Buy New
-
To see product details, add this item to your cart.
Ships from: Amazon.com Sold by: Amazon.com
Buy New
-
To see product details, add this item to your cart.
Ships from: Amazon.com
Sold by: Amazon.com
Used - Good
-
To see product details, add this item to your cart.
Ships from: True Oak Books Sold by: True Oak Books
Used - Good
-
To see product details, add this item to your cart.
Ships from: True Oak Books
Sold by: True Oak Books
Download the free Kindle app and start reading Kindle books instantly on your smartphone, tablet, or computer - no Kindle device required.
Read instantly on your browser with Kindle for Web.
Using your mobile phone camera - scan the code below and download the Kindle app.
Follow the author
Get new release updates & improved recommendations
Something went wrong. Please try your request again later.
OK
The Practice of Network Security Monitoring: Understanding Incident Detection and Response
Sorry, there was a problem loading this page. Try again.
Purchase options and add-ons
Network security is not simply about building impenetrable walls—determined attackers will eventually overcome traditional defenses. The most effective computer security strategies integrate network security monitoring (NSM): the collection and analysis of data to help you detect and respond to intrusions.
In The Practice of Network Security Monitoring, Mandiant CSO Richard Bejtlich shows you how to use NSM to add a robust layer of protection around your networks—no prior experience required. To help you avoid costly and inflexible solutions, he teaches you how to deploy, build, and run an NSM operation using open source software and vendor-neutral tools.
You'll learn how to:
–Determine where to deploy NSM platforms, and size them for the monitored networks
–Deploy stand-alone or distributed NSM installations
–Use command line and graphical packet analysis tools, and NSM consoles
–Interpret network evidence from server-side and client-side intrusions
–Integrate threat intelligence into NSM software to identify sophisticated adversaries
There’s no foolproof way to keep attackers out of your network. But when they get in, you’ll be prepared. The Practice of Network Security Monitoring will show you how to build a security net to detect, contain, and control them. Attacks are inevitable, but losing sensitive data shouldn't be.
In The Practice of Network Security Monitoring, Mandiant CSO Richard Bejtlich shows you how to use NSM to add a robust layer of protection around your networks—no prior experience required. To help you avoid costly and inflexible solutions, he teaches you how to deploy, build, and run an NSM operation using open source software and vendor-neutral tools.
You'll learn how to:
–Determine where to deploy NSM platforms, and size them for the monitored networks
–Deploy stand-alone or distributed NSM installations
–Use command line and graphical packet analysis tools, and NSM consoles
–Interpret network evidence from server-side and client-side intrusions
–Integrate threat intelligence into NSM software to identify sophisticated adversaries
There’s no foolproof way to keep attackers out of your network. But when they get in, you’ll be prepared. The Practice of Network Security Monitoring will show you how to build a security net to detect, contain, and control them. Attacks are inevitable, but losing sensitive data shouldn't be.
- ISBN-101593275099
- ISBN-13978-1593275099
- EditionIllustrated
- PublisherNo Starch Press
- Publication dateJuly 15, 2013
- LanguageEnglish
- Dimensions7.01 x 0.75 x 9.25 inches
- Print length376 pages
Frequently bought together

This item: The Practice of Network Security Monitoring: Understanding Incident Detection and Response
$50.85$50.85
Get it Sep 28 - 30
In stock
Usually ships within 3 to 4 days.
$41.10$41.10
Get it as soon as Wednesday, Oct 7
Sold by MYROSEGARDEN LLC and ships from Amazon Fulfillment.$37.46$37.46
Get it as soon as Monday, Sep 21
In Stock
Total price: $00$00
To see our price, add these items to your cart.
Try again!
Added to Cart
Some of these items ship sooner than the others.
Choose items to buy together.
Customers who viewed this item also viewed
Page 1 of 1 Start over
- Practical Packet Analysis, 3rd Edition: Using Wireshark to Solve Real-World Network ProblemsPaperbackGet it as soon as Wednesday, Oct 7
- How Cybersecurity Really Works: A Hands-On Guide for Total BeginnersPaperbackFREE Shipping on orders over $35 shipped by AmazonGet it as soon as Sunday, Sep 20
- Linux Basics for Hackers, 2nd Edition: Getting Started with Networking, Scripting, and Security in KaliPaperbackFREE Shipping on orders over $35 shipped by AmazonGet it as soon as Sunday, Sep 20
- Blue Team Handbook: Incident Response, 3rd Edition: A condensed field guide for the Cyber Security Incident Responder.PaperbackFREE Shipping by AmazonGet it as soon as Monday, Sep 21
- Cybersecurity for Small Networks: A Guide for the Reasonably ParanoidPaperbackFREE Shipping by AmazonGet it as soon as Sunday, Sep 20Only 20 left in stock (more on the way).
