Skip to content

Network Security Resources

Standards & Frameworks

Standard Focus
NIST SP 800-41: Guidelines on Firewalls and Firewall Policy Firewall architecture and policy fundamentals
NIST SP 800-53 Security and privacy controls, including the System and Communications Protection (SC) family
MANRS (Mutually Agreed Norms for Routing Security) Industry-driven BGP/routing security best practices
CIS Controls v8 Control 12 (Network Infrastructure Management) and Control 13 (Network Monitoring and Defense)

Books

  1. Network Security Essentials (William Stallings) - foundational textbook covering cryptography through to network-layer controls
  2. Practical Packet Analysis (Chris Sanders) - the standard reference for learning Wireshark-driven investigation
  3. The Practice of Network Security Monitoring (Richard Bejtlich) - NSM methodology, written by a former Air Force/Mandiant/GE threat hunter

Courses & Certifications

  • CompTIA Security+ - entry-level, covers network security fundamentals alongside broader security topics
  • CompTIA Network+ - vendor-neutral networking fundamentals, a strong prerequisite before specializing in network security
  • (ISC)² SSCP - covers network and communications security as one of its domains
  • TryHackMe - Network Fundamentals - guided, hands-on rooms covering OSI/TCP-IP, Nmap, and traffic analysis

Tools

Traffic Capture & Analysis

Tool Purpose
Wireshark GUI packet capture and protocol analysis - the de facto standard
tcpdump CLI packet capture, available on nearly every Unix-like system including headless servers
Zeek (formerly Bro) Network security monitoring - generates structured, queryable logs of network activity rather than raw packet dumps

Intrusion Detection / Prevention

Tool Purpose
Suricata High-performance, open-source IDS/IPS with native multi-threading and protocol-aware detection
Snort The original widely-deployed open-source IDS/IPS, rule-based signature detection
Security Onion Free, source-available Linux distribution bundling Suricata, Zeek, Elasticsearch, Kibana, and CyberChef into a ready-to-deploy NSM/threat-hunting platform

Recon & Scanning

  • Nmap - port scanning, service/version detection, and scriptable recon (nmap -sV -sC -p- target)
  • Masscan - internet-scale port scanner, orders of magnitude faster than Nmap for broad sweeps (pair with Nmap for detail on found ports)

Hands-On Labs & CTFs

See Network Security Red Teaming & Labs for full methodology and the practice-lab list (TryHackMe, PentesterLab PCAP exercises, Hack The Box) - this page intentionally stays a reference index, not a duplicate of that content.

Blogs & Research

  • MANRS Blog - routing security advocacy and incident analysis
  • Kentik Blog - BGP/network observability research, including historical incident write-ups
  • Cloudflare Blog - Security - frequent deep dives on DDoS, DNS, and BGP incidents as they happen
  • Krebs on Security - investigative reporting that frequently covers botnet/DDoS/infrastructure attacks in depth

Where to Go Next on This Site

Credits/References

  1. NIST SP 800-41: Guidelines on Firewalls and Firewall Policy
  2. MANRS
  3. Zeek Network Security Monitor
  4. Security Onion