Showing posts with label Business and Management. Show all posts
Showing posts with label Business and Management. Show all posts

Tuesday, July 30, 2013

Cisco CCNA Routing and Switching 200-120 Official Cert Guide Library, Academic Edition, 1st Edition, Wendell Odom


The new edition of bestselling CCNA 200-120 Cert Guide Library, Academic Edition by Wendell Odom textbook and study package for a beginner to intermediate-level networking course. The two books in this package: CCENT/CCNA ICND1 100-101 Official Cert Guide, Academic Edition and CCNA ICND2 200-101 Official Cert Guide, Academic Edition have been completely revised to align to Cisco's new CCNA 200-120 exam. Material is presented in a concise manner, focusing on increasing student's retention and recall of exam topics. The books are printed in four color, allowing students to benefit from carefully crafted figures that utilize color to convey concepts. Students will organize their study through the use of the consistent features in the chapters, including:

• Foundation Topics – These sections make up the majority of the page count, explaining concepts, configurations, with emphasis on the theory and concepts, and with linking the theory to the meaning of the configuration commands.
• Key Topics – Inside the Foundation Topics sections, every figure, table, or list that should absolutely be understood and remembered for the exam is noted with the words “Key Topic” in the margin. This tool allows the reader to quickly review the most important details in each chapter.
• Chapter-ending Summaries – These bulleted lists provide a quick and concise review of the key topics covered in each chapter.
• Chapter-ending Review Questions – Each chapter provides a set of multiple choice questions that help student’s test their knowledge of the chapter concepts, including answers and full explanations.
• Chapter-ending Exercises – Each chapter concludes with a series of exercises designed to help students increase their retention of the chapter content including key term reviews, key topic tables, command review exercises, and memory table exercises.
• Part Reviews – This new edition includes a new part review feature that helps students consolidate their knowledge of concepts presented across multiple chapters. A new mind mapping exercise helps students build strong mental maps of concepts. A new exam bank of part review questions helps students test themselves with scenario-based questions that span multiple topics.

In addition to these powerful chapter learning, review, and practice features, this book also contains several other features that make it a truly effective and comprehensive study package, including:

• Getting Started chapters at the beginning of each book. These are great overviews of the books and offer terrific advice for how to build an effective study plan.
• The DVD contains over 150 minutes of video mentoring from the author on challenging topics such as CLI navigation, router configuration, switch basics, VLANs, subnetting, OSPF, EIGRP, EIGRP Metrics, PPP, and CHAP.
• The books come complete with the CCENT ICND1 and CCNA ICND2 Network Simulator Lite software, providing students with the opportunity to practice their hands-on command line interface skills with Cisco routers and switches. The 26 labs included for free with this product cover a range of IP addressing and EIGRP configuration and troubleshooting exercises.
• The Pearson IT Certification Practice Test software that comes with the books includes 4 full ICND1 exams, 4 full ICND2 exams and 8 full CCNA exams, providing tons of opportunities to assess and practice. Including the book review questions and part review questions, the exam banks includes more than 900 unique practice questions.
• This book also comes with free versions of the Premium Edition eBooks, allowing students to access the digital copies in PDF, EPUB, or Kindle format on their computer or mobile device.
• Final Preparation Chapters help students review for final exams and prepare to take the official Cisco CCNA exams, if they want to achieve that certification.
• Study Plan Templates are included on the DVD to help students organize their study time.

Wendell Odom, CCIE No. 1624, has been in the networking industry since 1981. He has worked as a network engineer, consultant, systems engineer, instructor, and course developer; he currently works writing and creating certification tools. He is author of all the previous books in the Cisco Press CCNA Official Certification Guide series, as well as the CCNP ROUTE 642-902 Official Certification Guide, the QoS 642-642 Exam Certification Guide, coauthor of the CCIE Routing and Switch Official Certification Guide, and several other titles. He is also a consultant for the CCNA 640-802 Network Simulator from Pearson and for a forthcoming replacement version of that product. He maintains study tools, links to his blogs, and other resources at www.certskills.com.

Product Details :
  • Hardcover: 1700 pages
  • Publisher: Cisco Press; 1 edition (July 15, 2013)
  • Language: English
  • ISBN-10: 1587144875
  • ISBN-13: 978-1587144875
  • Product Dimensions: 10.3 x 8.2 x 2.5 inches

More Details about Cisco CCNA Routing and Switching 200-120 Official Cert Guide Library, Academic Edition, 1st Edition

or

Download Cisco CCNA Routing and Switching 200-120 Official Cert Guide Library, Academic Edition, 1st Edition PDF Ebook

Saturday, July 27, 2013

Applied Networking Labs, Pearson Custom Business Resources, 1st Edition, Randy J Boyle


I purchased this book as the hands on experience for. Dr Boyle's Networking and Servers course at the University of Utah. The labs are excellent as they teach you basic knowledge of dozens of programs that are commonly used by network administrators and professionals. After doing most of the labs I have substantially added skills to my resume that have greatly increased my visibility to employers. I applied to five network administrator positions and each of them gave me a call, even though I have no work experience. My resume was impressive enough with the skills that these labs added. That is why this book is so valuable; it doesn't teach theory but applicable skills that employers want. I suggest this book to anyone who is interested in learning networking and servers from a basic level. The only downside is that because there are so many programs covered there isn't full in depth discussion on how to use each program. That being said, the book isn't designed to be a user manual for each program but to give general knowledge and skills thereby allowing users to discover and learn on their own with the programs they are interested in.

Dr. Boyle's textbooks have always been a great resource for learning hands on applications of IT Security and Networking skills. Knowledge learned from this book can be put on a resume and teach you how to talk-the-talk during interviews. Unfortunately, many think that just by doing some of the exercises in the book constitute putting those skills on their resume. This book will give you a great introduction, but you have to apply yourself with more outside learning to become proficient enough to get through a job interview!

This book is fantastic. The projects in it are explained thoroughly, and the content is really interesting. I enjoyed doing the projects a lot.

One of my favorite projects involved creating a bootable Linux distro and running the OS from a flash drive as the computer boots.

Product Details :
  • Paperback: 336 pages
  • Publisher: Prentice Hall; 1 edition (July 24, 2010)
  • Language: English
  • ISBN-10: 0132310341
  • ISBN-13: 978-0132310345
  • Product Dimensions: 0.5 x 8 x 11 inches

More Details about Applied Networking Labs, Pearson Custom Business Resources, 1st Edition

or

Download Applied Networking Labs, Pearson Custom Business Resources, 1st Edition PDF Ebook

Business Data Networks and Telecommunications, Pearson Custom Business Resources,8th Edition, Raymond R Panko


This book is required reading for a network management course I am taking. The book is generally informative at maybe a college junior business student level 1st network management course. It is easy to read and discusses some important subjects. I have not finished it yet.

The authors do go off on a tangent about writing network speeds correctly which I think is a bit overdone.

The cost of the book is just way too high for me. If it was not required I would not have purchased this book.

I'm Computer Information Systems major in my university's business school and took this class the first semester of my senior year. Telecomm is more towards the technical end of our curriculum, but the information I got from this textbook -- and the associated class -- was invaluable. Even though I didn't have a very technical background like most Engineering or Computer Science students probably do, I found the book to be relatively easy to read. It went into sufficient depth that I was able to thoroughly understand the major concepts, but wasn't so comprehensive in the material it covered to the point that I lost sight of the big picture.

Having taught IT undergrads from earlier versions of this text, I'm extremely disappointed with the disjointed flow of the chapters, but also the helter-skelter way things are thrown together within the chapters. One of many, many examples- Early on, you get students just enough into protocols like TCP and UDP, the 5-layer model and such, and then break off into network security and management? Several chapter later you come back to TCP/IP, after new students have forgotten the earlier stuff several chapters earlier. It's crazy, it's confusing, and this edition is not one I want to continue with. And the price is simply insane- you could cut it in half and it would still be overpriced.

Product Details :
  • Hardcover: 528 pages
  • Publisher: Prentice Hall; 8 edition (August 4, 2010)
  • Language: English
  • ISBN-10: 0136100120
  • ISBN-13: 978-0136100126
  • Product Dimensions: 7.4 x 0.9 x 9.1 inches
  • Shipping Weight: 1.9 pounds

More Details about Business Data Networks and Telecommunications, Pearson Custom Business Resources,8th Edition

or

Download Business Data Networks and Telecommunications, Pearson Custom Business Resources,8th Edition, PDF Ebook

Wednesday, July 10, 2013

Business Data Communications and Networking, 11th edition


A balanced approach that keeps up with a fast-moving field

Rapidly evolving data communications and networking technology are shaping the future of the business world, creating new challenges for both business students and the instructors who must prepare them for the future careers.

