2022/01/02

Book review ‘Network Security Assessment’ (3rd)

Rating: ★★★★☆ (4 of 5 stars)

I can recommend reading the book even though it is from Dez. 2016 and therefore outdated in many topics. The book provides a great overview of the different network layers and assessment recommendations.

For me the chapters on lower network levels (OSI layer 2-3) were particularly interesting, as I did not have any assessment experience in those. Especially the sections on proprietary protocols were the most interesting ones for me in the book, for the same reason.

The linked articles in the book are awesome. Most topics are introduced superficially or just listed. If a topic caught your attention, the linked articles provide a great assistance to dig deeper into it.

Some topics are dealt with more detail, but some are just listed there for completion. I am aware that not everything fits into the book, but I had the impression some topics were randomly chosed to be described in detail while other topics were not.

Due to the short life cycle of vulnerabilities in my opinion the listing of CVEs concerning some products, protocols etc. is not very helpful as most are already “old” when the book is printed. Additionally looking up the CVEs heavily distrub the reading flow. Instead of listing some CVEs I would have hoped for other content.

Overall I think it is a great book to dive into the topic even though it is from 2016. In my opinion it has a lot of potential and I strongly recommend reading the linked articles regarding the topics you are interested in!