Customers also bought or read
Page 1 of 1Start over
- Practical Packet Analysis, 3rd Edition: Using Wireshark to Solve Real-World Network Problems
Paperback$41.10$41.10FREE delivery Oct 7 - 14 - Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software
Paperback$47.26$47.26FREE delivery Mon, Sep 21 - Linux Basics for Hackers, 2nd Edition: Getting Started with Networking, Scripting, and Security in Kali
Paperback$22.30$22.30Delivery Sun, Sep 20 - How Linux Works, 3rd Edition: What Every Superuser Should Know#1 Best SellerLinux Servers
Paperback$34.49$34.49Delivery Sun, Sep 20 - How Cybersecurity Really Works: A Hands-On Guide for Total Beginners
Paperback$34.97$34.97Delivery Sun, Sep 20 - The TCP/IP Guide: A Comprehensive, Illustrated Internet Protocols Reference#1 Best SellerEmail Administration
Hardcover$79.41$79.41FREE delivery Sun, Sep 20 - Applied Network Security Monitoring: Collection, Detection, and Analysis
Paperback$37.46$37.46FREE delivery Mon, Sep 21 - Cybersecurity for Small Networks: A Guide for the Reasonably Paranoid
Paperback$36.40$36.40FREE delivery Sun, Sep 20 - The Linux Command Line, 3rd Edition: A Complete Introduction#1 Best SellerLinux & UNIX Administration
Paperback$27.94$27.94Delivery Sun, Sep 20 - Blue Team Handbook: SOC, SIEM, and Threat Hunting (V1.02): A Condensed Guide for the Security Operations Team and Threat Hunter
Paperback$21.78$21.78Delivery Sun, Sep 20 - The Tao Of Network Security Monitoring: Beyond Intrusion Detection
Paperback$27.00$27.00Delivery Tue, Sep 22 - Learn PowerShell in a Month of Lunches, Fourth Edition: Covers Windows, Linux, and macOS#1 Best SellerMicrosoft .NET
Paperback$39.99$39.99FREE delivery Sun, Sep 20 - The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
Paperback$28.91$28.91Delivery Sun, Sep 20 - TCP/IP Illustrated: The Protocols, Volume 1 (Addison-Wesley Professional Computing Series)#1 Best SellerTCP-IP
Hardcover$64.49$64.49FREE delivery Mon, Sep 21 - Attacking Network Protocols: A Hacker's Guide to Capture, Analysis, and Exploitation
Paperback$44.10$44.10FREE delivery Oct 3 - 7 - Practical Linux Forensics: A Guide for Digital Investigators
Paperback$41.13$41.13$3.99 delivery Sep 28 - Oct 2 - Linux Basics for Hackers: Getting Started with Networking, Scripting, and Security in Kali
Paperback$40.85$40.85FREE delivery Sep 28 - Oct 1 - Practical Vulnerability Management: A Strategic Approach to Managing Cyber Risk
Paperback$29.06$29.06Delivery Sun, Sep 20 - Wireshark Network Analysis (Second Edition): The Official WCNA Study Guide (Chappell University Solution)
Paperback$109.85$109.85FREE delivery Sep 28 - 30 - Security Engineering: A Guide to Building Dependable Distributed Systems
Hardcover$47.55$47.55$3.99 delivery Sep 24 - 30 - Effective Threat Investigation for SOC Analysts: The ultimate guide to examining various threats and attacker techniques using security logs
Paperback$41.99$41.99FREE delivery Mon, Sep 21 - The Ultimate Kali Linux Book: Harness Nmap, Metasploit, Aircrack-ng, and Empire for cutting-edge pentesting
Paperback$29.82$29.82Delivery Mon, Sep 21
Loading...
Editorial Reviews
Review
"A comprehensive guide. Certain to make the reader a better information security practitioner, and their network more secure."
—Ben Rothke, Slashdot
"If you are in cyber security, this is a must read. The book is the best resource for tools I have seen anywhere."
—Stephen Northcutt, SANS Institute
"A very well written technical book. I would recommend this for anyone getting into the field of incident response who doesn't have a great understanding of NSM."
—Greg Hetrick, PaulDotCom
"Deploying NSM not only means you can quickly identify, contain, and remediate intrusions, it gives you insight into the network as a whole."
