Posts

Showing posts with the label writing

I Wrote a New Book for Corelight

Image
TLDR: I wrote a new book for Corelight called NDR Essentials . It's free at that link. This is the 10th book that I've authored or co-authored. The rest are all posted at taosecurity.com .    Why? It was time . That’s what I thought when I heard that Corelight wanted to update its 2021 book on network detection and response (NDR). Tamara Crawford, who owned the project, scheduled a meeting with me and asked if I might be interested in helping, depending on who might write the text. I volunteered immediately to write the whole book, but I had a few conditions. The text had to be at least 100 pages long, because 100 pages is my personal dividing line between “book” and “white paper.” I needed the freedom to cover the topics I wanted to address, and to not be told what to write. I wanted to show the four network security monitoring (NSM) data types working in a vendor-neutral manner, with technical details. Finally, I knew this project would take several month...

My First Book Is 20 Years Old Today

Image
On this day in 2004, Addison-Wesley/Pearson published my first book, The Tao of Network Security Monitoring: Beyond Intrusion Detection . This post from 2017 explains the differences between my first four books and why I wrote Tao .  Today, I'm always thrilled when I hear that someone found my books useful.  I am done writing books on security, but I believe the core tactics and strategies in all my books are still relevant. I'm not sure that's a good thing, though. I would have liked to not need the tactics and strategies in my book anymore. "The Cloud," along with so many other developments and approaches, was supposed to have saved us by now. Consider this statement from a report describing CISA’s red team against a fed agency:  “[A]ttempts to capture forensic data via packet captures occurred directly on the compromised Solaris and Windows hosts, where the red team observed the data being collected and therefore had the opportunity to disrupt collection, tam...

Notes on Self-Publishing a Book

Image
In this post I would like to share a few thoughts on self-publishing a book , in case anyone is considering that option. As I mentioned in my post on  burnout , one of my goals was to publish a book on a subject other than cyber security. A friend from my Krav Maga school, Anna Wonsley , learned that I had  published several books , and asked if we might collaborate on a book about stretching. The timing was right, so I agreed. I published my first book with Pearson and Addison-Wesley in 2004, and my last with No Starch in 2013. 14 years is an eternity in the publishing world, and even in the last 5 years the economics and structure of book publishing have changed quite a bit. To better understand the changes, I had dinner with one of the finest technical authors around, Michael W. Lucas . We met prior to my interest in this book, because I had wondered about publishing books on my own. MWL started in traditional publishing like me, but has since become a full-time ...

Latest Book Inducted into Cybersecurity Canon

Image
Thursday evening Mrs B and I were pleased to attend an awards seminar for the Cybersecurity Canon . This is a project sponsored by Palo Alto Networks and led by Rick Howard. The goal is "identify a list of must-read books for all cybersecurity practitioners." Rick reviewed my fourth book The Practice of Network Security Monitoring in 2014 and someone nominated it for consideration in 2016. I was unaware earlier this year that my book was part of a 32-title "March Madness" style competition . My book won the five rounds, resulting in its conclusion in the 2017 inductee list! Thank you to all those that voted for my book. Ben Rothke awarded me the Canon trophy. Ben Rothke interviewed me prior to the induction ceremony. We discussed some current trends in security and some lessons from the book. I hope to see that interviewed published by Palo Alto Networks and/or the Cybersecurity canon project in the near future. In my acceptance speech I explained how ...

Pre-Order The Practice of Network Security Monitoring Before Price Hike

Image
When my publisher and I planned and priced my new book The Practice of Network Security Monitoring , we assumed the book would be about 250 pages. As we conclude the copyediting process and put print in layout format, it's clear the book will be well over 300. The current estimate is 328, but I think it could approach 350 pages. Because of the much larger page count, the publisher and I agreed to reprice the book. The price will rise from the current list of $39.95 for paperback and $31.95 for ebook to $49.95 for paperback and $39.95 for ebook. However, those prices will not go into effect until next Friday, June 21st. That means if you preorder at the NoStarch.com Web site before next Friday, you will get the current lower prices. Furthermore, use preorder code NSM101 to save 30% off list. If you use NSM101 as your discount code it shows No Starch that you got word of this from me. Those of you who already preordered have already taken advantage of this deal. Thanks for ...

