackers Handbook, 3rd Edition ReviewCritical reviews are my least favorite aspect of my Amazon experience, but I believe readers expect me to be honest with them. Gray Hat Hacking, 3rd Ed (GHH3E) has a lot of potential, but it needs a reboot and a ruthless editor. I read and reviewed the original edition 6 1/2 years ago but skipped the 2nd Ed. This 3rd Ed (published in Jan 2011) features several exceptionally talented authors (such as Allen Harper and Chris Eagle), so my expectations remained high. Unfortunately, after finishing the book I had collected a pile of notes that I will try to transform into constructive commentary for a 4th Ed, which I would enjoy seeing!
The GHH team needs to revisit first principles and decide just what it is trying to accomplish. I recommend the authors ditch the first three chapters, or radically concentrate on the ethical disclosure debate. The rest of the so-called legal material reads like a brain dump, almost like a blog post that never finishes. In some cases the authors of the sections stray from their topic, such as the "Vendors Paying More Attention" section on p 71. Cut it out! Be ruthless! Similarly, the section on social engineering (ch 4) needs a major overhaul if it is to survive into the next edition.
Other chapters have issues. Ch 7, on BackTrack, is basically just installation instructions. Ch 17 only devotes 17 pages to Web app security; either remove it or add substantially to the material. Ch 18 is supposed to be about VoIP, but it's mainly a discussion of the VoIPER tool. Ch 19 is supposed to be about SCADA attacks, but it's really just talk of the Autodafe and TFTPFuzz tools. In ch 28, the author doesn't explain how Nepenthes acquires a malware sample, besides letting it run on a cable network for a few weeks. Having deployed Nepenthes I know how it works, but I expect a reader who wants to learn about Nepenthes would want to understand it based on the text he or she bought.
The organization of the book needs an overhaul too. It seems to promote a progress of less complicated to more complicated, but at this point it needs to be reconstructed in a fourth edition. Why does Part IV, Vulnerability Analysis, follow Part III, Exploiting? Doesn't exploiting require doing vulnerability analysis? In other cases, material seems redundant. Ch 28 and ch 29 cover similar material but are likely by different authors; I recommend combining them and dropping duplicate material.
For me, some of the chapters are on the right track and could lead the fourth edition to a more solid foundation. I recommend expanding Ch 16 (featuring nice coverage of a .pdf exploit). I would really like to see a chapter or more on Javascript for malicious purposes. Overall, I think the GHH team could be very successful if they looked for topics not covered in other books, and addressed those issues in GHH4E. Why try to summarize coding in C, assembly, Python, etc., into a chapter, when other subjects (like Javascript for the hacker/analyst) aren't really explained in any other book? Similarly, it's probably not necessary to cover social engineering, BackTrack, or Metasploit now that individual books are devoted to those concepts.
There's a lot of good technical information in GHH3E, but I don't see myself recommending it to analysts in a CIRT or similar group. I think if the book rebooted with a focus on specialized material not found elsewhere, leveraging the talents of people like Harper and Allen, GHH4E would be THE book to buy on those topics.Gray Hat Hacking The Ethical Hackers Handbook, 3rd Edition Overview

Want to learn more information about Gray Hat Hacking The Ethical Hackers Handbook, 3rd Edition?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...