Please fill up the below form
and our Career Consultant will
contact to you in next 12 hours!
Live Practice Labs

Our live access labs provide full console access to a self-paced study lab environment. This is an ideal place to re-work lab exercises from class or to experiment with advanced configuration from your home or hotel room. Find out which works for you and get a downloadable eKit when you enroll.

|
|
NIDS using Snort
This Course is for those who want to learn how to build a Snort IDS/IPS from scratch using many of the open source tools and plug-ins available to help manage, tune and deliver feedback on suspicious activity in your networks. Hands-on labs with fully documented instructions help students construct solid, secure Snort installations and understand the inner workings of the premier open source IDS/IPS available today. Students will also learn how to fine tune and configure Snort in addition to creating custom rules and learning techniques for optimizing rules. Can you really trust your security framework to a single component, say a firewall? Also, is it good enough to know only what you want to protect? How about the awareness on the threats to your environment, do you consider it important? Can you possibly build defenses to protect against attacks without knowing the nature and methods of your enemy? How can you detect signs of an intrusion to your network before damage is done? Before you fall for Snort and then get stuck on deployment, you may want to consider the following as guidelines; * To start with, what do you consider an Intrusion? * We do agree that the benefits of detecting an intrusion early enough are undeniable. However, there may be some real challenges. Any clue? * You know what; exploits on the internet are real. If your thoughts are, “what is the anatomy of an attack, and how can you possibly use that knowledge to your Network’s advantage”, then, your must be a clever chap. * Does it really matter to know how systems on a network communicate, the make-up of a packet, interpreting logs and/or possibly identifying suspicious packets? * Why should you consider Snort as the right candidate for your NIDS? * Having snort installed and running may not be much of an issue but how do you tailor it to suit your environment, assess its intelligence and even more? * Being able to detect an exploit early enough with the help of Snort as your NIDS sounds great for a start, but can you have Snort do more? Say, function as Intrusion Prevention System (IPS). If so, how? * The promise of an IPS is very attractive, but there are some risks that may not be obvious at first glance. Are those risks worth considering when planning the deployment of Snort as an IPS? Target Audience: Prerequisites
Course Outline
UNIT 1: Installation UNIT 2: Sniffer Mode UNIT 3: Logging Mode UNIT 4: Berkeley Packet Filters (BPFs) UNIT 5: Network Intrusion Detection System (NIDS) Mode UNIT 6: Output Plugin - Barnyard Configuration UNIT 7: BASE - MySQL® Implementation UNIT 8: Rules Configuration & Updates Labs you can’t possibly wait to have your hand-on PRACTICE LABS: Installing snort from source on Linux Generating Real-Time Alerts Logging Snort logs to MySQL Managing Snort Sensors with ACID Setting up Snort as an IPS using flexible response, SnortSAM and snort Inline patch plug-ins Detecting Stateless Attacks and Stream Reassembly Detecting Fragmentation attacks and Fragmentation Reassembly Detecting HTTP evasion attacks Decoding Application Traffic Getting Performance Metrics How to build snort rules and tips on writing effective snort rules. Testing snort rules
Trainings
|





