Customer Service or Enrol: 0800 282 353 or +44 1372 364610
 

Detecting and Analysing Intrusions: Hands-On
Network Security Monitoring (NSM)

Course: 588   Type: Hands-On   Duration: 4 Days
Quick Enrol  

You Will Learn How To

  • Detect and analyse network- and host-based intruder attacks
  • Integrate intrusion detection systems (IDS) into your current network topology
  • Tune IDS operations using the latest tools and techniques
  • Scope and remediate intrusions with Network Security Monitoring (NSM)
  • Correlate IDS alerts with scanner vulnerability information
  • Enhance IDS detection by writing custom signatures

Course Benefits
IDSs are the most powerful tools for alerting analysts to network- and host-based exploits. In this course, you gain knowledge of how attackers break into networks, how an IDS can play a key role in detecting these attacks, and how NSM can be used to analyse these events. You also learn how to configure, deploy and tune an IDS to identify attacks, and how to use NSM techniques to resolve IDS alerts.

Who Should Attend
Those involved in maintaining network and system security. Participants should have knowledge at the level of Course 468, "System and Network Security Introduction", and a working knowledge of TCP/IP.

Hands-on Training
You gain hands-on experience using several IDS and NSM tools. Exercises include:
  • Exposing network attacks with Snort NIDS
  • Managing Snort with IDS Policy Manager
  • Detecting common Nmap scans
  • Monitoring enterprise security with BASE/MySQL/Apache console
  • Correlating Snort alerts with Nessus vulnerability scans
  • Tuning IDS for a successful detection
  • Resolving IDS alerts with Sguil
  • Catching server hacks with OSSEC HIDS
  • Performing risk assessment and event correlation with OSSIM
  • Writing custom Snort signatures

Introduction to NSM
Defensible networks
  • The enemy's plan of attack
  • Rapidly identifying intrusions
  • Utilising multiple detection components
The role of an IDS
  • Revealing violations of information assurance policies
  • Validating IDS events with NSM techniques
Navigating the IDS landscape
  • Classifying detection techniques by the attack time line
  • Investigating the Snort MySQL alerts database
  • Enhancing attack detection with honeypots
Deploying a Network IDS
Monitoring attacks on the network
  • Locating NIDS sensors
  • Operating sensors in a stealth mode
  • Detecting wireless intrusions with Snort-Wireless
Solutions for a switched network
  • Sniffing switches with Switch Port Analyzer (SPAN) feature
  • Connecting sensors with hubs and Taps
  • Combining outputs of a dual Tap
Uncovering intrusions in the enterprise
  • Designing a multilayer distributed IDS hierarchy
  • Consolidating with Security Management Systems
  • Ensuring reliability with IDS load balancers
Interpreting IDS Alerts
Identifying IDS signatures
  • Anomaly and misuse detection, stateful analysis and advanced string matching
  • Selecting raw and smart signatures
  • Improving signature quality for an exploit
  • Discovering IDS signature syntax
Discovering attacks with Host-IDS (HIDS)
  • Centralising logs with syslog
  • Analysing server and firewall logs for anomalies
  • Detecting log tampering
  • Querying logs with Microsoft Log Parser
Verifying IDS operation
  • Scanning with Vulnerability Assessment (VA) tools
  • Replaying traces of real attacks with tcpreplay
  • Crafting IP attack packets
Tuning the IDS
  • Minimising false positives with dynamic tuning and attack relevancy
  • Utilising event filtering, propagation, consolidation and parameter tuning
  • Aggregating multiple events
Evading IDS
  • Hiding Web attacks via SSL and polymorphic mutation
  • Overlapping IP and TCP fragments
  • Slicing packets with fragroute
Analysing Intrusions
Monitoring network security using NSM
  • Examining transcripts and sessions
  • Resolving an attacker's identity
  • Scoping the intrusion
  • Catching internal attacks with extrusion detection
Validating intrusions
  • Correlating IDS alerts with vulnerabilities
  • Congregating events from multiple sources
  • Capturing a high-level security view with event correlation
Classifying attack scenarios
  • Directly attacking servers
  • Indirectly attacking clients
  • Discovering island hopping attacks
Performing digital network forensics
  • Securing the sensor
  • Collecting evidence
Recognising Attacks
Scanning for low-hanging fruit
  • Footprinting an organisation
  • Detecting stealth port scans
Creating buffer overflow (BO)
  • Discovering remote BO attacks
  • Mutating BO exploits
Cyberextortion with Denial of Service (DoS)
  • Attacking with hacker botnets
  • Reflecting with DrDoS (Distributed Reflection DoS)

Related Courses
 

request more info Salutation*:

First Name*:

Last Name*:

Job Title:

Company*:

Post Code*:

Country*:
   Codes
Office Telephone*:

Extension:

E-mail*:

* Required

A Learning Tree representative will contact you to follow up your request for information.

Save 55%
Detecting and Analysing Intrusions

Participants detecting an attack using an intrusion detection system.

£ 1,695 - Standard Tuition
Savings Plans
£ 980 - 10-Day Training Pass
£ 915 - Flex-Training Passport
£ 1,460 - 10-Training Vouchers
£ 1,560 - 5-Training Vouchers
£ 1,525 - Alumni Gold Tuition

 
Certification Core Course
 
ISC2 32 A
 
Customer Service or Enrol: 0800 282 353 or +44 1372 364610