Search
 Advanced SearchView Cart   Checkout   
 Location:  Home » Books » Host Integrity Monitoring Using Osiris and SamhainAugust 30, 2008  
Bestsellers
Security Warrior
Computer Security Basics
PC Magazine Fighting Spyware, Viruses, and Malware
Steal This Computer Book 4.0: What They Won't Tell You About the Internet
PC Help Desk in a Book: The Do-it-Yourself Guide to PC Troubleshooting and Repair
Computer Viruses For Dummies
It's Never Done That Before
The Art of Computer Virus Research and Defense (Symantec Press)
Secure Your Network for Free
Protecting Your PC (General Computing Series)
Browse
Books
Computers
Electronics
New Releases
15 Steps to PC Security!
Home Computer Security - Basic Training (Edocster)
Host Integrity Monitoring Using Osiris and Samhain
Host Integrity Monitoring Using Osiris and Samhain
Authors: Brian Wotring, Bruce Potter, Marcus Ranum
Publisher: Syngress
Category: Book

List Price: $44.95
Buy New: $28.21
You Save: $16.74 (37%)
Buy New/Used from $17.95

Avg. Customer Rating: 4.5 out of 5 stars(5 reviews)
Sales Rank: 847657

Media: Paperback
Edition: 1
Number Of Items: 1
Pages: 450
Shipping Weight (lbs): 1.7
Dimensions (in): 9.1 x 7.1 x 0.9

ISBN: 1597490180
Dewey Decimal Number: 004
EAN: 9781597490184
ASIN: 1597490180

Publication Date: June 1, 2005
Release Date: May 1, 2005
Availability: Usually ships in 1-2 business days

Editorial Reviews:

Product Description
Your IDS Just Detected an Attack: Was it Successful? This book is about one of the most crucial aspects of system and security management: host integrity protection. Fundamentally, host integrity protection is all about understanding the changes that occur on your system--friendly or hostile, deliberate or accidental--and understanding the impact of those changes. In other words, it's change control in a potentially hostile environment. Best of all, this book is written by Brian Wotring, who has designed and deployed host integrity monitoring systems, used them, and relied on their results. It's hard to overstate the value of such experience. Books like the one you're holding are the survival kits for the future of computing. They're full of the important clues that you're going to need if you want to be one of the survivors instead of the statistics.

--From the Foreword by Marcus J. Ranum

  • Detect Successful Attacks Determine exactly which attacks successfully compromised your host environment.
  • Download and Run Invaluable Scripts Use real-world scripts and configurations, which have been successfully deployed in enterprise host integrity monitoring solutions.
  • Perform Damage Assessment Understand the extent to which a host was compromised, and learn exactly how the attacker penetrated your defenses.
  • Reduce False Positives Learn how to dramatically reduce false positives, which can obfuscate your valuable, legitimate results.
  • Monitor Your Entire Environment Develop a solution to monitor files, users and groups, the kernel, open network ports, privileged executables, and other runtime elements.
  • Learn the Importance of Proper Planning Gain insight into successful planning, deployment, and administration of a working host integrity monitoring solution.
  • Master Defensive Techniques Learn how to mitigate attacks on the host integrity monitoring system itself.
  • Monitor Log Files and Create Notifications Use Swatch to monitor Osiris and Samhain log files, and create custom notification messages.
  • Establish Audit Trails Create trusted audit trails of activity that can prove invaluable in forensic investigations.

Your Solutions Membership Gives You Access to: A comprehensive FAQ page that consolidates all of the key points of this book into an easy-to-search Web page

"From the Author" Forum where the authors post timely updates and links to related sites

Custom, working scripts from the book.

