SE-500
INTRUSION DETECTION WITH SNORT

2 Days

Tuition: $1190

Target Audience: System Administrators, Security Auditors, IT Managers

Prerequisites:

  • Intermediate or Advanced Network and Systems Admin experience
  • Network Intrusion Protection course

As a result of completing this course, the student will be able to:

  • Deploy Snort IDS software on either Linux or Windows platforms
  • Modify Snort rules to reduce false positives 
  • Create customized rules for new threats
  • Enable database logging
  • Perform data analysis with ACID
  • Integrate Snort with firewall products

 

Student Materials:

  • Binder of printed overheads & labs
  • Reference Book: Snort Cookbook (O’Reilly)

 

IDS Overview

Snort Features

Installation of Snort Software

Rules

Preprocessors and Plug-ins

Generating Test Packets

Data Analysis with ACID

Advanced Logging to Databases

False Positives: Tuning Your Rules

Integration with Firewalls to provide Intrusion Prevention

Summary List of Lab Exercises/Tools:

 

·         Snort Installation on Windows/Linux

·         Editing Snort.conf

·         Editing IDS signatures

·         Configuring Logging

·         Generating Malicious Packets for Testing


Home
Solaris Programming Microsoft Desktop Linux Cisco Security
About SYSTEMS Computer Training
Contact Us


© 2003-2004  SYSTEMS Computer Training, A Testmasters Company

Solaris and Java are registered trademarks of Sun Microsystems.