2005-03-16

Richard Bejtlich

I had the distinct honor of meeting Mr. Richard Bejtlich on Monday for lunch. I first heard about Richard from Keith Jones, author of "The Anti-Hacker Toolkit", in a Foundstone course Keith was teaching. Keith told me I should contact Richard to discuss Snort and open source tools for network security monitoring. I never was able to get in touch with Keith after the class was over to get Richard's contact information, but it worked out in the end.

Richard gave a presentation at the February ISSA-NOVA meeting on network security monitoring. I contacted him after the meeting to see if we could get together, not thinking he would actually be available for a peon like me. :) But, I had to ask because the worst he could say was no. To my delight he wanted to meet for lunch, although it did take almost a month for us to set up a date and time.

Richard is very personable and exudes intelligence. I felt dumb just sitting at the same table with him. He brought a co-worker, I guess to make sure I wasn't some pyscho or stalker. We talked about my company and the customer we are on contract with. I talked about the frustration my shop has with the customer's security policies. We talked about network appliances such as the Niksun Net Detector and Sand Storm Net Entercept. Richard asked about providing some training for my group and I think it would be great. I am going to talk with my manager about scheduling some dates if possible. I know we would have to set up two dates to get everyone in.

To give Richard's book a plug, it is called "The Tao of Network Security Montioring, Beyond Intrusion Detection". It is an excellent resource for any information security professional, new or experienced. Richard also has a new book coming out later this year with Keith Jones called "Real Digital Forensics", which will be interactive and allows readers to actually work out some digital forensic cases. I can't wait for that!

0 Comments:

Post a Comment

<< Home