As computer attackers ramp up their abilities, information security professionals must also keep our skills sharp in preventing, detecting, and responding to attacks. Based on the experiences of the SANS Internet Storm Center incident handling team, this session provides hands-on experience with attack and defense methodologies from the real-world released in the past twelve months. We'll also analyze emerging attack vectors that incident handlers are just starting to cope with in the wild. Each attack will be covered from an incident handlers' mindset, with a detailed and lively discussion of how to respond when an organization comes under fire. Also, numerous hands-on exercises will help incident handlers get into the mindset of attackers so they can counter the bad guys' moves.
If you take SEC517 at a conference, hands-on exercises throughout the session will build to a capture the flag event during the last half of the day where attendees will work in teams to apply what they have learned in a reality-based, hands-on attack scenario. We have stood up a Virtual Lab for SEC517 for use by OnDemand students. You will access the lab over the Internet through a VPN.
This virtual training lab lets you put what you learn in the course into practice with the Capture The Flag event. By penetrating systems, discovering subtle flaws, and using puzzle-solving techniques, you can test the skills you've built in the course in this engaging event.
Paranoia is good!
*Your laptop may be attacked. Do not have any sensitive data stored on the system. SANS is not responsible for your system if someone in the class attacks it in the workshop. We recommend that you have a personal firewall on your system which will block inbound access unless you allow it.*
You will have access to the SEC517 Virtual Lab the entire time you have access to your OnDemand SEC517 course. Formal "office hours" when someone will be available to respond quickly if you are having issues with one of the target servers or need help with one of the tools are as follows:
Every month, during the first full week (all times are US Eastern):
- Tues - 10:00 AM - 12:00 PM
- Thur - 6:00 PM - 8:00 PM
- Sat - 12:00 PM - 2:00 PM
The hours are distributed at different times on different days so that if some folks cannot access the Virtual Lab during normal work hours or during the week from work, then hopefully there is at least one time you will be able to access the lab when someone is standing by to assist if needed. "First full week" refers to "Sunday through Saturday". There will be no office hours held on days that are U.S. Federal holidays.