The security section at ApacheTutor currently offers reviews of leading books in the area of security with Apache. It may offer additional articles in future.
Several books on the subject of security with Apache are available. This review compares the most up-to-date of these:
Both of these have got good reviews elsewhere, and are worth reading if you're responsible for running a server. In reviewing them, I should also mention a third book which I haven't read but which has been well-received elsewhere:
Barnett is insightful on the Big Picture. He is chief of security at a big software and services company, and his book is in essence an apprenticeship to that job. Ristic is more of the classic textbook, and is the more thorough and comprehensive of the two if you're looking for a reference manual.
If your job is to run servers, keep the Ristic always to hand. If you're managing people who run servers, get both and read the Barnett yourself.
Barnett is chief of security at EDS, and project lead for the Apache security benchmark at the Center of Internet Security. His book is in essence an apprenticeship, taking in the tools, techniques and thought processes involved in his job.
For a techie book, this is very, very readable. Barnett's writing engages the reader, and guides you to think secure. He is a disciple of Sun Tzu (who he even mentions by name), and exhorts you to know the enemy. He makes great use of anecdotes to bring his points home. If you find it hard to motivate yourself to read techie books, this one will make a pleasant change. On the downside, the technical detail is rather patchy. In parts it's excellent, but there are also omissions and inaccuracies I find alarming. There are matters of detail in which I would firmly disagree with his recommendations, particularly where they have very severe performance implications (which he doesn't discuss at all).
The areas where Barnett offers more than Ristic focus on "Big Picture" insights, such as running a "honeypot" to gather intelligence on the threats active on the Web.
This article about filtering information leaks gives a feel for both what's good and bad about this book.
Ristic's principal claim to fame in the area is mod_security, the market-leader in web application firewalls, and the only open-source product in its class. In September 2006, Ristic's company Thinking Stone was acquired by Breach Security, Inc, with whom Ristic took up a senior position.
Ristic writes very well, though I find his style dryer and less engaging than Barnett's. As a manual, Ristic is the more thorough of the two by a clear margin, both in range of core server administration topics and depth of technical detail. Topics Ristic covers on which Barnett says little or nothing include:
Ristic, like Barnett, puts security ahead of performance. He does discuss performance issues, but it is not his strongest point. My main reservation there is in his coverage of mod_security. Using mod_security to scan and processes HTTP headers and log suspect events is cheap. But scanning incoming or outgoing bodies with it gets very, very expensive as the size grows. Neither author is clear on this important distinction.
Ristic also has one appendix, in which he briefly introduces a number of tools that may be of interest. Nicely written, with just enough description of each tool to motivate you to try it!