About
Chris Sanders is an information security author, trainer, and researcher originally from…
Articles by Chris
Activity
13K followers
Experience
Education
-
Baylor University
-
-
My research sits at the intersection of cyber security, education, and cognitive psychology. My primary focus is identifying skills and traits that make analysts successful when conducting investigations.
-
-
-
-
-
-
Licenses & Certifications
-
GIAC Security Expert (GSE)
SANS
Issued -
Certified Ethical Hacker (CEH)
EC-Council
-
Certified Wireless Security Professional (CWSP)
P3 Wireless
-
CISSP
ISC2
-
GIAC Certified Incident Handler (GCIH)
SANS
Credential ID 13574 -
GIAC Certified Intrusion Analyst (GCIA)
SANS
Credential ID 5993 -
GIAC Penetration Tester (GPEN)
SANS
Credential ID 7520 -
GIAC Reverse Engineering Malware (GREM)
SANS
Credential ID 3151 -
Microsoft Certified Information Technology Professional (MCITP)
Microsoft
Publications
-
Applied Network Security Monitoring
Syngress
See publication“How do I find bad stuff on the network?”
The path to knowledge for the practice of NSM typically always begins with that question. It’s because of that question that we refer to NSM as a practice, and someone who is a paid professional in this field as a practitioner of NSM.
Unfortunately, when I started practicing NSM there weren’t a lot of reference materials available on the topic. Quite honestly, there still aren’t. Aside from the occasional blog postings of industry…“How do I find bad stuff on the network?”
The path to knowledge for the practice of NSM typically always begins with that question. It’s because of that question that we refer to NSM as a practice, and someone who is a paid professional in this field as a practitioner of NSM.
Unfortunately, when I started practicing NSM there weren’t a lot of reference materials available on the topic. Quite honestly, there still aren’t. Aside from the occasional blog postings of industry pioneers and a few select books, most individuals seeking to learn more about this field are left to their own devices. I feel that it is pertinent to clear up one very important misconception to eliminate potential confusion regarding my previous statement. There are menageries of books available on the topics TCP/IP, packet analysis, and various intrusion detection systems. Although the concepts presented in those texts are important facets of NSM, they don’t constitute the practice of NSM as a whole. That would be like saying a book about wrenches teaches you how to diagnose a car that won’t start.
With that in mind, my co-authors and I are incredibly excited to announce our newest project, a book entitled “Applied Network Security Monitoring”. This book is dedicated to the practice of NSM. This means that rather than simply providing an overview of the tools or individuals components of NSM, we will speak to the process of NSM and how those tools and components support the practice. -
Practical Packet Analysis, 2nd Edition
No Starch Press
See publicationThis significantly revised and expanded second edition of Practical Packet Analysis shows you how to use Wireshark to capture raw network traffic, filter and analyze packets, and diagnose common network problems. Take control of your network today!
Wireshark is the world's most popular "packet sniffer," allowing its users to uncover valuable information about computer networks by analyzing the TCP packets that travel through them. This significantly revised and expanded second edition of…This significantly revised and expanded second edition of Practical Packet Analysis shows you how to use Wireshark to capture raw network traffic, filter and analyze packets, and diagnose common network problems. Take control of your network today!
Wireshark is the world's most popular "packet sniffer," allowing its users to uncover valuable information about computer networks by analyzing the TCP packets that travel through them. This significantly revised and expanded second edition of Practical Packet Analysis shows you how to use Wireshark to capture raw network traffic, filter and analyze packets, and diagnose common network problems. Author Chris Sanders begins by discussing how networks work and gives you a solid understanding of how packets travel along the wire. He then explains how Wireshark can be used to monitor and troubleshoot networks. Numerous case studies help you apply your newfound knowledge to your networks.
This revision offers more detailed explanations of key networking protocols; expanded discussions of wireless protocol analysis and an examination of network security at the packet level; expanded discussion of the meaning of packets and how they can offer insight into network structure; and new scenarios and examples. Whether fighting a virus infestation or a confounding connectivity problem, Practical Packet Analysis, 2nd Edition will help you find the problem and fix it.
-
Practical Packet Analysis
No Starch Press
See publicationIt's easy enough to install Wireshark and begin capturing packets off the wire--or from the air. But how do you interpret those packets once you've captured them? And how can those packets help you to better understand what's going on under the hood of your network? Practical Packet Analysis shows how to use Wireshark to capture and then analyze packets as you take an indepth look at real-world packet analysis and network troubleshooting. The way the pros do it.
Wireshark (derived from…It's easy enough to install Wireshark and begin capturing packets off the wire--or from the air. But how do you interpret those packets once you've captured them? And how can those packets help you to better understand what's going on under the hood of your network? Practical Packet Analysis shows how to use Wireshark to capture and then analyze packets as you take an indepth look at real-world packet analysis and network troubleshooting. The way the pros do it.
Wireshark (derived from the Ethereal project), has become the world's most popular network sniffing application. But while Wireshark comes with documentation, there's not a whole lot of information to show you how to use it in real-world scenarios. Practical Packet Analysis shows you how to:
* Use packet analysis to tackle common network problems, such as loss of connectivity, slow networks, malware infections, and more
* Build customized capture and display filters
* Tap into live network communication
* Graph traffic patterns to visualize the data flowing across your network
* Use advanced Wireshark features to understand confusing packets
* Build statistics and reports to help you better explain technical network information to non-technical users
Because net-centric computing requires a deep understanding of network communication at the packet level, Practical Packet Analysis is a must have for any network technician, administrator, or engineer troubleshooting network problems of any kind.
Technical review by Gerald Combs, creator of Wireshark
Organizations
-
Southeastern Collegiate Cyber Defense Competition (SECCDC)
Judge
- Present -
CyberPatriot
Mentor
- Present -
Charleston ISSA
Education Director
-Responsible for coordinating speakers and educational opportunities for the Charleston chapter of the ISSA. http://www.charleston-issa.org/
Recommendations received
2 people have recommended Chris
Join now to viewOther similar profiles
Explore top content on LinkedIn
Find curated posts and insights for relevant topics all in one place.
View top content