Network Security Resources
Standards & Frameworks
Books
- Network Security Essentials (William Stallings) - foundational textbook covering cryptography through to network-layer controls
- Practical Packet Analysis (Chris Sanders) - the standard reference for learning Wireshark-driven investigation
- The Practice of Network Security Monitoring (Richard Bejtlich) - NSM methodology, written by a former Air Force/Mandiant/GE threat hunter
Courses & Certifications
- CompTIA Security+ - entry-level, covers network security fundamentals alongside broader security topics
- CompTIA Network+ - vendor-neutral networking fundamentals, a strong prerequisite before specializing in network security
- (ISC)² SSCP - covers network and communications security as one of its domains
- TryHackMe - Network Fundamentals - guided, hands-on rooms covering OSI/TCP-IP, Nmap, and traffic analysis
Traffic Capture & Analysis
| Tool | Purpose |
| Wireshark | GUI packet capture and protocol analysis - the de facto standard |
| tcpdump | CLI packet capture, available on nearly every Unix-like system including headless servers |
| Zeek (formerly Bro) | Network security monitoring - generates structured, queryable logs of network activity rather than raw packet dumps |
Intrusion Detection / Prevention
| Tool | Purpose |
| Suricata | High-performance, open-source IDS/IPS with native multi-threading and protocol-aware detection |
| Snort | The original widely-deployed open-source IDS/IPS, rule-based signature detection |
| Security Onion | Free, source-available Linux distribution bundling Suricata, Zeek, Elasticsearch, Kibana, and CyberChef into a ready-to-deploy NSM/threat-hunting platform |
Recon & Scanning
- Nmap - port scanning, service/version detection, and scriptable recon (
nmap -sV -sC -p- target) - Masscan - internet-scale port scanner, orders of magnitude faster than Nmap for broad sweeps (pair with Nmap for detail on found ports)
Hands-On Labs & CTFs
See Network Security Red Teaming & Labs for full methodology and the practice-lab list (TryHackMe, PentesterLab PCAP exercises, Hack The Box) - this page intentionally stays a reference index, not a duplicate of that content.
Blogs & Research
- MANRS Blog - routing security advocacy and incident analysis
- Kentik Blog - BGP/network observability research, including historical incident write-ups
- Cloudflare Blog - Security - frequent deep dives on DDoS, DNS, and BGP incidents as they happen
- Krebs on Security - investigative reporting that frequently covers botnet/DDoS/infrastructure attacks in depth
Where to Go Next on This Site
Credits/References
- NIST SP 800-41: Guidelines on Firewalls and Firewall Policy
- MANRS
- Zeek Network Security Monitor
- Security Onion