SEC503: Intrusion Detection In-Depth
- Contents | Schedule | Additional Info
- Instructor: Mike Poor
- GCIA Certification
- 36 CPE/CMU
- Laptop Required
Learn practical hands-on intrusion detection and traffic analysis from top practitioners/authors in the field. This challenging track methodically progresses from understanding the theory of TCP/IP, examining packets, using Snort to analyze traffic, becoming familiar with the tools and techniques for traffic and intrusion analysis, to reinforcing what you've learned with a hands-on challenge of investigating an incident. Students should be able to "hit the ground running" once returning to a live environment where traffic analysis it required.
This is a fast-paced course, and students are expected to have a basic working knowledge of TCP/IP in order to fully understand the topics that will be discussed. Although others may benefit from this course, it is most appropriate for students who are or who will become intrusion detection/prevention analysts. Students generally range from novices with some TCP/IP background all the way to seasoned analysts. The challenging hands-on exercises are specially designed to be valuable for all experience levels. We strongly recommend that you spend some time getting familiar with tcpdump before coming to class.
TCP/IP
- Tcpdump Overview and TCP/IP concepts
- ICMP
- Fragmentation
- Stimulus - Response
- Microsoft Protocols
- Domain Name System (DNS)
- IPv6
Hands-On tcpdump Analysis
- Mechanics of running tcpdump
- General network traffic analysis
Hands-On Snort Usage
- Various modes of running Snort
- Writing Snort rules
Intrusion Analysis
- Intrusion Detection Architecture
- Intrusion Detection/Prevention Analysis
| Course Contents | Instructors | Schedule |
|---|---|---|
| SEC503.1: TCP/IP for Intrusion Detection | Mike Poor |
Wed Jan 16th, 2013 9:00 AM - 5:00 PM |
OverviewStudents will be able to translate native hexadecimal at the IP, transport layers, and some protocols such as DNS. The material presented in this day will give students the knowledge and understanding of TCP/IP and free tools, like tcpdump to assist them in troubleshooting all types of networking complaints from routing problems to firewall and critical server issues. CPE/CMU Credits: 6 TopicsRefresher of TCP/IP
TCP/IP Communication Model
IP Fragmentation
Internet Control Message Protocol (ICMP)
Stimulus and Response
Microsoft Protocols
Domain Name System (DNS)
IPv6
|
||
| SEC503.2: Network Traffic Analysis using Tcpdump - Part 1 | Mike Poor |
Thu Jan 17th, 2013 9:00 AM - 5:00 PM |
OverviewIn this two-day module, students will learn how to interpret header fields and values in a packet. We will build on that skill to learn traffic analysis with lab exercises to reinforce the theory. Tcpdump is the tool of choice selected to demonstrate the theory and is used in hands-on exercises. The intent of these days is to provide the foundation to enable the analyst perform packet/traffic interpretation. Note: This course is available to Security 503 participants only. CPE/CMU Credits: 6 TopicsIntroduction to Tcpdump
Writing Tcpdump filters
Tcpdump filters
Examining Datagram fields with Tcpdump
Analysis of Tcpdump output
Advanced analysis
Application protocols and detection
|
||
| SEC503.3: Network Traffic Analysis using Tcpdump - Part 2 | Mike Poor |
Fri Jan 18th, 2013 9:00 AM - 5:00 PM |
OverviewIn this two-day module, students will learn how to interpret header fields and values in a packet. We will build on that skill to learn traffic analysis with lab exercises to reinforce the theory. Tcpdump is the tool of choice selected to demonstrate the theory and is used in hands-on exercises. The intent of these days is to provide the foundation to enable the analyst perform packet/traffic interpretation. Note: This course is available to Security 503 participants only. CPE/CMU Credits: 6 TopicsIntroduction to Tcpdump
Writing Tcpdump filters
Tcpdump filters
Examining Datagram fields with Tcpdump
Analysis of Tcpdump output
Advanced analysis
Application protocols and detection
|
||
| SEC503.4: Intrusion Detection Snort Style | Mike Poor |
Sat Jan 19th, 2013 9:00 AM - 5:00 PM |
OverviewInstall, configure, and use the powerful and versatile freeware intrusion detection system - Snort. In addition, learn to customize Snort for many special uses. Hands-on exercises that will challenge both the novice and seasoned Snort user are included so that students will feel confident in their ability to effectively utilize Snort for their site's specific needs when they get back to the office. Note: This course is available to Security 503 participants only. CPE/CMU Credits: 6 TopicsIntroduction
Modes of operation
Writing Snort rules
Configuring Snort as an IDS
Miscellaneous
|
||
| SEC503.5: Intrusion Analysis | Mike Poor |
Sun Jan 20th, 2013 9:00 AM - 5:00 PM |
OverviewThis day starts to bring together the knowledge gained on previous days to help you become a combat ready analyst. You'll learn how to assess and prioritize the events generated by an Intrusion Detection System (IDS) / Intrusion Prevention System (IPS), including how to correlate events across multiple platforms and operating environments. You'll participate in analyzing network traffic, including performing network traffic forensic analysis. Note:This course is available to Security 503 participants only. CPE/CMU Credits: 6 TopicsAnalyst Toolkit: Examine some libpcap-based tools to assist with specific tasks for traffic analysis
Wireshark: Extensive coverage of use of Wireshark for the following:
Wireshark: SiLK: Open Source Network Flow
SiLK: Network Traffic Forensics
Network Architecture for Monitoring
Correlation
|
||
| SEC503.6: IDS Challenge | Mike Poor |
Mon Jan 21st, 2013 9:00 AM - 5:00 PM |
OverviewThis day is the culmination and consummation of all the previous days where you use your knowledge for a hands-on exercise to investigate an actual attack. This is a guided approach of discovering the network architecture, profiling traffic, identifying attacks, analyzing possible compromises, characterizing the enemy, tracking the hacker's activities, and correlation. This engaging activity allows you to work with a team or individually to reinforce what you've learned and challenge you to think analytically. Note: This course is available to Security 503 participants only. CPE/CMU Credits: 6 |
||
| Additional Information | ||
| Laptop Required | ||
|
For Security 503: Intrusion Detection In-Depth you will need to install the required software on your laptop for the hands-on exercises that will be done in class. A Linux VMware image is supplied for class exercises. Familiarity and comfort with entering commands via the command line will facilitate your experience with the hands-on exercises. Before coming to the course, you will need to perform the following actions:
Note: The VMware image supplied for the course is used to do all of the Security 503 exercises. The VMware image CD will be supplied during the course. Mandatory Laptop Hardware Requirements:
If you have additional questions about the laptop specifications, please contact laptop_prep@sans.org. |
||
| Who Should Attend | ||
|
||
| Prerequisites | ||
Students must possess at least a working knowledge of TCP/IP and hexadecimal. To test your knowledge, see our TCP/IP & Hex Quizzes here. |
||
