Books can be read when needed, so the continuous repetition of how dangerous SSL is, especially compared to the single sentence mentioning FireSheep, annoyed me.
The front cover says: " Learn to:
Identify key characteristics of modern malware
Recognize malware infections
Implement effective application and network controls
"
Modern malware uses common ports, can hop between them, and can access popular sites like Facebook to get instructions and even download malware through (zero-day) exploits.
This booklet sounds like application whitelisting doesn't exist, which is a shame as it could be an effective control. I guess it assumes kernel-level exploits.
The only effective control i gathered from it is to whitelist certain sites (even though those can also host malware, as mentioned briefly), and only for certain users, and to buy the stuff in the PaloAlto ad on the final page that supposedly decrypts SSL.
Surely there are free solutions like operating systems that enforce the principle of minimal privilege.
A good start for thos interested in what malware can do. It is a little scary at some points. It should be though. You will need to know a bit about computers to fully understand the book.