In order to provide the most relevant, hands-on learning toll currently available, the latest edition of Business Data Communications and Networking has been thoroughly update and revised, reflecting the input of users of this textbook worldwide. While retaining the balanced coverage of the technical and managerial aspects of data communications that has made previous editions so popular, the edition features a wealth of cutting-edge applications and new applied exercises designed to help students succeed in an ever-changing field.

Highlights of the 11th Edition include:

Combined coverage of wireless and wired LANs into one chapter
New streamlined and user-friendly format that reflects only current technologies
Expanded labs and real-world activities to reinforce key concepts and illustrate the practical uses of network technology
Updated coverage on routing, Ethernet and IP services
About the Author
Professor Alan Dennis is professor of information systems in the Kelley School of Business at Indiana University and holds the John T. Chambers Chair in Internet Systems. The Chambers Chair was established to honor John Chambers, president and chief executive officer of Cisco Systems, the worldwide leader of networking technologies for the Internet.
Prior to joining Indiana University, Professor Dennis spent nine years as a professor at the University of Georgia, where he won the Richard B. Russell Award for Excellence in Undergraduate Teaching. Professor Dennis has a bachelor's degree in computer science from Acadia University in Nova Scotia, Canada, and an MBA from Queen's University in Ontario, Canada. His Ph.D. in management of information systems is from the University of Arizona. Prior to entering the Arizona doctoral program, he spent three years on the faculty of Queen's School of Business.

Dr. Jerry Fitzgerald is the principal in Jerry Fitzgerald & Associates, a firm he started in 1977. He has extensive in risk analysis, computer security, audit and control of computerized systems, data communications, networks, and systems analysis. He has been active in risk-assessment studies, computer security, audit reviews, designing controls into applications during the new system development process, date communication networks, bank wire transfer systems, and electronic data interchange and date communication networks. Dr. FitzGerald has a Ph.D.in business economics and a master's degree in business economics from the Claremont Graduate School, an MBA from the University of Santa Clara, and a bachelor's degree in industrial engineering from Michigan State University. He is a certified information systems auditor (CISA) and holds a certificate in data processing (CDP). He belongs to the EDP Auditors Association (EDPAA), the Institute of Internal Auditors (IIA), and the Information Systems Security Association (ISSA). Dr. FitzGerald has been a faculty member at several California universities and a consultant at SRI International.

Alexandra Durcikova is an Assistant Professor at the Eller College of Business, University of Arizona. Alexandra has a Ph.D. in Management Information Systems from University of Pittsburgh. She has earned a M.Sc. degree in Solid States Physics from Comenius University, Bratislava, worked as an experimental physics researcher in the area of superconductivity and as an instructor of executive MBA students prior to pursuing her Ph.D. Alexandra's research interests include knowledge management and knowledge management systems, knowledge management system characteristics, governance mechanisms in the use of knowledge management systems; and human compliance with security policy and characteristics of successful phishing attempts within the area of network security. Her research appears in Information Systems Research, Journal of Management Information Systems, International Journal of Human-Computer Studies, and Communications of the ACM.

Product Details :
  • Hardcover: 608 pages
  • Publisher: Wiley; 11 edition (August 23, 2011)
  • Language: English
  • ISBN-10: 111808683X
  • ISBN-13: 978-1118086834
  • Product Dimensions: 10.2 x 7.4 x 1 inches

More Details about Business Data Communications and Networking, 11th edition

or

Download Business Data Communications and Networking, 11th edition PDF Ebook

Tuesday, May 28, 2013

The Quantum Age of IT 1st edition, Charles Araujo



'Charles has really nailed it for any executive struggling with IT strategy. How IT got here and where it's going. This book really hits at the heart of what is missing in IT today and provides step-by-step approaches loaded with examples for steering the strategic course for IT in the 21st century. An easy read, yet will get the creative juices flowing for any IT professional executive!' (Randy Steinberg, Author, ITIL Service Operation, 2011 Edition, Principal - Migration Technologies) 'What a great, insightful and thought-provoking work! The best part is that Charlie makes it practical and easily understandable with his real-life examples. Finally, a road-map for IT professionals who want to thrive in the business world in which they are being thrust.' (Jaime L. Rosado, Jr, Col (ret), USAF, Medical Serice Corps, FACHE, FAHM) 'A bracing indictment of IT dysfunction, and a well-informed discussion of promising avenues for IT improvement. I agree completely with Charlie that a systems approach is essential. Recommended!' (Charles T. Betz, erp4it.com) 'Araujo's easy-reading style belies the significance of his message. IT has changed fundamentally. Don't get left behind.' (Mark Smalley, Ambassador at the not-for-profit ASL BiSL Foundation and freelance IT Management Consultant) 'The role of IT has changed in a revolutionary way. Success in this new world order will require a new way of thinking and a new set of competencies. Charles Araujo helps his readers understand the need for change, as well as the ways that they must change in order to leverage this exciting opportunity.' (Larry Bonfante - CIO USTA, Founder CIO Bench Coach, Author, Lessons in IT Transformation)

This book is really great, very interesting and the book inspired me to push myself to establish detailed a long term education plan for myself.

I really liked the first part of the book, say the first 100 pages and the last part of the book really got me fired up!!
It was a very enjoyable read and pushed me in the right direction - quite fun at times and I felt it was written in a way that spoke to me directly.

I highly recommend this book to anyone that would like to see where IT is going in the future... you better get ready and prepare yourself or you will be out!

An excellent read from a thought leader in IT Governance and transformation. The author has clearly worked in and around the IT field for quite awhile judging by the scenarios and insights scattered throughout this book. While it is a quick read, I discovered valuable ideas and sections that I will be coming back to reference for years to come.

As an IT professional for almost 17 years and having worked for start-ups, consultancies, and multi-billion dollar corporations, I found the specific directions for mapping future IT careers and organizations of particular interest. Most "thought-provoking" books are light on specific knowledge to look into while most technical books ignore too much of the interdepartmental planning, coordination, and interfacing standards and controls needed for larger projects and initiatives to succeed (and the knowledge needed by individuals to succeed in those environments).

The scenarios and suggestions would be just as useful in SMBs with some streamlining/simplification where needed, as well.

Again, while it was a bit short, it was an engaging and interesting read with enough worthwhile information to justify adding to my professional library.

When I started to read this book, I was very skeptical. The title and cover did not promise an interesting read. But as they say, you cannot judge a book by its cover. Lately, I found that many business books are very shallow or based on ideas that might have enough depth for a blog entry but not for a whole book. Well, this book definitely is not one of these books. It is a long overdue critical review of the IT function in a corporate setting with a great historical perspective but more importantly with an important look toward the future. It explores how the IT function must change to stay relevant in order to provide value to its customers. It challenges IT professionals to stop hiding behind technologies and develop the critical soft skills that a necessary to deliver value. Somewhere hidden in the book is a sentence that perfectly sums up the core message:"...the real catalyst for change will not be the (social) technology, but rather the purely human social interactions that must occur". Not an easy message for the average IT professional that bases her/his self-esteem on technical prowess. However, a much needed message. In my own experience there is a state of stagnation in many IT organizations which makes them focus on the wrong areas just as the author points out. This book, although you quite naturally might not agree with every point, should be a must-read book for IT professionals that want to evolve and everybody that "owns" IT in a corporate environment.

"The Quantum Age of IT" is both much needed and a pleasure. It is in fact overdue in a time when IT organizations are facing unparalleled pressures for change from both internal and external sources. This book draws heavily on a rich matrix of anecdotes from history, literature, IT experiences, and the author's own personal history, that underscore and illuminate the fact that most of the problems facing IT profesionals today are less technical than human ones. Given the breadth of scope-- from the impact of cloud to IT-to-client dialog, to the evoluton of IT as an organization -- the author's flow is surpsiingly cohesive and easy to grasp. The recommendations for emerging into the "Quantum Age" also make sense and are readily understood. I recommend this book to anyone interested in re-evaluating their present/future in or around IT, including non-IT consumers of IT services seeking to better understand what the dilemma might look like from the "other side."

Product Details :
Paperback: 314 pages
Publisher: ITGP (November 29, 2012)
Language: English
ISBN-10: 1849283753
ISBN-13: 978-1849283755
Product Dimensions: 5.5 x 0.6 x 8.5 inches

More Details about The Quantum Age of IT 1st edition

or

Download The Quantum Age of IT 1st edition PDF Ebook

Sunday, May 19, 2013

Top-Down Network Design 3rd Edition, Priscilla Oppenheimer



If you are designing networks for your company or customers this book is an excellent resource. I highly recommend it and the Network Warrior as excellent and complementary resources in network design and configuration.

Bought this book before I boarded a plane, I worked for an MSP going over network designs offering advice to improve designs I found this book invaluable for appealing to both the technical roles as well as the management and C-level personnel. One thing I want to advise on, is this book good for the principles behind network designs but I this book can get your CCDP if that's you main purpose for getting this book. If your after your CCDP you definitely want to read this book but don't let it be your main source of study material, I'd consider it a supplemental supplemental source.