Practice of Network Security Monitoring Table of Contents

Image
Since many of you have asked, I wanted to provide an updated Table of Contents for my upcoming book, The Practice of Network Security Monitoring . The TOC has only solidified in the last day or so. I delayed responding until I completed all of the text, which I did this weekend. You can preorder the book through No Starch . Please consider using the discount code NSM101 to save 30%. I'm still on track to publish by July 22, 2013, in time to teach two sessions of my new course, Network Security Monitoring 101 , in Las Vegas. I'll be using the new book's themes for inspiration but will likely have to rebuild all the labs. I expect the book to approach the 350 page mark, exceeding my initial estimates for 256 pages and 7 chapters. Here's the latest Table of Contents. Part I, “Getting Started,” introduces NSM and how to think about sensor placement. Chapter 1, “NSM Rationale,” explains why NSM matters, to help you gain the support needed to deploy NSM in your envi...

Practical Network Security Monitoring Book on Schedule

Image
First the good news: my new book Practical Network Security Monitoring is on track, and you can pre-order with a 30% discount using code NSM101 . I'm about 1/3 of the way through writing the book. Since I announced the project last month, I've submitted chapters 1, 2, and 3. They are in various stages of review by No Starch editors and my technical editors. I seem to be writing more than I expected, despite trying to keep the book at an introductory level. I find that I want to communicate the topic sufficiently to make my point, but I try to avoid going too deeply into related areas. I'm also encountering situations where I have to promise to explain some concepts later, rather than explain everything immediately. I believe once I get the first chapter ironed out with the editor, the rest will be easier to digest. I'm taking a fairly methodical approach (imagine that), so once the foundation in chapter 1 is done the rest is more straightforward. I'm keeping a...

How to Win This TCP/IP Book

Image
Last week I wished this blog happy tenth birthday and announced plans for a new book on network security monitoring . I also mentioned a contest involving a book give-away. I finally figured out a good way to select a winner, and it involves your participation in my current writing project! Thanks to No Starch Press I have a brand-new, shrink-wrapped copy of The TCP/IP Guide , a mammoth 1616 page hardcover book by Charles M. Kozierok. Here's what you have to do to try to win this book: submit a case study on how network security monitoring helped you detect, respond to, and contain an intrusion in your environment . You don't have to reveal your organization, but I want to know some general information like the number of users and computers. Readers need to know the sort of environment where NSM worked for you, but I don't want you to reveal your organization (unless you want to). Tell the reader what happened, what NSM data you used, how you used it, and how you ha...

Bejtlich's New Book: Planned for Summer Publication

Image
Nearly ten years after I started writing my first book , the Tao of Network Security Monitoring , I'm pleased to announce that I just signed a contract to write a new book for No Starch titled Network Security Monitoring in Minutes . From the book proposal: Network Security Monitoring in Minutes provides the tactics, techniques, and procedures for maximum enterprise defense in a minimum amount of time. Network Security Monitoring (NSM) is the collection, analysis, and escalation of indications and warnings to detect and respond to intrusions. Network Security Monitoring in Minutes teaches information technology and security staff how to leverage powerful NSM tools and concepts immediately. Using open source software and vendor-neutral methods, the author applies lessons he first began applying to military networks in 1998. After reading this book, the audience will be able to integrate the same winning approaches to better defend his or her company’s data and networks. Net...

Tactical Traffic Assessment

When I wrote Extrusion Detection in 2004-5 I used the term Traffic Threat Assessment to describe a means of inspecting network traffic for signs of malicious activity. I differentiated among various assessments using this terminology. A vulnerability assessment identifies vulnerabilities and exposures in assets. A penetration test identifies at least one way that an adversary could exploit vulnerabilities and exposures to compromise a target or satisfy a related objective. A traffic threat assessment identifies traffic that indicates a network has already been compromised. The goal of the customer determined which of the actions to perform. I was not really comfortable with the term "traffic threat assessment," so I'm going to use Tactical Traffic Assessment starting now. That definition for TTA nicely differentiates between a short-term, focused, tactical effort and a long-term, enterprise-wide, strategic program like Network Security Monitoring. Tactical Traffic A...

Is It NSM If...

Image
Frequently I'm asked about the data sources I cite as being necessary for Network Security Monitoring, namely statistical data, session data, full content data, and alert data. Sometimes people ask me "Is it NSM if I'm not collecting full content?" or "Where's the statistical data in Sguil? Without it, is Sguil a NSM tool?" In this post I'd like to address this point and answer a question posted as a comment Joe left on my post My Investigative Process Using NSM . In 2002 while working for Foundstone, I contributed to the fourth edition of Hacking Exposed , pictured at left. On page 2 I defined NSM as the collection, analysis, and escalation of indications and warning to detect and respond to intrusions . Since then I've considered modifying that definition to emphasize the traffic-centric approach I intended to convey by using the term "network." Whenever I speak or write about NSM I emphasize the four types of network data mos...

