Book Image

Instant OSSEC Host-based Intrusion Detection System

By : Brad Lhotsky
Book Image

Instant OSSEC Host-based Intrusion Detection System

By: Brad Lhotsky

Overview of this book

Security software is often expensive, restricting, burdensome, and noisy. OSSEC-HIDS was designed to avoid getting in your way and to allow you to take control of and extract real value from industry security requirements. OSSEC-HIDS is a comprehensive, robust solution to many common security problems faced in organizations of all sizes. "Instant OSSEC-HIDS" is a practical guide to take you from beginner to power user through recipes designed based on real- world experiences. Recipes are designed to provide instant impact while containing enough detail to allow the reader to further explore the possibilities. Using real world examples, this book will take you from installing a simple, local OSSEC-HIDS service to commanding a network of servers running OSSEC-HIDS with customized checks, alerts, and automatic responses. You will learn how to maximise the accuracy, effectiveness, and performance of OSSEC-HIDS' analyser, file integrity monitor, and malware detection module. You will flip the table on security software and put OSSEC-HIDS to work validating its own alerts before escalating them. You will also learn how to write your own rules, decoders, and active responses. You will rest easy knowing your servers can protect themselves from most attacks while being intelligent enough to notify you when they need help! You will learn how to use OSSEC-HIDS to save time, meet security requirements, provide insight into your network, and protect your assets.
Table of Contents (7 chapters)

About the Reviewers

JB Cheng has over 20 years' experience in the networking and security industry. His professional experiences include working for the IBM RTP Network Management Division, AT&T Wireless Data Division, and WatchGuard Unified Threat Management appliance development group. Since 2007, he has joined Trend Micro as a Senior Staff Engineer and is currently the OSSEC project manager responsible for OSSEC releases and for engaging with the open source community. His personal blog can be found at http://ossec-notebook.blogspot.com/.

Scott Miller is a Linux administrator, security professional, and IT professional in Raleigh, North Carolina. His expertise includes system administration, Apache/nginx, Amazon web services, security, and Linux. He has worked in large-scale academia IT environments as well as in the enterprise private sector in mission-critical environments. Currently employed at MetaMetrics, Inc. in Durham, NC, He has previously worked for Qualys, UC Davis, and UC Berkeley. Scott is a contributor to many online IT blogs and outlets.

Mark Stanislav is the security evangelist for Duo Security, an Ann Arbor, Michigan-based start-up focused on two-factor authentication and mobile security. With a career spanning a decade, he has worked within small businesses, academia, start-up, and corporate environments primarily focused on Linux architecture, information security, and web application development. He holds a Bachelor's degree in Networking and IT Administration and a Master's in Technology Studies focused on Information Assurance, both from Eastern Michigan University. He also holds his CISSP, Security+, Linux+, and CCSK certifications.