Covers a little bit of everything with the exception of Data Center/Nexus which is a newer technology. However LAN/WAN/Routing/Security/Management/Addressing are all covered in this book. With some good points for each subjects.

Whereas most other networking books focus on one technology or one aspect of network design, Oppenheimer really does guide the reader through designing a network in a top-down (gathering requirements to documentation) fashion. Overall, the book takes you from a 30,000 foot view to about a 2,000 foot view. Despite Oppenheimer's Cisco-focused background and being published by Cisco Press, her book admirably avoids plugging Cisco as the end-all-be-all solution. Overall, I would recommend this book for all parts of network design, and recommend others for the actual IOS/device configuration (which Top-Down Network Design avoids).

As others have identified, the books is divided into four sections. The section titles are descriptive enough, so I'll just point out the highlights by chapter instead.

The first chapter covers an introduction to network design, including analyzing business goals and constraints. It emphasizes the need for the network design to make "business sense," as in justify the business itself. Constraining the network design to the budgetary and staffing constraints of the customer is also important -- after all, what good is a highly-reliable, highly-complex network to a CCENT-level network engineer who can't make necessary modifications without taking down the network?

The fourth chapter relates to the network traffic of the existing network. By categorizing users into "user communities" based off job role (usage of sets of applications) and categorizing the traffic flows themselves, one can describe at a high level the network flow while still providing useful data for technical purchase decisions. The traffic flows are categorized into groups such as peer-to-peer, client/server, server-to-server, terminal/host, and distributed computing.The traffic is also displayed by frame size, broadcast/multicast/unicast type, and error rate to give useful data. QoS requirements for voice and other sensitive applications are also discussed, as are different service categories based off the Asynchronous Transfer Mode Forum definitions.

I appreciate this model, as without these abstractions it's tough to talk about network flow at a high level without losing specificity.

In chapter six, there's a sizable section on naming schemes, especially in the Windows world. The "Guidelines for Assigning Names" section is full of solid advice, though the section on WINS can probably be safely removed in the next edition.

Chapter seven is mostly focused on the actual switching and routing protocols, but also covers the creation of decision trees to assist with protocol selection. Table 7-5 on page 230 is a *very* handy summary of the routing protocols covered in the text.

In the last chapter, number 14, Oppenheimer gives a summary of top-down network design by going through the steps of the design methodology, which I found very useful. She also highlights the importance of the network design document, details how to respond to client RFP's, and then goes over the sections of the network design document in detail.

I found this to be an extremely useful book for its intended purpose. Top-Down Network Design will be a text I refer to for any network design needs I encounter in my future.

The book is sure a good buy, sumamrizes many important steps of network design approach, recaps on important technical topics in clear way, and provides a companion website with useful checklist.
Some things I would have liked to see in the book but were not there:
- migration/upgrade techniques: it might have been beneficial to lokk at situations where the basis is an existing network, though the approach may be similar
- more examples of IP networks design: only 2 were reported to illustrate a campus and a enterprise edge design.
To this regard I suggest the older but still good Large-scale IP networks, which include 3-4 large scale network designs.
Overall anyway is definitely a very good book.

Priscilla Oppenheimer's Top Down Network Design is found on virtually every senior network engineer's bookshelf but yet is written with such clarity that even a novice can understand. The book is divided into four sections and walks you step by step through the process of designing reliable high-available computer networks.

"Section 1: Identifying your Customer's Needs and Goals" gives a comprehensive review of assessing business goals and technical requirements of a network. This is a critical step that builds the foundation for your design.

In "Section 2: Logical Network Design" the author explains the development of a high-level scalable network topology using current hierarchical and modular design practices.

"Section 3: Physical Network Design" builds on the previous sections with the creation of a low level design. You start by selecting a LAN cabling plant and LAN technologies. Then continue by designing the layer 3 topologies such as the IP Addressing scheme, selecting the appropriate routing protocol, and developing a network management and security posture.

"Section 4: Testing, Optimizing and Documenting your Design" explains how to prototype your network, write and implement a test plan, optimize your network, and finally the most often missed network documentation.

The process described in" Top Down Network Design" is the exact methodology we use when designing for our customers and leads to highly stable and reliable networks.

Top Down Network Design 3rd Edition was one of the very first Cisco Press books I read while interning for a big IT Shop. As a Systems Administrator having excellent design skills is a necessity. This book's rich systems analysis based philosophy for design can be applied to any Enterprise Project.

Oppenheimer is no stranger to the Network world and that really comes through in her book. I own another Oppenheimer book, "Troubleshooting Campus Networks" which also really delivers in terms of relating design to real world problems. Top Down Network Design 3rd Edition is not exception in this case. Too often Cisco Press Books are too full of technical theory and not enough practical use cases. However Oppenheimer manages to successfully guide through practical exercise that relate back to the real physical infrastructure and end-user experience.

This book will be one of the go-to books on my shelf for many years to come when starting any major IT Project.

If you are new to networking and want to learn the right way to approach network design, this book is for you. If you're not new to networking and you want to learn a more structured approach that is proven to be successful, this book is for you. Many people have said that this book is helpful for studying for the CCDA; it is, but this book is more than that. Its purpose is not to help you pass a test, it's here to help you become a better network engineer. Too often, network engineers take a strictly short-term operational view when it comes to upgrading their networks, and that can be a bit short-sighted, leading to all sorts of unexpected issues and suboptimal performance in the long run. Sometimes we need to step back and begin again from the top. In the words of another mentor of mine, we must ask "What problem are we trying to solve?", then iterate from the top down to design a modular, structured network that meets current demands and can accept future growth and upgrades easily. That's not quite as easy as it sounds, but this book will help get you there.

I've read the 2nd and 3rd editions of this book. The new 3rd edition is slimmed down and updated. A lot of extremely good information is packed into just over 400 pages, but it's so easy to read that it seems even shorter. I've been in networking for several years and I still picked up several new ideas when reading the new edition, and in other cases I had gentle reminders to avoid certain bad habits.

If you want to get serious about improving your network design skills, get this book.

This is a review of the 3rd edition.

Oppenheimer directs the book at a network analyst who might have to design a large scale network for a client company. The discussion starts by suggesting an analysis of the client's industry and needs. This is reinforced by definitions of various network performance metrics, like MTBF, MTTR, capacity, throughput, delay (latency), delay variation, etc. Chapter 2 is distinguished by a comprehensive explanation of each metric. The explanations are fairly non-technical. You don't need a degree in computer science or electrical engineering to follow it.

The text then goes into how to characterise any existing network. This is a pragmatic recognition that you typically do not have a blank slate, with no pre-existing network. These days, a company is likely to already have a network, which presumably is developing bottlenecks or other problems, such that you have been called in to suggest upgrades.

Later in the book, the narrative does get more involved, delving into the design of a network topology, with associated switches and routers. Various common protocols are briefly but succinctly covered. As a network designer, you need thorough acquaintance with these and the text is an excellent discourse.

I have never seen the 1st or 2nd editions, so I'm unsure exactly how the 3rd differs. I am guessing that much of the text is unchanged. For example, the protocols have been largely stable for several years. While the advice about network topologies could also have been largely unaltered. The most recent portions of this text may pertain to the latest capabilities of switches and routers.

The text is also admirably ecumenical in its hardware descriptions. No lock in for Cisco hardware.

Product Details :
Hardcover: 600 pages
Publisher: Cisco Press; 3 edition (September 3, 2010)
Language: English
ISBN-10: 1587202832
ISBN-13: 978-1587202834
Product Dimensions: 7.6 x 1.2 x 9.2 inches

More Details about Top-Down Network Design 3rd Edition

or

Download Top-Down Network Design 3rd Edition PDF Ebook

Real Digital Forensics: Computer Security and Incident Response 1st edition, Keith J. Jones



Unfortunately, this book is a little outdated and doesn't explain many of its steps very well. If you are newer to Unix like myself, you will have a hard time following much of the Unix commands in this book. Following one of the labs actually caused my laptop to become bricked for a few days until I could fix it. If you have much prior knowledge, this is a good book, else steer clear.

Even though this book Real Digital Forensics was published in 2006, it is a must read for any Security & Incident Response Cyber Analyst. It would be nice if it had a revised edition to cover Windows Vista, Windows 7, and many other technologies that have come into play these past five years and the new emerging technologies.

OK. What more do you need to know? This book is written by three gentlemen who live, eat and breathe computer incident response & forensics. The fact that they present the information in a well written and easy to follow format is just a bonus! If you're one of those "I wanna do it" types like me, you'll read through the material and then tackle the provided data to see if you can solve the crime. A great starting point for future incident responders and folks who want to know more about computer forensics.