Bejtlich Book Signing Thursday 1230 in DC

Image
I will attend a book signing event at USENIX LISA 06 at the Wardman Park Marriott Hotel in Washington DC from 1230-1330 on Thursday 7 December. Representatives from Reiters will be selling books there as part of the conference expo from 1000-1400 on Thursday. Please stop by to say hello if you'd like a book signed. I'll return to LISA on Friday to teach Network Security Monitoring with Open Source Tools . You can still sign up onsite if you'd like to attend. Thank you.

Extrusion Detection Sightings

Image
I've noticed the term extrusion detection appearing more frequently, usually tied to the latest buzzphrase -- "insider threat." The GSA -loving magazine Federal Computer Weekly recently mentioned the following: Emerging tools known as extrusion-detection systems are helping government agencies and private companies detect whether sensitive information is leaving their organizations... “Our goal is to monitor traffic from the inside going out,” said Daniel Hedrick, product manager at Vericept and a former intelligence officer in the Air Force. “If I see content going out the door, with or without the approval or the knowledge of the user, I will automatically encrypt it.” (emphasis added) Wow, that's something. So once this "content" is "encrypted," what does the intended recipient do with it? I'm hoping this is an example of a writer misreporting Mr. Hedrick's answers to questions. I mildly dislike seeing terms become hyphenated (e.g...

Chapter 3 from Extrusion Online

Image
In addition to Chapter 18 from Tao , I noticed Chapter 3 from my third book , Extrusion Detection: Security Monitoring for Internal Intrusions is also online at SearchSecurityChannel.com . This book has been getting some attention because it starts with the premise that your internal network is compromised. Given that assumption, how do you detect, contain, and eradicate intruders on your network? The model applies well to insider and outsider threats. I consider Extrusion to be a companion volume to Tao , and as such I recommend reading Tao first and then Extrusion . Real Digital Forensics is a book where network security monitoring, network incident response, and network forensics are intergrated with host- and memory-centric security operations.

Chapter 18 from Tao Online

Image
With the launch of the new SearchSecurityChannel.com site, I can report that chapter 18 of my first book , The Tao of Network Security Monitoring: Beyond Intrusion Detection is now available online . Chapter 18 is "Tactics for Attacking Network Security Monitoring." It outlines technical means attackers may degrade or deny operations to detect and respond to intrusions. Keep an eye on SearchSecurityChannel.com . I am working with the editor on a plan to contribute regular content for the site.

Keith Jones Podcast on Real Digital Forensics

Image
Keith Jones was interviewed about our book Real Digital Forensics . The site conducting the interview is Let's Talk Computers . You can reach the audio in Real Audio or Windows Media format here . You can tell this interviewer has been around the block. He actually broadcasts on real AM and FM radio . The whole interview is about 13 minutes long and very informative.

Tuning Snort Article in Sys Admin Magazine

Keep an eye on your local news stands or mail box for the August 2006 issue of Sys Admin magazine. They published an article I wrote titled Tuning Snort . I describe simple steps one should take with Snort to reduce the number of unwanted alerts. I used a beta of Snort 2.6.0 when writing the article a few months ago.

New Review of Extrusion Detection Posted

Image
Tony Stevenson wrote a very thorough review of my newest book , Extrusion Detection: Security Monitoring for Internal Intrusions . Tony really seems to understand this book, unlike the author of a recent review for Information Security magazine who completely missed the point of Extrusion . Tony writes in his review in Windows IT Library : While it is true that his latest book can be read in isolation from the previous one, I agree with Bejtlich when he says, "in many ways, Extrusion Detection is an attempt to extend The Tao to the addressing of internal threats." By reading both books, and by rigorously applying the strategies that are described within them, it becomes possible to significantly increase the odds in your favor of not having your company's systems violated, either from an external threat or from an internally generated attack.

IA Newsletter Article Posted

The Defense Technical Information Center houses a group called the Information Assurance Technology Analysis Center . IATAC publishes the IA Newsletter . I recently learned that an article I wrote, Network Security Monitoring: Beyond Intrusion Detection , was published in Volume 8, No. 4 (.pdf). I wrote it as a response to an earlier article called The Future of Network Intrusion Detection in Volume 7, No. 3 (.pdf). This earlier article preached the common idea that intrusion prevention systems are the future of network intrusion detection. Read my article for an alternative opinion.

Bejtlich FreeBSD Article in February Sys Admin Magazine

The February 2006 issue of Sys Admin magazine features an article I wrote called Keeping FreeBSD Up to Date . This article represents my latest opinions on the matter, and where possible supersedes my previous work on the subject. If you administer any Unix systems, or you want to know more about Unix, I highly recommend subscribing to Sys Admin. I don't know of another multi-Unix, multi-topic magazine like it. Every issue has at least one article on a subject I need to understand. In a world where magazine racks are dominated by Windows-centric rags, I like supporting Sys Admin!