1-800-THE-TREE (1-800-843-8733)
TRAINING YOU CAN TRUST
 
 

Detecting and Analyzing Intrusions: Hands-On

Network Security Monitoring (NSM)
 
Course: 588   Type: Hands-On Training   Duration: 4 Days
 
 

You Will Learn How To

  • Detect and analyze network- and host-based intruder attacks
  • Integrate intrusion detection systems (IDS) into your current network topology
  • Tune IDS operations using the latest tools and techniques
  • Scope and remediate intrusions with Network Security Monitoring (NSM)
  • Correlate IDS alerts with scanner vulnerability information
  • Enhance IDS detection by writing custom signatures

Course Benefits

IDSs are the most powerful tools for alerting analysts to network- and host-based exploits. In this course, you gain knowledge of how attackers break into networks, how an IDS can play a key role in detecting these attacks, and how NSM can be used to analyze these events. You also learn how to configure, deploy and tune an IDS to identify attacks, and how to use NSM techniques to resolve IDS alerts.

Who Should Attend

Those involved in maintaining network and system security. Participants should have knowledge at the level of Course 468, "System and Network Security Introduction," and a working knowledge of TCP/IP.

Hands-On Training

You gain hands-on experience using several IDS and NSM tools. Exercises include:
  • Exposing network attacks with Snort NIDS
  • Managing Snort with IDS Policy Manager
  • Detecting common Nmap scans
  • Monitoring enterprise security with BASE/MySQL/Apache console
  • Correlating Snort alerts with Nessus vulnerability scans
  • Tuning IDS for a successful detection
  • Resolving IDS alerts with Sguil
  • Catching server hacks with OSSEC HIDS
  • Performing risk assessment and event correlation with OSSIM
  • Writing custom Snort signatures

Related Courses

 

Upcoming Dates

May 26 - 29, 2009
 Washington, DC (Rockville, MD)

For complete schedule, please visit www.learningtree.com
 
http://www.learningtree.com/courses/588pf.htm
 
 
1-800-THE-TREE (1-800-843-8733)
TRAINING YOU CAN TRUST
 
 

Detecting and Analyzing Intrusions: Hands-On

Network Security Monitoring (NSM)
 
Course: 588   Type: Hands-On Training   Duration: 4 Days
 
 
Course 588 Content
 

Introduction to NSM

Defensible networks

  • The enemy's plan of attack
  • Rapidly identifying intrusions
  • Utilizing multiple detection components

The role of an IDS

  • Revealing violations of information assurance policies
  • Validating IDS events with NSM techniques

Navigating the IDS landscape

  • Classifying detection techniques by the attack time line
  • Investigating the Snort MySQL alerts database
  • Enhancing attack detection with honeypots

Deploying a Network IDS

Monitoring attacks on the network

  • Locating NIDS sensors
  • Operating sensors in a stealth mode
  • Detecting wireless intrusions with Snort-Wireless

Solutions for a switched network

  • Sniffing switches with Switch Port Analyzer (SPAN) feature
  • Connecting sensors with hubs and Taps
  • Combining outputs of a dual Tap

Uncovering intrusions in the enterprise

  • Designing a multilayer distributed IDS hierarchy
  • Consolidating with Security Management Systems
  • Ensuring reliability with IDS load balancers

Interpreting IDS Alerts

Identifying IDS signatures

  • Anomaly and misuse detection, stateful analysis and advanced string matching
  • Selecting raw and smart signatures
  • Improving signature quality for an exploit
  • Discovering IDS signature syntax

Discovering attacks with Host-IDS (HIDS)

  • Centralizing logs with syslog
  • Analyzing server and firewall logs for anomalies
  • Detecting log tampering
  • Querying logs with Microsoft Log Parser

Verifying IDS operation

  • Scanning with Vulnerability Assessment (VA) tools
  • Replaying traces of real attacks with tcpreplay
  • Crafting IP attack packets

Tuning the IDS

  • Minimizing false positives with dynamic tuning and attack relevancy
  • Utilizing event filtering, propagation, consolidation and parameter tuning
  • Aggregating multiple events

Evading IDS

  • Hiding Web attacks via SSL and polymorphic mutation
  • Overlapping IP and TCP fragments
  • Slicing packets with fragroute

Analyzing Intrusions

Monitoring network security using NSM

  • Examining transcripts and sessions
  • Resolving an attacker's identity
  • Scoping the intrusion
  • Catching internal attacks with extrusion detection

Validating intrusions

  • Correlating IDS alerts with vulnerabilities
  • Congregating events from multiple sources
  • Capturing a high-level security view with event correlation

Classifying attack scenarios

  • Directly attacking servers
  • Indirectly attacking clients
  • Discovering island hopping attacks

Performing digital network forensics

  • Securing the sensor
  • Collecting evidence

Recognizing Attacks

Scanning for low-hanging fruit

  • Footprinting an organization
  • Detecting stealth port scans

Creating buffer overflow (BO)

  • Discovering remote BO attacks
  • Mutating BO exploits

Cyberextortion with Denial of Service (DoS)

  • Attacking with hacker botnets
  • Reflecting with DrDoS (Distributed Reflection DoS)
 
http://www.learningtree.com/courses/588pf.htm
 
 
1-800-THE-TREE (1-800-843-8733)
TRAINING YOU CAN TRUST
 
 

Detecting and Analyzing Intrusions: Hands-On Tuition

Network Security Monitoring (NSM)
 
Course: 588   Type: Hands-On Training   Duration: 4 Days
 
 

Course Tuition
$ 2,790 Standard Tuition
Tuition with a Savings Plan
$ 1,800 10-Day Pass
$ 1,670 Training Passport
$ 1,700 Premium-Pass
$ 2,200 Voucher 10-Pack
$ 2,515 Alumni Gold Discount
$ 2,484 Government Discount
 

 

Your Course Tuition Entitles You To...

  • Class participation
  • Team workshops
  • Use of in-class hands-on equipment
  • Comprehensive course materials
  • Morning and afternoon refreshments
  • Course Completion Certificate awarding Continuing Education Units
  • FREE participation in Professional Certification
  • FREE participation in College Credit programs (including related exams)
 
 

Tuition Savings Plans

Training Passport
  • 3 courses in 12 months
  • As little as $1,670 per course
  • Savings as much as 40%
  • Only $5,000
Premium Pass
  • 4 courses in 24 months
  • As little as $1,700 per course
  • Save as much as 45%
10-Day Pass
  • A NEW way to save on training
  • 10 days of training for one person
  • Save as much as $990 per course
  • Only $4,500
Training Vouchers
  • Save as much as $990 per course
  • Fully transferable
  • As low as $2,200 per course
Alumni Gold Discount Attend your first course and you'll receive a personalized Alumni Gold Discount card, entitling you to save as much as $305 on each course you take within the following 12 months. Take just one course each year and you'll be entitled to ongoing discounts...year after year!

Your Guarantee of Satisfaction

Unless you feel 100% satisfied that Learning Tree delivered even more than you expected, there is no fee for your course attendance. Our Guarantee of Quality lets you experience the value of the course--and then pay only if you feel the course was well worth the tuition.

Enrolling is Easy and Flexible!

Enroll by phone or online. If your plans change, just let us know and, without a fee, you can transfer to another course or cancel your enrollment. Pay after you've taken the course, and then only if you are 100% satisfied.

 
http://www.learningtree.com/courses/588pf.htm