This book is written in such a style that is easy to understand, yet technical and detailed enough to maintain your interest and attention all the way through.

The book presents several ways of accomplishing the same tasks in a non-biased, non-vendor-specific way. It explores the use of free, open-source tools as well as commercial offerings, and drills down into forensic analysis of both Windows and Unix/Linux Operating Systems.

The included CD contains actual forensic data and a few tools, which is both interesting and exciting to use while following along with the lessons in the book.

After receiving this book and opening it to the first page, I was almost unable to set it down until I finished it. I received it on a Friday afternoon and I had completed reading it by the end of the weekend. I highly recommend this book to anyone with an interest in Computer or Network Security.

As an author and instructor, I tend to be pretty picky about the books I choose to read and use in my classes. The authors present the material in a good logical progression. I especially like that it also provides sample evidence on the DVD. Most of the computer forensic books that currently exist contain mostly theory. This is the first good hands-on text that I have seen.

The authors have captured a good cross section of scenarios and then guide you through each case in-depth, offering practical solutions when faced with obstacles. The content provides methodologies, techniques, and tools that anyone can use. In addition it covers a variety of media such as USB memory and Palm devices.

This is a book that I will definitely keep. It is one of the best forensic investigations books currently on the market and would be a great asset to anyone wishing to enhance their skills.

There is a real lack of well written books in this category, and this one stands out because it is comprehensive, yet easy to digest and carefully laid out, including case studies to understand data capture and analysis techniques.

The progression of the chapters mirror an investigative process; there is discussion of how to properly handle digital evidence, how to make a duplicate of the source data, and how to make sense of what you have collected. There are many real-world type case studies in the beginning of the book that could easily read off the front of any newspaper, and the captured evidence is on the included DVD for you to search to find the "smoking gun". Very well done.

The book takes the unusual role of discussing not only the more popular commercial tools like EnCase or Forensic Tool Kit, but also all the open source tools available for free, which is a real plus if you don't have the deep pockets required for the retail products. The book also does an excellent job of explaining the advantages and shortcomings of all the products discussed, something not often seen in technical books. Along with the open source discussion are source web sites for downloading the tools. The accompanying DVD is packed with stuff to get you started. The book is filled with well illustrated screen shots to help you orient yourself when trying the programs yourself.

Be forewarned, this book assumes a pretty reasonable amount of technical knowledge and while it addresses the commercial products available on the Win32 platform, a lot of tools and utilities referenced are written for Linux. While a novice investigator can certainly find value in the book, there is a lot of "meat" that even a seasoned professional will find useful.

This is definitely the best book currently available on data forensic investigations.

Bejtlich, Jones and Rose 'Real Digital Forensics' is as practical as a printed book can be. In a very methodical fashion, the authors cover live response (Unix, Windows), network-based forensics following the NSM model (Unix, Windows), forensics duplication, common forensics analysis techniques (such as file recovery and Internet history review), hostile binary analysis (Unix, Windows), creating a forensics toolkit and PDA, flash and USB drive forensics. Is that it? :-)Well, there is some other fun stuff too. In other words, the book is both comprehensive and in-depth; following the text and trying the investigations using the enclosed DVD definitely presents an effective way to learn forensic techniques. I would recommend the book to all security professionals (even those not directly involved with forensics on a daily basis).

Anton Chuvakin, Ph.D., GCIA, GCIH, GCFA is a Security Strategist with a major security company. He is an author of the book "Security Warrior" and a contributor to "Know Your Enemy II" and the upcoming "Hacker's Challenge III". In his spare time, he maintains his security portal info-secure.org and his blog at O'Reilly. His next book will be about security log analysis.

There have been several authoritative books on computer forensics. (Including "Tao of Network Security Monitoring" by Bejtlich.) But this "Real Digital Forensics" book breaks new ground. Not in the theoretical modelling of an attack or countermeasures against it. Instead, there are several indepth case studies, that key off data given in the book's DVD. And the latter is a DVD, not a CD. The authors needed the multigigabyte capacity to store the provided data. Even then, these are compressed. This should give you some feeling of the book's emphasis.

The authors address a serious lack in this field. How does someone [you] gain experience analysing a real attack? Without already being employed at a company experiencing such an event? In response, the authors made several scenarios that, they claim, reflect what actual attackers would likely have done.

This is an experimental book. There is no overarching elegant theory. You are meant to roll up your sleeves and tackle each case. En route, the book shows how, as a defender, you can use several open source packages to dissect the attack, as well as impose countermeasures. Which is another nice feature. Those packages are free. It makes your forensics education very cheap, in terms of explicit capital outlay.

Which is not to say that the book ignores commercial forensic tools. But the authors have a clear preference for open source, with which you might well concur.

Product Details :
Paperback: 688 pages
Publisher: Addison-Wesley Professional (October 3, 2005)
Language: English
ISBN-10: 0321240693
ISBN-13: 978-0321240699
Product Dimensions: 7 x 1.5 x 9.2 inches

More Details about Real Digital Forensics: Computer Security and Incident Response 1st edition

or

Download Real Digital Forensics: Computer Security and Incident Response 1st edition PDF Ebook

CCNP Security Secure 642-637 Official Cert Guide 1st edition, Sean Wilkins



As a person who does technical writing, I can understand how small mistakes or oversights can find their way into a text. Nevertheless, the problems we see in this volume are not small. Aside from the typos, configuration syntax errors, and other problems, my biggest issues involve diagrams that are incorrectly labeled or lack critical information. An example can be found in chapter 19, where the author puts forth a GET VPN configuration example. The IP addressing scheme in the diagram does not match the router output (on the diagram it has 172.16.x.x and in the router it is 172.17.x.x). In task one, the author says to input an IKE policy but does not say which router he is working on. Instead of putting a hostname into the router so we can see what is going on, virtually all examples in the book have a router(config)# prompt. Oh, and it gets better: in his VPN example he has the wrong subnet specified as the interesting traffic to be protected, and he doesn't tell us what address is assigned to the interfaces where the crypto maps are applied. You couldn't have messed a chapter up worse than this--it is like Cisco is deliberately trying to confuse people who read the book.

I found myself ditching this text and going right to the Cisco whitepapers and online examples. The book never should have made it to print.

This is quite possibly the worst textbook i have ever come across. It is filled with typo's! And they're not just in the text, in example 18-1 they have a line of config "yunnel mode gre multipoint"! Unfortunately that is not the worst of it, the biggest problem is that the examples they include don't always follow the explanation. So they may be using one ip range in an explanation and another in the printed config example, as you can imagine this makes it a lot harder to follow what is going on.

The book contains a lot of information, but heck they all do, I'm not a huge fan of the Cisco Press books, but it seems the higher the test that is pretty much what you get. The material is pretty intuitive and covers what appears to be all the information for the test. Like some reviews there are repeated items and some types or information that does not appear accurate. However I did OK on the test, almost passed, but I did only give myself 3 weeks to study and I didn't have any hands on practice with the material. That is something I would do but in this case I had a free test to take and jumped on it. I will study more slowly and get the hands on that I need, but as far as the book goes I think it is an excellent starting point and contains enough information to know what you need to do well on the test. Good Luck.

I should leave myself a bit of the blame in this purchase since the previous reviews were less than stellar. I almost felt sorry for the author, well, that was until I started reading. I finished it last night and I'm still left to wonder how this got past the technical review process. Like others, I had to research and cross reference multiple items because honestly I couldn't "trust" this is as a single repository. I assume that along with other Cisco Press books should be the de-facto standard for exam prep material, considering that is their primary goal with these "cert guides". While I will still attempt to sit the exam, I'm not sure how well this particular guide really assisted in getting me there. I'm quite disappointed and hope the 2nd Edition may be more worthwhile. I can't really recommend this book until then.

I read the other reviews, downloaded the errata, then made the corrections in the physical book. I figured this would address the majority of the problems that people are having. I've encountered a larger problem though. I just can't trust this book and having to spend so much time fact checking is making the book rather worthless and almost detrimental as a study resource. I reached a point where I was going to just make an outline from the table of contents and then research the topics myself. If you are thinking about buying this book, just grab a copy of the table of contents. That's what you can expect. They broke things up into 4 parts and the chapters don't necessarily match the sections. You can tell there was a lot of copying and pasting done while making this book because items were duplicated and not changed.

Take all 6 Star Wars movies, substitute Luke Skywalker in the place of Darth Vader in half of Vader's scenes (including those in which both appear onscreen simultaneously). Neglect to mention anything about the familial relationships of Vader/Anakin-Luke-Leia and then film the whole thing with some of the actors appearing occasionally in their street clothes. Then release the episodes in a random order with "A New Hope" coming last and two of the episodes titled "Revenge of the Sith". You would then have the Star Wars equivalent of this book.