—Michael W. Lucas, author of Absolute OpenBSD, 2nd Edition
"The Practice of Network Security Monitoring: the best surveillance book you'll read anytime soon."
—Peter N. M. Hansteen, author of The Book of PF
"This gem from No Starch Press covers the life-cycle of Network Security Monitoring (NSM) in great detail and leans on Security Onion as its backbone. I recommend an immediate download of the latest version of Security Onion and a swift purchase of Richard’s book."
—Russ McRee, senior security analyst, Microsoft
"The principles Bejtlich outlines for running your security monitoring are the kind of best practice you should apply to any important server."
—Mary Branscombe, ZDNet
"If you want to know what to do when intruders arrive on your network and how to best prepare for that eventuality, you must read this book."
—Sandra Henry-Stocker, ITWorld
"Bejtlich is a master of his craft and also possesses the rare gift of being able to share his knowledge in a comprehensible way."
—Richard Austin, IEEE Cipher
"As tech books go, it's a pretty fun ride."
—Michael Larsen, Testhead
—Ben Rothke, Slashdot
"If you are in cyber security, this is a must read. The book is the best resource for tools I have seen anywhere."
—Stephen Northcutt, SANS Institute
"A very well written technical book. I would recommend this for anyone getting into the field of incident response who doesn't have a great understanding of NSM."
—Greg Hetrick, PaulDotCom
"Deploying NSM not only means you can quickly identify, contain, and remediate intrusions, it gives you insight into the network as a whole."
—Michael W. Lucas, author of Absolute OpenBSD, 2nd Edition
"The Practice of Network Security Monitoring: the best surveillance book you'll read anytime soon."
—Peter N. M. Hansteen, author of The Book of PF
"This gem from No Starch Press covers the life-cycle of Network Security Monitoring (NSM) in great detail and leans on Security Onion as its backbone. I recommend an immediate download of the latest version of Security Onion and a swift purchase of Richard’s book."
—Russ McRee, senior security analyst, Microsoft
"The principles Bejtlich outlines for running your security monitoring are the kind of best practice you should apply to any important server."
—Mary Branscombe, ZDNet
"If you want to know what to do when intruders arrive on your network and how to best prepare for that eventuality, you must read this book."
—Sandra Henry-Stocker, ITWorld
"Bejtlich is a master of his craft and also possesses the rare gift of being able to share his knowledge in a comprehensible way."
—Richard Austin, IEEE Cipher
"As tech books go, it's a pretty fun ride."
—Michael Larsen, Testhead
About the Author
Richard Bejtlich is Chief Security Strategist at FireEye, and was formerly Chief Security Officer at Mandiant. He also served as Director of Incident Response for General Electric, where he built and led the 40-member GE Computer Incident Response Team (GE-CIRT). He is a graduate of Harvard University and the United States Air Force Academy. His previous works include The Tao of Network Security Monitoring, Extrusion Detection, and Real Digital Forensics (all from Addison-Wesley). He blogs (http://taosecurity.blogspot.com/) and writes on Twitter as @taosecurity.
Product details
- Publisher : No Starch Press
- Publication date : July 15, 2013
- Edition : Illustrated
- Language : English
- Print length : 376 pages
- ISBN-10 : 1593275099
- ISBN-13 : 978-1593275099
- Item Weight : 1.35 pounds
- Dimensions : 7.01 x 0.75 x 9.25 inches
- Best Sellers Rank: #276,181 in Books (See Top 100 in Books)
- #13 in Network Disaster & Recovery Administration
- #26 in Computer Networks
- #141 in Computer Hacking
- Customer Reviews:
About the author
Follow authors to get new release updates, plus improved recommendations.

Mr. Bejtlich has been an author for two decades. Please see www.linkedin.com/in/richardbejtlich/ for details on Mr. Bejtlich's biography. As an Amazon Associate I earn from qualifying purchases.

















![Florida Property and Casualty Study Cards: Florida Property and Casualty Insurance License Exam Prep 2026-2027 and Practice Test Questions [Full Color Cards]](https://m.media-amazon.com/images/I/41ILUCZ+HSL._AC_SR100,100_QL65_.jpg)
![Intellectual Property In the Digital Age [Edition 2024]: A Practical Guide on Patents, Trademarks, Copyrights, and Protecting Confidential Information [AI Insight Bonus]](https://m.media-amazon.com/images/I/41WitElGixL._AC_SR100,100_QL65_.jpg)


