An Introduction to Intrusion Detection In the last three years, the networking revolution has finally come of age. More than ever before, we see that the Internet is changing computing as we know it. The possibilities and opportunities are limitless; unfortunately, so too are the risks and chances of malicious intrusions. http://www.acm.org/crossroads/xrds2-4/intrus.html
How to detect hackers on your web server A discussion of the methods used by hackers to attack IIS web servers, and how you can use event log monitoring on your web server to be alerted to successful attacks immediately. http://www.gfi.com/whitepapers/detect-hackers-on-web-server.pdf
How to perform network-wide security event log monitoring This white paper explains the need to monitor security event logs network-wide and how you can achieve this using GFI LANguard S.E.L.M. It is written by Randy Franklin Smith, author of the in-depth series on the Windows security log in Windows 2000 & .NET Magazine. http://www.gfi.com/whitepapers/networkwide-security-event-log-monitoring.pdf