I knew this was going to be a rough read when the very first sentence of Chapter 1 was a grammatical nightmare, but since it's technical material I set aside my reservations about the quality of the writing and focussed on the technical merits. Sadly, only disappointment lay in that direction as well. Serious and obvious technical errors abound - as an example, the most recent one I read showed a sample configuration which included an access list where the author mistakenly entered a subnet mask rather than a wildcard mask. While the statement is still technically syntactically valid, it would have a very different effect than was described - a clear indication that neither of the authors nor either of the technical reviewers bothered doing anything as basic as actually *testing* the configurations they wrote up prior to publishing. This one is merely an example - additional technical errors can be found in multiple places.

Overall, the book reads as if written by someone whose grasp on the English language is tentative at best, and whose mastery of the subject matter seems questionable. I expected better from Cisco.

Like for first reviewer, I am currently using this book towards by certification exam and find it poorly written and mistake-prone. To properly understand the subject matter and be certain of the accuracy of the information being read, you will have to constantly research other information on the internet. I find myself regularly scouring the Cisco.com support pages for additional information, to explain topics better or deal with mistakes in the book. Should be of a much higher standard.

*** I have since finished this book and while I was hopeful that it would improve as I continued sadly it did not. Without even attempting to find mistakes in the book I was constantly presented with them. While most were typos there were still many technical errors. The amount of typos, though in themselves relatively easy to correct, only made me less confident in the quality of technical material I was reading. One of the most embarrassing errors I found was when doing the "Do I Know This" questions for Chapter 15. When checking the answers in the back of the book, question 3 has the answer as literally "E?" as though not even the writer was not sure and question 7 an answer of "S" when the options presented are A, B, C, D or E. If even these basic things can't be checked and corrected during review what level of confidence is a reader meant to have in the rest of the book.

Another issue I had with the book was that it seemed the CLI commands presented in examples were not entered into and then copied directly from a Cisco device but instead typed directly into the book script and formatted manually as there are many examples of syntax errors and wrong formatting which would not exist if the context was copied directly from a console/SSH session. An example of this is in example 21-10 where the command "ca trust-point MY-TP" is misspelt as "ca trust-poitn MY-TP" and example 20-14 places a hyphen between the words policy and group when this is not the syntax and should be "policy group". Example 17-24 also misses the EIGRP process number from the "no ip next-hop-self" command for example. These are just some of the many syntax errors I found that I believe are a result of this content of the book not being copied from commands first input into a switch or router.

I could go on but basically when a book is marketed as the guide for an exam and endorsed by a company that is not only the exam creator but one of the largest companies in the world the book should be much better than this. This book needs serious work.

I am currently using this book to prepare for the 642-637 exam. I think this book was poorly written. There are so many errors, both technical an non-technical. There are flaws that should not pass through a technical review and remain uncorrected. Yet they did. This makes one to wonder as to what the technical review is all about then. I'll advise anyone who is using this book as an exam prep tool to also use Cisco's documentation on its website. The authors and technical reviewer need to revisit this material.

Product Details :
Hardcover: 800 pages
Publisher: Cisco Press; 1 edition (July 7, 2011)
Language: English
ISBN-10: 1587142805
ISBN-13: 978-1587142802
Product Dimensions: 7.7 x 1.5 x 9.3 inches

More Details about CCNP Security Secure 642-637 Official Cert Guide 1st edition

or

Download CCNP Security Secure 642-637 Official Cert Guide 1st edition PDF Ebook

Snort IDS and IPS Toolkit Jay Beale's Open Source Security 1st edition, Brian Caswell



This book is a good tool to help understand how snort works and what that features are. I used it for my IDS class and learned a lot from it.

The product description does not mention that as of 2012, the CD is no longer included. The companion website is listed on the book's back cover as www.elsevierdirect.com/companion.jsp?isbn=9781597490993

I will review this book when I complete my graduate course in a few weeks.

I have run Snort at previous jobs and currently run it at home. I found the book to be packed with tons of valuable information and a great reference for tweaks you may want to make to your install down the road as your needs change. The only down side is that it's already "out of date" as far as current versions go. It's not so out of date that the information is irrelevant but just keep that in mind and make sure to read up on new features and bugs compared to what is listed in the book and the version you are installing.

This is the best single book on Snort I've come across, so I bought it. I used it as reference recently to customize a Snort configuration including writing a few custom rules. It has a really good index. It can be used as an in-depth tutorial or good quality reference.

Description of Chapters:
1) Intrusion Detection Systems - A nice overview of some basics
2) Introducing Snort 2.6 - Fairly comprehensive coverage of the product
3) Installing Snort 2.6 - Good coverage of the different options.
4) Configuring Snort Add-Ons (I don't recommend snort on Windows, but whatever)
5) Inner Workings - One of the best chapters on how snort really works
6) Preprocessors - Another great chapter on the inner workings.
7) Playing by the Rules - Good coverage of snort rule syntax.
8) Snort Output Plug-Ins - Another good chapter
9) Exploring IDS Event Analysis Snort Style - Some of these add-ons are a bit dated, but it's nice to have it all in one place.
10) Optimizing Snort - Principles of Snort optimization...
11) Active Response - More useful options
12) Advanced Snort - Not much of use here for most people.
13) Mucking Around with Barnyard - It's good to at least know what Barnyard is.

At 700 plus pages, this is the best collection of Snort info around.

Syngress published "Snort 2.0" in Mar 03, and I gave it a four star review in Jul 03. Syngress followed with "Snort 2.1" in May 04, and I gave it a four star review in Jul 04. I recommend reading those reviews, since the latest edition -- "Snort IDS and IPS Toolkit" (SIAIT) -- makes many of the same mistakes as its predecessors. Worse, it includes material that was already outdated in BOTH previous editions. If you absolutely must buy a book on Snort, this edition is your only real choice. Otherwise, I would stick with the manual and online articles.

SIAIT looks impressive page-wise, but it suffers from the multiple-author, no-editing, rush-to-production problems unfortunately inherent in many Syngress titles. One would think that including many contributing authors (11, apparently) would make for a strong book. In reality, the book contributes very little beyond what appears in "Snort 2.1," despite the fact that "only" chapters 8, 10, 11, and 13 appear to be repeats or largely rehashes of older material. Comparing to "Snort 2.1," these compare to old chapters 7, 10, 12, and 11, respectively.

The absolute worst part of this book is the re-introduction of all the outdated information in chapters 8 and 10. It is 2007 and we are STILL reading on p 353 that XML output is "our favorite and relatively new logging format" and on p 367 that "Unified logs are the future of Snort reporting." (I cited both of these as being old news in Jul 04!) I should note that these chapters are not entirely duplicates; if you compare output such as that on page 335 of "Snort 2.1" with page 365 in SIAIT you'll see the author replaced the original 2003 timestamps with 2006! This is the height of lazy publishing. Chapter 10 features similar tricks, where traffic is the same except for global replacements of IP addresses and timestamps; notice the ACK numbers are still the same and the test uses Snort 1.8.

There's plenty more in this book to make you cringe. Mentions of Netbus, SubSeven, BO2k, ExploreZip, QAZ, and the like in ch 1 will make you think it's 1999 all over again. In ch 2 you can be mislead into thinking that "there will be rule upgrades released with each major version of Snort for those who do not care to register." In reality the last rule set for unregistered users arrived with Snort 2.4 in Jul 05. Ch 3 wastes time rambling about SMP, threads, operating systems, and other topics I can better learn in a non-Snort book. I also liked reading how to install Snort 2.4.3 on OpenBSD in a book about Snort 2.6.x. Ch 3 also featured such pearls of wisdom as recommendations to not run Metasploit but instead use worthless stateless tools like Snot and Sneeze (p 123).

A few more choice words could be said about these disasters. Check out the "three way handshake" diagram on p 238 that shows FIN ACK / FIN ACK / FIN, and the "graceful close" diagram on p 239 that shows FIN / FIN ACK / ACK / ACK. These sorts of train wrecks are evidence that someone is asleep at the publishing house. Returning to the old material theme for ch 9, be prepared for screenshots or output from BASE 1.0.2 from Jul 04, Sguil 0.3.1 from Apr 04, and SnortSnarf from Jan 03. Finally, ch 12: why bother?

I have a few positive comments. The best chapter in SIAIT is ch 5 (Inner Workings). I liked seeing Afterglow, Tenshi, and SEC in ch 9. I enjoyed hearing something about performance profiling in ch 6. I thought the rules chapter was ok, but (to repeat a plea from my earlier reviews) would someone please consider writing a real rule writing reference that exceeds the introductory material found in this book and elsewhere? We also need coverage of shared object rules and other advanced Snort features.

It should be clear by now that the Syngress Snort book procession needs to end. Another publisher should consider writing a real Snort book for version 3.0 once it is available.