Downloadable chapters from these best-selling books:

  • Snort 2.1 Intrusion Detection, Second Edition
  • Ethereal Packet Sniffing
  • Nessus Network Auditing
  • Microsoft Log Parser Toolkit

TOC

Chapter 1 Host Integrity

Chapter 2 Understanding the Terrain

Chapter 3 Understanding Threats

Chapter 4 Planning

Chapter 5 Host Integrity Monitoring with Open Source Tools

Chapter 6 Osiris

Chapter 7 Samhain

Chapter 8 Log Monitoring and Response

Chapter 9 Advanced Strategies

Appendix A Monitoring Linksys Devices

Appendix B Extending Osiris and Samhain with Modules

Appendix C Further Reading




Customer Reviews:

4 out of 5 stars Good introduction to Samhain and Osiris   September 30, 2005
  1 out of 2 found this review helpful

This is a solid introduction to Samhain and Osiris. It stars slow with an introduction to the topic and some chapters on process and specification that feel more management level in style. Then there are the chapters that cover the monitoring tools from installation through setup and continued use. The book is well written, but it could use some more illustrations. In particular in the tools chapters which are really at the heart of the book.


5 out of 5 stars HIGHLY RECOMMENDED   September 7, 2005
  1 out of 3 found this review helpful

The information necessary for you to understand the what, why, and how of host integrity monitoring, can be found in this book. Authors Brian Wotring, Bruce Potter, Rainer Wichmann and Marcus Ranum, have done an outstanding job of providing you with a book that walks you through the entire process of establishing host integrity monitoring, including the fundamentals, understanding threats, planning, deployment, administration and response.

Wotring, Potter, Wichmann and Ranum begin by revealing everything that is involved in maintaining the integrity of your hosts. Next, the authors explore the many areas of the host environment with respect to establishing an effective host integrity monitoring system (HIMS). Then, they examine some of the most common threats to the integrity of a host environment. The authors continue by walking you through the process of planning the deployment of a HIMS. In addition, the authors next introduce you to Osiris and Samhain. They also provide in-depth practical information about how to properly deploy, configure, and administer the Osiris HIMS. The authors next deal with life after deployment. Finally, they outline some progressive techniques that can be used to strengthen and fine-tune your host integrity monitoring deployment.

With the preceding in mind, the authors have done an excellent job of providing the readership with a book that shows what is involved in planning and deploying an effective host integrity monitoring system. At the end of the day, you'll learn the importance of monitoring various elements of the host environment, how to plan for deployment, and how to interpret and respond to integrity violations.



4 out of 5 stars When did this happen, and where else is this going on in you domain?   September 6, 2005
  1 out of 2 found this review helpful

Host integrity monitoring is the process by which system and network administrators validate and enforce the security of their systems. This can be a complex suite of approaches, tools, and methodologies, and it can be as simple as looking at loggin output. In the past, tools like Tripwire were used to check the configurations on hosts. The freeware version of this tool was limited in its manageability, which was available mainly in the commercial version.

Tools like Osiris and Samhain came along to fill the gap and have since evolved into mature projects themselves. Like any existing software tool out there, any new book should be evaluated not only on its own but also in he context of the existing documentation. Both Osiris and Samhain have decent amounts of documentation available already (Samhain seems to have a larger user documentation repository online than the Osiris tool does), and the book contributes to these docs quite well.

Host Integrity Monitoring shows you how to set up these tools and put them into production on Windows, UNIX, and OS X. Wotring's writing is fairly good, and his examples are usually pretty clear. The pace of the material is good, and there's not a whole lot of domain-specific expertise beyond system administration skills required to make use of the book. At times some of the formatting of the text gets in the way, but that's trivial compared to the quality of writing (which is pretty good).

Overall the material in the book is decent. The book opens with an overview of what host integrity monitoring is, why you should use it, and some of the basic premises. Then it goes on to discuss Samhain and Osiris, starting with their basic installation and then on to their advanced usage. They differ enough that each project merits its own pieces of documentation, even though they're similar in spirit. You'll learn how to schedule scans, integrate with other tools like Swatch, and in general administer a site installation.

The author of the book, Brian Wotring, is also the author of Osiris and is clearly more familiar with Osiris than he is with Samhain. More material (100 pages) is devoted to using Osiris than is given to Samhain (60 pages), which is to be expected. The coverage of both is sufficient, though, and fills the major parts of the book.

There are three major strengths to this book over the existing docs. The first is seeing not just the tools themselves covered but also the threats they cover in place. The second is having the two tools covered side by side, allowing you to see how to accomplish the same task with each. And thirdly, there are two appendices that are true gems of this book. The first covers how to get your Linksys Linux based AP device monitored using the Osiris tool, which isn't a small feat. The second is how to write your own modules for Osiris and Samhain, for which this appears to be the only documentation for Osiris (Samhain's website has a How To on writing modules). Again, these add value to the book over the freely available documentation.

