SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsThere are a number of security measures that can be implemented to protect a network. One of the key components that will assist in determining whether a system is being attacked is a network-based intrusion detection system (NIDS). A wonderful and free NIDS is snort. The GSEC course discusses how to set up snort on a Windows-based system. I will discuss how to set up snort 1.9.1 - the latest version - on a virtual Linux machine. First, the 'before' scenario will describe the situation before this security improvement is enacted. Second I will asses the risk discuss why someone should consider network intrusion detection talk about snort VMware and Linux and investigate configuration options. I'll conclude with some implementation notes enhancements and the 'after' scenario. The appendices provide brief installation instructions and resources for further information.