Publisher's Synopsis
Traditional intrusion detection and logfile analysis are no longer enough to protect todays complex networks. In the updated second edition of this practical guide, security researcher Michael Collins shows InfoSec personnel the latest techniques and tools for collecting and analyzing network traffic datasets. Youll understand how your network is used, and what actions are necessary to harden and defend the systems within it.In three sections, this book examines the process of collecting and organizing data, various tools for analysis, and several different analytic scenarios and techniques. New chapters focus on active monitoring and traffic manipulation, insider threat detection, data mining, regression and machine learning, and other topics.Youll learn how to:Use sensors to collect network, service, host, and active domain dataWork with the SiLK toolset, Python, and other tools and techniques for manipulating data you collectDetect unusual phenomena through exploratory data analysis (EDA), using visualization and mathematical techniquesAnalyze text data, traffic behavior, and communications mistakesIdentify significant structures in your network with graph analysisExamine insider threat data and acquire threat intelligenceMap your network and identify significant hosts within itWork with operations to develop defenses and analysis techniques