|
SE-500
INTRUSION DETECTION WITH SNORT
2 Days
Tuition: $1190
Target Audience:
System Administrators, Security Auditors, IT Managers
Prerequisites:
-
Intermediate or Advanced Network and
Systems Admin experience
-
Network Intrusion Protection course
As a result of completing this course, the
student will be able to:
-
Deploy Snort IDS software on either Linux
or Windows platforms
-
Modify Snort rules to reduce false
positives
-
Create customized rules for new threats
-
Enable database logging
-
Perform data analysis with ACID
-
Integrate Snort with firewall products
Student Materials:
-
Binder of printed overheads & labs
-
Reference Book: Snort Cookbook (O’Reilly)
IDS Overview
Snort Features
Installation of Snort Software
Rules
Preprocessors and Plug-ins
Generating Test Packets
Data Analysis with ACID
Advanced Logging to Databases
False Positives: Tuning Your Rules
Integration with Firewalls to provide Intrusion
Prevention
Summary List of Lab Exercises/Tools:
·
Snort Installation
on Windows/Linux
·
Editing Snort.conf
·
Editing IDS
signatures
·
Configuring
Logging
·
Generating
Malicious Packets for Testing |