Hello and welcome to CertForums.co.uk, here we host free active certification forums with links to the best free resources for Microsoft's MCSA MCSE MCDBA Cisco's CCNA CCDA and CCNP, and CompTIA's A+ Network+ i-NET+ and Security+ certifications in the UK. If you wish to post or use other advanced features you will need to register first. Registration is absolutely free and takes only a few minutes to complete so sign up today!

If you have any problems with the registration process or your account login, please contact support

Go Back   CertForums > General Forums > Articles, Reviews and Interviews > Reviews
Home Forums Register Search Today's Posts Mark Forums Read

Security Monitoring with Cisco Security MARS

Post New ThreadReply
 
Thread Tools Display Modes
  #1  
Old 11-Oct-2007, 03:46 PM
tripwire45's Avatar
tripwire45 tripwire45 is online now
Administrator
Posts: 13,995
Points: 4638 tripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 points
Power: 196
None
Join Date: 29 Jun 2003
Location: Boise, ID, USA
Certifications: A+ and Network+
Security Monitoring with Cisco Security MARS

Authors: Gary Halleen and Greg Kellogg
Format: Paperback, 336
Publisher: Cisco Press; 1st edition (July 6, 2007)
ISBN-10: 1587052709
ISBN-13: 978-1587052705

Review by James Pyles
October 11, 2007

Cisco's MARS (Monitoring, Analysis, and Response System) is a hot topic just now. This book's back cover touts it as the "next-generation Security Threat Migration system (STM)" and further states, "easy-to-use family of threat mitigation appliances enables you to centralize, detect, mitigate, and report on priority threats by leveraging the network and security devices already deployed in the network, even if the devices are from multiple vendors". That's a tall order, but Cisco Press would have to be out of its collective mind to publish something and not be able to deliver...wouldn't it?

The real problem with many books like this one is that while the text tells you how to install, configure, and deploy the tool in question, it doesn't really explain how to apply it to a thousand different real-world scenarios that you'll actually face in real life. Few if any "out-of-the-box" solutions adapt perfectly to a production environment, so even if Halleen and Kellogg write the perfect MARS book generically, will it still help you to use MARS on your "real-to-life" network?

Turns out that's the goal of the book and the authors have the credentials to back it up. Halleen is a Cisco security consultant and Kellogg is a VP for a security solutions company. If anyone should be able to turn out a good print product about MARS, it should be them. That fits right in to the target audience for the book which is just about anyone who has the titles "information security analyst, security officer," or anyone else who manages firewalls, IPS or IDS systems, and so on.

As it turns out, this book delivers as promised. The authors leverage their own real-life experiences in the field and apply it to the use of MARS on actual networks. They also write in an easy-to-understand and straightforward manner. Although the security expert is the reader of choice here, you don't have to possess much (if any) direct experience using MARS. This book outlines how to get started in deploying MARS from beginning to end.

Not only does the product deliver but the book does as well. The text describes the basics of setting up MARS and provides enough details to where you can easily adapt it to how your network is configured. On top of that, you will be enabled to protect your infrastructure from intrusion including queries and reports so that you'll have the information you need at your fingertips. You won't have to analyze an intrusion after the fact. MARS provides you with real-time information so you can stop trouble before it starts. This book tells you how to use MARS to your best benefit. If you are responsible for network security and you aren't using MARS, buy this book today. It'll make a difference.


You know, I wish my parents played Mozart when I slept because half the time I don't even know what the heck anyone's talking about!
 
Reply With Quote
Post New ThreadReply Spread this thread: Submit this thread to digg Submit this thread to del.icio.us


Go Back   CertForums > General Forums > Articles, Reviews and Interviews > Reviews


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Cisco confirms design cert track may reach CCIE level jackson Design 0 25-Jul-2007 05:55 PM
Cisco Revamps Security Cert tripwire45 News 0 03-May-2007 12:41 AM
Cisco Fundamentals Security laup Security+ 6 26-Feb-2007 01:27 PM
Cisco Betas New CCIE Security Written Exam zimbo News 0 14-Jan-2007 08:29 PM


All times are GMT +1. The time now is 04:45 AM.

Powered by vBulletin® Version 3.6.11
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
CertForums.co.uk (C) copyright 2003-2007 All Rights Reserved. Content published on CertForums.co.uk requires permission for reprint.
Hosted by Lunarpages