SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsThis practical has two objectives: guide users of BlackICE to report incidents to their ISPs (using ClearICE Report Utility) and show users the importance of submitting firewall logs to the dshield.org project. Since the installation of BlackICE does not require much work on a single workstation, I will assume that it's already installed and start from the incident itself, passing through the BlackICE's alert, blocking the intruder to avoid his activities and working with ClearICE to create an useful report to the attacker's ISP to help them track the malicious user. Considering that all computers on the Internet are targets, you could help information security professionals and systems administrators. Submitting your firewall logs to the Dshield.org project, you help administrators and users all around the world to discover new trends in activities (anomalous and / or malicious) and to prepare better firewall rules. If more and more users and administrators submit their logs to dshield.org, their database will become bigger and the trends discovered easily. Also, firewall rules created based on their analysis will be more accurate.