I would have liked to have seen the chapters devoted specifically to Osiris and Samhain, chapters 6 (Osiris) and 7 (Samhain) broken up into two or three chapters covering their installation and use. The length of these chapters can make finding some material difficult at times. I would have also have liked to see the use of the "bold is input, normal text is output" technical book convention. In many examples finding the user input text can be challenging.

Host Integrity Monitoring Using Osiris and Samhain is not only about these tools but about how to accomplish host integrity monitoring on the cheap (since the code is freely available). While you can find docs on each project, this book complements those docs nicely and provides a nicely wrapped package about how to get the most out of each tool. If you've been thinking about how to ensure that no one is tampering with your system, these tools, and this book, should definitely make your solutions list.



4 out of 5 stars Excellent one-of-a-kind book on an overlooked security discipline   August 8, 2005
  7 out of 9 found this review helpful

Host Integrity Monitoring Using Osiris and Samhain (HIM) is an excellent book on a frequently overlooked security discipline. Most people who hear about host integrity monitoring nod their heads and agree that performing it is a good idea. These same people usually don't implement HIM, and frequently cannot count the number of hosts, operating systems, and applications working in their enterprise. Thankfully, HIM provides a way to use open source tools to help remedy this situation. Consistent with the Visible Ops methodology, HIM provides guidance on how to keep track of host integrity.

When writing HIM, author Brian Wotring could have easily concentrated on the program he coded -- Osiris. Luckily for readers, Brian chose to address his program and another open source host integrity monitor -- Samhain. By comparing and contrasting these two programs, readers learn more about each and understand the capabilities and limitations of each application's approach to the HIM problem. Consistent with this dual methodology, Brian explains how to install Osiris on both Unix and Windows platforms. (Samhain is mainly a Unix solution.)

The first third of the book provides background information on HIM rationales and planning. I was initially inclined to skip ahead, but I found the explanations of monitoring various system elements to be helpful. Brian's view of security closely mirrors my own, but he approaches it from a host-centric view. He still accepts that prevention eventually fails and that preparation for incident response is a necessity, not a luxury. Brian also correctly uses the term "threat" and recognizes threats are not vulnerabilities. Bravo.

The middle third and some of the final third of the book deal exclusively with installing and configuring Osiris and Samhain. The instructions are wise and very thorough. I was impressed by guidance on how to compile and install Osiris on Windows from source, using MinGW and MSYS. I also liked the book's frequent use of FreeBSD as a Unix reference platform.

I found a few minor issues with HIM, and one major drawback that prevented a five star review. First, I disagree with the statement on p 19 that "most attacks originate from within the network by authorized users." The annual CSI/FBI study has repeatedly shown this to not be true; rather, insider attacks, when they do occur, are typically more damaging that those perpetrated by outsiders. Second, I found some minor rough editing, e.g. "Nimbda" repeatedly used in place of "Nimda." Third, and most important, it would have been extremely helpful to have shown case studies of Osiris and Samhain in action when detecting configuration changes and/or intrusions. I left the book with a lot of ideas on installation and configuration, but it would have been helpful to see case studies on using host-based data to identify intrusions.

I am adding HIM to my recommended reading list for system administrators. HIM gives administrators the documentation and theory they need to add another critical tool to their security arsenal. I would like to see a second edition that adds case studies, and perhaps chapters on using Radmind for open source change management.



5 out of 5 stars Everything you need to know, nothing you don't   July 18, 2005
  4 out of 6 found this review helpful

What a breath of fresh air! Wotring and Potter take the reader from a definition of integrity monitoring and fundamental principles to the pragmatic "how to" implement a monitoring capability - step by step. They clearly have a wealth of experience shown by their tips on what to do and what not to do. If you are considering Osiris or Samhain, this book is invaluable! The time you save and the capability you develop will pay for the book many times over!

Powered by: Dknc, inc. and Amazon.com


For your safety and security, orders are processed through amazon.com