Writing a book?
I did something the other day that I haven't had the opportunity to do in a while: visited a bookstore to browse for a new addition to my library.
As some of you may know, I'm past the point of needing a purely technical book. Most of my interests involve more than just learning a new tool. I was hoping to find a good book on "complex attack heuristics", but that is not a field that lends itself to a single book. Since most books are about "how" and not "why", I think I'm out of luck.
So, unless any of you know of a good book on risk-based analysis of audit trails, logfile correlation, or event scoring algorithms which maintain representations of known attack scenarios, I will probably start researching to write my own.
For this, I'll need as many post-intrusion analysis reports and logfiles as I can find. Reply if you have any good sources.
