First published 2017
Michael Collins faces a world where hackers have evolved beyond traditional defenses. The security researcher knows that standard intrusion detection systems and basic logfile reviews cannot stop today's sophisticated attacks on complex networks. Collins develops new methods for gathering and examining network traffic data to understand how systems are actually being used. He organizes his approach into three core areas: collecting and structuring data, deploying analysis tools, and applying different analytical methods to real scenarios. Collins explores active monitoring techniques, traffic manipulation detection, and insider threat identification. He incorporates data mining approaches, regression analysis, and machine learning algorithms into his defensive toolkit. Collins shows InfoSec teams how to move beyond reactive security measures toward proactive network hardening based on solid data analysis.
Genres: science, non-fiction, technology, information-science, computer-science, algorithms
Vibes: fast-paced, suspenseful, thought-provoking
Tropes: investigative-journalism, problem-solving
428 pages · Paperback · O'Reilly Media