This book is an excellent starter into the world of IDS/IPS. Would be nice if they went thru on only 2-3 platforms instead of 10. THere should be a follow up book after this to go more in depth. Still very valuable information here though.

Product Details :
Paperback: 768 pages
Publisher: Syngress (February 1, 2007)
Language: English
ISBN-10: 1597490997
ISBN-13: 978-1597490993
Product Dimensions: 8 x 1.5 x 10 inches

More Details about Snort IDS and IPS Toolkit Jay Beale's Open Source Security 1st edition

or

Download Snort IDS and IPS Toolkit Jay Beale's Open Source Security 1st edition PDF Ebook

Advanced Persistent Threat: Understanding the Danger and How to Protect Your Organization 1st edition, Eric Cole



I would like to start off with the bottom line first. There is a LOT of great information in the book, but the layout of the book makes it a bit hard to find the key points even with the incredibly detailed table of contents. Syngress should adopt call outs, text boxes and other publishing techniques to highlight key information instead of producing one huge "run on" manuscript.

In light of that what I would like to do in this review is highlight some of the practical tips in the book. A major theme is that while protection is ideal, detection is a must. Dr. Cole, a practitioner in the field, has learned what we all need to understand. The odds are very high that any organization is already compromised. The key is to detect the information as the attackers try to exfiltrate it.

Some other points, that are not to be missed:
Page 15 Do not allow HTML mail unless you absolutely need it for your business
Page 16 Do not allow documents with macros unless you absolutely need it for your business
Page 29 Activity does not equal security, tackle the highest priority risk
Page 31 Assume the attackers are already in your network
Page 39 Focus on protecting your critical data (data centric security)
Page 71 237 rules in your firewall equals ANY ANY ANY ANY - ALLOW
Page 91 The advice here will not be popular, but if you do not absolutely need it for your business, get rid of it
Page 107 The entire section on data classification is a must read, must implement
Page 140 More hard, but valuable advice, do not allow email attachments unless you absolutely need them for your business
Page 176 Repeat after me, users are the target, this is the root of most successful attacks
Page 193 Begins a section on the 20 Critical Controls - read, memorize and act
Page 212 You cannot fight the cloud (amen)
Page 234 The APT Defendable Network section is a must read
Page 243 Expands on the points on page 29, glad that got fleshed out
Chapter 11 talks about some common sense solutions including sandboxing and whitelisting. For the life of me, I cannot understand why more organizations have not adopted both
Chapter 12 is essentially a recap. A suggestion to the reader is read chapter 12 first. It is filled with a number of key points that you can pick up when you read the rest of the book.

I have known Dr. Cole for several years and he is an amazing presenter, teacher and cyber security professional. In his latest book he really captures the essence of the APT and describes it in a manner that can actually help organizations protect against it. There has been much talk about APT for some time now - it is time we take action. Dr. Cole gives organizations specific and actionable items that can be taken to properly detect and defend against the advanced adversary. In this book you will find a blueprint for success. The APT is a very challenging threat that requires a new approach to properly protect against it. Most organizations are failing. The author does a great job of laying out a scalable solution to this daunting problem.

Having worked for several large financial institutions in cyber security, organizations have been challenged by the APT and how to deal with it. Spending money alone is not enough to protect an organization. In this well written book, Dr. Cole provides a step by step, actionable plan organizations can take to start implementing effective security. In addition to traditional measures, Dr. Cole provides proven creative solutions that organizations can take to minimize the impact of the advanced adversary. Definitely a must read.

Plenty of people could have written a book on the APT, but Dr. Cole has the vast experience across multiple industries to write the definitive book.

This could have been merely a "fun" and easy to read book capitalizing on the latest buzzwords, terms, and acronyms like APT, and that could have been good.

Instead this book, which while a fun read, has practical advice from in the trenches on how to combat persistent and dedicated attackers who often have vast resources, such as that of nation-states and other formidable adversaries.

No hype, just what works, and with a fascinating section on "The Future and How to Win."

Being in sales and marketing we hear customers talk about the APT and you can see the discouragement on their face because they are not sure how to effectively deal with this new threat that has emerged. In this easy to read but very insightful book Dr. Cole brings to life the problem and shows a structured detailed plan that organizations can take to properly detect and defend against the APT. This book is written in such a way that it has value to anyone who works in business or is involved with running a business. If you have not ordered a copy you need to do so today.

APT is rapidly becoming the cyber menace of concern. Given the continuous and specific targeting of an organization by highly skilled intrusion experts using the best of techniques, the probability of loss, theft, and damage to organizations has reached new heights. Advertised loss can seriously harm customer confidence and business and intellectual and sensitive information may be compromised. Traditional security measures are basically ineffective. To counter this threat, one of our best national network security experts has removed much of the pain in learning how to counter the APT facing us. Dr. Eric Cole has provided hope in the form of expert guidance. As a highly regarded national resource in advanced network security, Dr. Cole has managed to present the details of a highly complex topic in such a way that all can achieve a clear understanding of this threat. Known as an outstanding teacher, Dr. Cole has extended his method of teaching through example in this book, as he has in his many other books. The examples are clear, concise, and highly informative. Furthermore, his mastery of protective measures is interwoven throughout the book to demonstrate how to actually counter the APT. One can try and go to a variety of sources and vendors to try and counter the APT, or one can go to this one book. Dr. Cole's recent work demonstrates why he is so highly regarded. In my recent book, Predicting Malicious Behavior: Tools and Techniques for Ensuring Global Security, I describe how to anticipate malicious intent and behavior, including network threat. As a security professional, Dr. Cole's new book is now my number one resource to guide my continuing work.

Simply put Dr. Cole seems to have a knack for making the very complex subject of network security easily understandable, while at the same time captivating the reader. In this book on APT, he gives organizations a new way of going after the adversary with tips and tricks that actually work and that can be implemented today. In my consulting practice this is a book that I will definitely recommend to my clients. It is written in such a way that it provides valuable insight and actionable plans to mitigate risk that can immediately be taken not only by the hands-on IT staff but also up the ladder through management all the way up to the CEO. As organizations start to think that there is nothing they can do about advanced threats, this book provides a blueprint for success. If you want an action plan for dealing with today's more determined adversary in this new world of "APT" then this is the authoritative text that you must have.

Dr. Cole does an amazing job of explaining how to build a defensible network. His real world examples bring the subject matter to life. I have heard the term APT used but never really understood what it meant and most importantly what could be done about it. In this book, the subject matter is brought to life with practical ways to defend and detect the advanced threats that are targeting networks of all sizes. There is so much workable knowledge that the book would be worth it even if it was five times the price. This is definitely a must read for anyone involved in security.

Product Details :
Paperback: 320 pages
Publisher: Syngress; 1 edition (November 27, 2012)
Language: English
ISBN-10: 1597499498
ISBN-13: 978-1597499491
Product Dimensions: 9.2 x 7.4 x 0.9 inches

More Details about Advanced Persistent Threat: Understanding the Danger and How to Protect Your Organization 1st edition

or

Download Advanced Persistent Threat: Understanding the Danger and How to Protect Your Organization 1st edition PDF Ebook

Monday, May 13, 2013

Windows® Communication Foundation 4 Step by Step 1st edition, John Sharp



The book is very complete and very good detail and explains the exercises and examples are clear. I recommend it.

Its practical learn-by-doing approach works well for me. Chapter 1 provided a walk-through example that I was able to adapt to create a working prototype of the app I had in mind when I set out to learn how to use WCF, so I don't think I'll need much more for now. My goals were pretty simple-- I wanted a data source for a SharePoint/InfoPath solution that was not tightly coupled to the database server.

Great book that covers WCF in detail. Assumes a good working knowledge of .NET Framework, C#, entity framework, data access. Helped me get up to speed on web services. Well written, lots of examples,sample code included for each chapter. Worth the time and money. Highly recommend.

I have completed 5 chapters of the book but it's getting harder for me from there on. I can follow the steps but "why" are we doing it that way? That's what I am unable to understand fully ! Author explains it but I think it's probably because my knowledge in distributed systems, networking, http ptotocol, tcp/ip is not very good. Reader must be good at networking concepts and then it will be fine. If you are good at networking stuff and have got some knowledge of distributed computing then this book is fine for you. It explains everything step by step and you would be able to complete it. I have taken a break from this book and am spending time learning networking concepts (HTTP programming from Jeff Heaton book). I will give it 5 ratings because you cannot get stuck at any point because everything is basically spoon fed. At the end you will have a working program. By the way, you do not need any database knowledge, its just the initial setup that requires it.

