While researching for my new book The Tao of Network Security Monitoring, I wanted to read articles published in scholarly journals and other academic forums. I found the CiteSeer Scientific Literature Digital Library to be extremely valuable. You can query by keywords or browse collections like Intrusion Detection by date. When you come across a paper with lots of citations, like Intrusion Detection: A Bibliography, they are usually linked. The University of California at Davis offers a Computer Security Archives Project where older but useful papers are kept. I found Todd Heberlein's site archives all of his papers, including those on network security monitoring. Honeypots.net, not part of the Honeynet Project, contains lots of references. Citeseer event mentions a paper I wrote.
Zeek in Action Videos
This is a quick note to point blog readers to my Zeek in Action YouTube video series for the Zeek network security monitoring project . Each video addresses a topic that I think might be of interest to people trying to understand their network using Zeek and adjacent tools and approaches, like Suricata, Wireshark, and so on. I am especially pleased with Video 6 on monitoring wireless networks . It took me several weeks to research material for this video. I had to buy new hardware and experiment with a Linux distro that I had not used before -- Parrot . Please like and subscribe, and let me know if there is a topic you think might make a good video.