Hi, This book is about WCF (Windows Communication Foundation) which is Microsoft's API for building SOA (service oriented application) infrastructures. SOA is very important because todays devices (especially tablets, smartphones, IPADS). all need to make HTTP calls to some URL addressable endpoint, whether it be SOAP based, REST based or just simple HTTP xml services. HTTP over TCP/IP is the universal transport mechanism for all these web-enabled devices. Lest we forget, SOA's also can serve as the building blocks for calls to get data for websites, Silverlight or FLASH based apps as well.

I am very interested in SOA architectures and believe that they are very important to any organization's IT department as a mechanism to eventually have "building blocks" of services which make the application of business logic or some type of workflow process easier to consistently apply this logic across the organization.
It also allows organizations to more rapidly build applications because once you have an SOA architecture in place, these services can be called from any client-side environment such as a web page, mobile device, tablet or whatever else may come down the pike.

Another key advantage is the fact that SOA's usually use standardized data exchange formats such as XML or JSON so that different devices from different manufacturers (android/IOS/Blackberry/Windows Phone) all can understand the data while abstracting away concepts such as operating system type or CPU architecture etc.. In other words, SOA's when correctly built are platform agnostic.
The first several chapters of the book cover pretty much what you would expect from any WCF book, things like what WCF is, what is SOA, how and where can WCF be hosted (for example WCF is designed to be very flexible, the services built within WCF can be hosted in IIS, run as a windows service and can also use different protocols (HTTP, TCP/IP, PEER to PEER) and also can be secured in a variety of ways (WINDOWS security, FORMS authentication, SSL certificates, custom authentication hooks)).
Fairly complex topics such as service endpoints, hosting services, bindings, fault propagation are covered in an easy to understand manner in the first couple of chapters.
Chapters 4 and 5 deal with a critical topic which is how to protect your services (authentication and authorization). These chapters do a pretty good job of describing the challenges for services that may be hosted on an internal corporate network as opposed to services which will be URL accessible across the internet. These topics are critical to the success of any SOA architecture because if you do not have a way of identifying and granting access to who may call your services, you can run the risk of exposing your data in a manner which you did not intend to. Remember, these SOA architectures are exposed as http endpoints across the world wide web! Make sure you understand security implications before you get too far. In my opinion implementing SSL for your service endpoints exposed in the WWW is a must for most organizations unless you have in mind very simple services such as returning the current temperature for a given zip code (in other words, things that you do not necessarily want secured, maybe something like the time a movie is showing at a particular theatre).

One topic dealing with authentication/authorization is called federated (claims based authentication/authorization). This was given very little coverage in the book, I can understand why though, because there are entire books written about the subject. I did find it disappointing that so little mention was made of federated (claims based authentication/authorization). For excellent coverage of this topic look for the book titled Programming Windows Identity Foundation by Vittorio Bertocci.

Chapter 6 deals with service contracts and data contracts which are a way of structuring your WCF programming. Service contracts describe the operations your service supports (it basically defines an implementation interface) and data contracts are important because that is how you get the "platform neutrality" that maximizes the usage of your WCF services. In prior programming projects using regular "web services"), I was guilty of sending back very .net specific data structures such as ado.net datasets. In today's world, it's much more critical that you use data contracts (and data members) which will cause WCF to generate very neutral generic return data structures that are recognizable by all platforms. This is because today we see the rise of android, IOS (ipad), Windows Phone, java devices, blackberry etc... The future will see the advent of many more connected devices, some we have not yet even dreamed of as of yet.

Chapter 7 deals with WCF state and how to preserve state, usually http based services are stateless, but there are ways of persisting session state between calls.

Chapter 8 brings into the picture, mind blowing power which comes from integrating WCF with Windows Workflow foundation services, which is a true workflow API built into the .net framework, this is how you can truly build stateful service calls built upon the concept of "workflows" by using the workflow engine. The windows workflow engine can persist a workflow inside of sql server and "rehydrate" that workflow right back where it left off, very powerful!
The rest of the book covers topics such as transactional processing with WCF services, reliable sessions and asynchronous calls. There is a nice chapter (Chapter 13) on how to support features such as service throttling, MTOM protocol (sending binary objects efficiently across HTTP) and streaming data (such as video streaming).
One of the more interesting topics is the SOAP protocol versus RESTFUL services debate raging in today's world. (read some of the links below)
[...]
[...]
[...]
[...]

Chapter 15 has a nice chapter on RESTFUL services based upon ODATA (AKA WCF data services). I read this chapter and got a lot of useful information about it, as mentioned many of these chapters are topics that actually have whole books written about them. WCF by default is SOAP based, but it also supports the concept of building REST services. I encourage you to read more about REST services, because I believe ultimately most SOA's are going to be built using this type of architecture. As a matter of fact, for those of you interested in SharePoint, SharePoint 2010 now has a REST based callable SOA based upon WCF data services. It has a few quirks, but once I understood it, I was amazed at how powerful and easy to use the SharePoint REST based API is.
Not covered at all is another WCF based technology called WCF RIA services, which is mostly used from what I have seen in Silverlight projects. I was a little disappointed that no mention was made of this technology, at least a paragraph or two should have been included.
There is also an exciting new WCF based api they are calling WCF web api which was too new for the author to include in this book, I am following this WCF web api because it looks very promising, I predict really powerful and useful things to come from this WCF web api.

([...])

CONCLUSION
All in all, I would consider this book an intermediate level book on WCF, the book gives a nice overview of WCF although it's missing a few topics I would have liked to at least have seen mentioned. I did like the REST chapter of the book a lot, because you would be surprised how many WCF books don't even deal with REST at all.
Certainly I would highly recommend this book as a gateway to other more detailed WCF books such as Juval Lowy's excellent Programming WCF services book, there are several very nice O'Reilly books that cover REST.
The author does a good job at covering WCF at a high level, but with some good levels of detail. The topic of WCF could easily cover thousands of pages, so the author should be commended at being able to produce a good, intermediate level WCF book with the amount of space he had to work with (700 pages).
I do like this book and give it 4.5 out of 5 stars and recommend it.
Thank you for reading my book review.

The book is thick and full of information but if you're like me who has no idea what a WCF to start with, and in a hurry to learn the concepts for your project and have no time to browse through the pages, then I would suggest getting Mike Liu's book.

I'm using this book as reference after I have created my services because there are a lot of things I need to learn and understand about WCF that this book fully explains. Just four stars because I'm not really a fan of thick books just to get the point across. I've learned to create my services in 4 short chapters in the other book while I have to read so much pages with this book.

This is truly the most usual review I have ever given a software text. For me, the author's style of writing and instruction are top shelf. That being said, I have wasted several full days just getting Windows 7 to do what the author needs to be done in order to get through the simple exercises in Chapter 1 and Chapter 2. I'm sitting here on my iMac typing this review while Windows 7 is loading for the 3rd time with the message, "This may take several hours to complete". After this is done, I suspect the two second click of the mouse I need to perform will happen without difficulty--or not. The last several hour re-load of the OS did get me most of the way through Chapter 1. This 3rd reload is at the start of Chapter 2.

Now, mind you, it isn't the author's fault that Microsoft's operating system won't do what he tells me to do. It isn't his fault that I have spent countless hours at this point surfing the Internet looking for fixes to these OS setup issues--and there are issues a plenty on blogs all over the Net from Microsoft and others. It isn't his fault that I'm reinstalling the software a 3rd time either. However, this book is from Microsoft Press, so I expect these dozen or so settings that keep failing to at least be in the errata part of the book's website--they aren't.

So, I'm giving this book a low score and I'm only on Chapter 2. This is unfair to the author as has probably spent hours, even days, at giving painfully detailed instructions, while I spend 5 minutes writing a review to trash those instructions as not doable. However, in fairness to you--the buyer--you need to be prepared to make a large commitment to surfing the Internet and reinstalling the operating system repeatedly to enjoy this author's hard work. I wasn't prepared for that, and I still am not prepared to do that. But at this point, it looks like MS is the problem and another book might now solve the issues that keep cropping up.

Well, let's see, the PC says that Windows 7 is 10% through the 3rd reinstall I've done in 4 days, so I guess I'll go mow the lawn for the afternoon instead of learn WCF.

Mr. Sharp, I do apologize. This low review is targeted to alert people to your publisher's defects in meeting the requirements you offer in your writing and not your writing style. I'm sure that with all your expertise, you have avoided the pitfalls that are giving me yet another wasted day. I do dread Chapter 3 at this point more than a trip to the dentist.



Product Details :
Paperback: 736 pages
Publisher: Microsoft Press; 1 edition (November 30, 2010)
Language: English
ISBN-10: 0735645566
ISBN-13: 978-0735645561
Product Dimensions: 5.9 x 0.6 x 9.8 inches

More Details about Windows® Communication Foundation 4 Step by Step 1st edition

or

Download Windows® Communication Foundation 4 Step by Step 1st edition PDF Ebook

Saturday, May 11, 2013

Cyberpower and National Security 1st edition, Franklin D. Kramer



“Experts in the field of ‘cyberpower’ address a range of issues arising from the use of cyberspace by malevolent actors and ‘the many security vulnerabilities that plague this sphere.’ Both the theory and practical application of cyberpower are discussed.”

"Cyberpower security is now one of the major national security problems facing the United States. This book recognizes and emphasizes the need for the government to develop a holistic approach to cyberpower; without this awareness and commitment, our national security is in jeopardy."


"It's about time! After nearly 20 years, finally, a well-thought-out, analytical compendium of the current state of the art. The challenge is implementing these ideas in a meaningful manner that provides true cybernational security against a world of asymmetric actors. This is going to be one of my primary references for years to come."

"National Defense University [NDU] is the trailblazer in thinking about cyberpower. This book and the workshops NDU convened while it was drafted provide some of the absolutely best thinking around on how cyber is reshaping the exercise of power and what that will mean for American security."

"This book not only offers an inside look at military cyberpower, tactics, and strategies, but also gives a unique look at cyber deterrence, cyber law, and opportunities for future research. In today's cyber environment, the United States must work diligently to not only keep up with our near-peer competitors, but to stay one step ahead of them. Cyberpower and National Security explores policy issues, theories, trends, and future technologies that can give the United States that edge in the cyber domain"


Last week at the InfowarCon Dan Kuehl handed me a copy of "Cyberpower and National Security." This has been a topic Dan has been exploring in some detail for quite a while. I first met Dan in 1996 when I was a student at the USMC Command and Staff College. Dan was already writing and exploring concepts related to cyber power and information warfare, and his deep focus and insights into this still emerging mission area continues today.

About the book, it is big. Not just in pages (it weighs in at 642 pages). It is big in info. Chapters are written by some of the greatest thinkers of the Cyber War mission area. Folks like Dan Kuehl, Edward Skoudis, Greg Rattray, Martin Libicki, Irving Lachow, Tim Thomas, Tom Wingfield and of course the editors Franklin Kramer, Stuart Starr and Larry Wentz. These and the other contributors are all well respected thought leaders and each provide insights I believe will be of use to today's strategic planners.

As for the content, it starts with a great foundation and overview of what is meant by Cyberspace (building on Dan Kuelh's well articulated definition) and also spells out key issues that policy makers and national security strategists must tackle. It then spells out changes in cyberspace including projections into the near future, and ends with an analysis of the impact of all these changes- including the considerations we must think through in our strategic deliberations.

I now consider this book a critical foundational work that should be studied by anyone who seeks to dialog on modern national security issues. This book does for the strategic domain what the Common Audit Guidelines did for the operational cyber domain. Cyberpower and National Security (National Defense University)

The National Defense University, the sponsor of this book, has produced an excellent collaboration on the related subjects of Cyberspace and Cyberpower and their influence on National Security. The authors selected for this effort appear remarkably competent for the task and have together produced a highly informative and useful book.
Unlike so many books in this genre, this book begins with an accurate and well developed definition of "cyberspace" that brings the concept from a vague buzzword to a concrete multi-tiered system. The authors of this book are particularly adept at identifying and analyzing the layers and protocols that constitute cyberspace. Perhaps most importantly one chapter discusses the role of the Department of Defense developed Global Information Grid (GIG) which is base for military use of cyberspace. Although the book makes a valid reference to the misnamed Global Network, it fails to note that the GIG actually is a component of this network. Still it nails the concept of cyberspace very accurately.
Given its sponsor the book of course devotes a good deal of attention to the military use of cyberspace particularly in its central role in the latest iteration of command and control doctrine called `Command, Control, Communications, Computers, Intelligence, Surveillance, and Reconnaissance' (C4ISR) which the basis for the "network centric warfare" concept which has been widely adopted by the U.S. Navy and Air Force. Still the book also includes information of considerable importance to non-military applications of cyberspace and the concept of civil infrastructure protection.
This leads to the concept of cyberwar in which an enemy tries disrupt or destroy targeted military and civilian computer networks by means of hostile computer systems. The prospect of cyberwar is the foundation for one of the most interesting series of discussions in this book on the subject of"cyberpower."
The late U.S. Navy Admiral Arthur Cebrowski was a strong advocate for the evolution of naval command and decision systems to C4ISR systems. He also had a very significant idea on cyberspace, which he argued was the new "commons" on which 21st Century commerce would depend. This represented a modernization of A.T. Mahan's concept that the sea represented the `commons' on which maritime commerce was based. ("Transforming Military Force", Praeger 2007). In this book it is argued that cyberpower is analogous to sea power and a 21st Century mission of the U.S. Military is to acquire and maintain control over cyberspace much as it remains the Navy and Air Force missions to acquire and maintain control over the sea and air.
This book is one the most complete and technically accurate books written to date on the increasingly important issues of cyber warfare and cyber security.

I like the book and I like the authors and I do NOT like the fact that neither decision-support nor intelligence (decision-support) nor M4IS2* are in this book. Retired Reader's review--at five stars--is the review I would have written were I to read the book rather than just appreciate it via Look Inside the Book, and he and I have discussed the intellectual and leadership vacuum we all have in cyberspace where most simply have no idea what they are doing.

* Multinational, Multiagency, Multidisciplinary, Multidomain Information-Sharing and Sense-Making (M4IS2)

I must defer to Retired Reader and Bob Gourley on the good of this book, and hence five stars from em as well. However, and with proper regard for the the vastly experienced and well-intentioned authors, it troubles me that they do not include core concepts and context such as were developed by Robert Garigue, who died at the age of 55 before being able to produce his master work. His Preface to my third book, Information Operations: All Information, All Languages, All the Time and a couple of his briefings that I have featured at Phi Beta Iota the Public Intelligence Blog, are all that we have to remember his towering genius. As with all my books, all free online.

Here is Robert Garigue's bottom line: cyber-power--and cyber-security and what some would call today cyber-command (actually an oxymoron) are about TRUTH & TRUST. All this stuff about protecting legacy systems that are 90% rubbish or interdicting and interfering with the 10% of our enemies that have sophisticated system, is out of touch with reality. The Chinese have whipped our butts on both stealth and riding electrical circuits into NSA's computers and they did it because we pretend that spending money on contractor vapor-ware (SAIC's Trailblazer comes to mind) is somehow equivalent to being competent at something useful.

This brings me to the bottom line: cyber-power does not exist in a vacuum. It is, like a weapon, an extention of the humans that it serves or empowers. Right now US cyber-power is--to the extent it is even relevant or effective--being managed by gerbils (Madeline Albright's term, not mine) for utterly unsound and intellectually as well as morally bankrupt ends--and it is not doing a single thing to help infantry squads see over the next hill, survive improvised explosive devices that still cannot be detected (on behalf of the Marine Corps, my #1 requirement for MASINT in 1988 after seeing the wood-encased IED's in El Salvador in 1979-1980) and on and on.

I take the time to provide this extended comment here because I agree with Retired Reader and Bob Gourley and others--this book is important. It is however, terribly incomplete and out of context, and that is something I would like to see NDU correct as soon as possible. Cyber-power is strategic, operational, tactical, and technical; it should TRANSFORM how we do policy, acquisition, and operations, to include enabling multinational "eight-tribe" operations in which cyber-power HARMONIZES a shared view of the challenge, the solution, and the campaign.

I have a graphic at Phi Beta Iota that I used in my presentation to NSA in Las Vegas, from Mich Kabay, on Cyber-Threat 101. FIFTY PERCENT is from errors and omissions--and I will just quote Paul Strassmann, at the time (1992) Director of Defense Information--"Information Technology makes bad management worse!" We are throwing money at vendors in the name of cyber-power when there are only 67 people in the USA doing code-level research on information security, and none of them work for a vendor. [See my piece 2010: OPINION--America's Cyber Scam in Homeland Security Today.] We are doing nothing on the tri-fecta of cyber-power, open spectrum, free/open source software, and open source intelligence. The government managers do not have a strategic framework (cyber is about humanity, not computers), they have no clue how to evaluate the vapor-ware claims of the vendors, and they will all be long-retired before they can be held accountable for blowing hundreds of millions of dollars (witness the last five or six NSA chiefs).

I could go on but I will save the rest for anytime in the future that NDU wants to think about Round II.

Argh. 5 stars for intent, 4 stars for missing half the picture, 5 because Retired Reader and Bob Gourley cannot be denied.

Product Details :
Paperback: 664 pages
Publisher: Potomac Books Inc.; 1 edition (April 2009)
Language: English
ISBN-10: 1597974234
ISBN-13: 978-1597974233
Product Dimensions: 5.9 x 1.5 x 9.1 inches

More Details about Cyberpower and National Security 1st edition

or

Download Cyberpower and National Security 1st edition PDF Ebook