Logg inn: Glemt passord
Skriv inn hva du ønsker å lære eller hvor du ønsker kurs for å få opp forslag

Aktuelle kategorier
Nettverk- og systemadministrasjon (620)
IT strategi og business intelligence (297)
Informasjonssikkerhet (48)
Datakommunikasjon (10)
TCP/IP (8)
Annet (5)
Telekommunikasjon (4)
Antivirus og brannmur (3)
Intranett (2)
» Se flere kategorier

Enterprise Intrusion Analysis (SC-375)

Skriv ut
Dette kurset ligger i kategorien(e):

Kursarrangør: Sun Microsystems
Sted: På forespørsel i hele landet.
(Dette kurset kan holdes de fleste steder på forespørsel. Men i de fleste tilfeller vil det kreve et visst antall deltakere for at kurset kan holdes på ditt hjemsted.)
         Ta kontakt for mer informasjon
Type: Åpent kurs / gruppeundervisning
Undervisningstid: Ta kontakt for avtale

The Enterprise Intrusion Analysis course provides students with the skills needed to discover and analyze enterprise intrusions in a UNIX environment.


Upon completion of this course, students should be able to:
1. Detect an enterprise system intrusion
2. Analyze a compromised system for crucial information: attack time, attacker location, attcker modifications to the system
3. Corrolate multiple log files from different parts of the enterprise to determine attacker usage
4. Conduct an audit of file systems to determine attacker modifications
5. Describe modern attacker methodology with proof of concept examples

Content:

Enterprise Footprinting

• Describe the principals of least privilege and disclosure
• Describe how attackers use active fingerprinting using port scans, DNS and ICMP
• Describe how attackers use passive fingerprinting using search engines
• Describe how attackers enumerate services by collecting banner messages and protocol information
• Describe how attackers use social engineering methods to gather information about an enterprise

Unauthorized System Access

• Describe how attackers gain unauthorized access through user accounts
• Describe how attackers gain unauthorized access through software flaws
• Explain the attacker methodology for locating vulnerable enterprise services and creating exploits
• Describe a buffer overflow
• Descirbe privilege escalation
• Describe a Trojan horse as a means to escalate priviliges

Securing root Access

• Describe how attackers secure root access through backdoors on a system
• Describe the following back doors: SUID shell, bound shell, and trusted hosts
• Describe a file system root kit
• Demonstrate how a file system root kit hides files, processes, and connections
• Describe a kernel root kit
• Demonstrate how a kernel rootkit captures all system activity

Encrypting and Hiding Data on a System

• Review encryption technology
• Describe how attackers use cryptography to encrypt files
• Demonstrate encryption using GnuPGP and OpenSSL
• Describe digital steganography
• Demonstrate how attackers hide files within files using digital steganography
• Describe how attackers hide data withing unexpected parts of the file system
• Demonstrate how attackers hide a file in file system metadata
• Demonstrate how attackers use the loopback file system and extended attributes to hide data

Enterprise Log Analysis

• Identify the different types of enterprise services: like DNS, DHCP, SMTP, HTTP, and Firewalls
• Identify available log files for enterprise services
• Describe the relevant intrusion information in each log file
• Examine enterprise log files to locate suspicious activity
• Corrolate information from multiple log files to determine an intrusion

Unauthorized System Access Intrusion Analysis

• Identify default system access log files in the /var directory structure
• Identify optional Basic Security Module (BSM) and system accounting log files
• Describe log file formats and tools available to read the formats
• Describe the relevant information in each log file
• Corrolate information from multiple log files to determine unauthorized system access
• Demonstrate how attackers modify log files to hide their presence on a system

File System Intrusion Analysis

• Define systems and utility trust
• Locate backdoors on a UNIX System: alternate root accounts, bound shells, SUID shells, trusted host files
• Locate file system root kits on a UNIX System
• Discover hidden directories, replaced system commands, remote command utilities, and network sniffers
• Describe automated file system analysis tools
• Implement the rkhunter, chkrootkit, and Solaris Fingerprint Database to locate root kits

System Memory Analysis

• Describe the important types of intrusion data that resides in memory
• Describe techniques to capture volatile memory data to a file system
• Introduce memory analysis tools mdb and gdb
• Demonstrate how to recovery data from memory using the mdb and gdb tools

Incident Investigation Methodologies

• Identify different types of intrusion scenarios
• Apply a methodology based on an intrusion scenario
• Collect the appropriate data (log files, file systems, and memory images) based on the intrusion scenario

Målgruppe for kurset
Students who can benefit from this course are systems administrators and security administrators who are responsible for detecting and analyzing enterprise system intrusions.

To succeed fully in this course, students should be able to:
• Demonstrate basic UNIX system and network administration skills
• Demonstrate a basic understanding of Transmission Control Protocol/Internet Protocol (TCP/IP) networking
• Demonstrate an intermediate understanding of network services: DNS, DHCP, SMTP, HTTP, and firewalls

Related courses before:
• SA-200-S10: System Administration for the Solaris 10 Operating System Part 1 (SA-200-S10)
• SA-300-S10: Network Administration for the Solaris 10 Operating System (SA-300-S10)
• SC-300: Administering Security on the Solaris Operating System (SC-300)
• SC-345: Solaris Operating System Network Intrusion Detection (SC-345)

Related courses after:
• SC-410: Computer Security Forensics and System Recovery (SC-410)
Enterprise Intrusion Analysis (SC-375)
Ønsker du mer informasjon om dette kurset?

Navn:  
Firma:  
E-post:  
Telefon:  
Melding:  
Påmelding:
Klikk her hvis du ønsker å
melde deg på dette kurset
Sun Microsystems

Sun ble grunnlagt med én eneste visjon som drivkraft. En visjon om datamaskiner som kommuniserte med hverandre uansett hvem som hadde laget dem. En visjon om teknikk som arbeider for deg, ikke motarbeider deg. Mens andre utviklet varemerkebeskyttede og proprietære løsninger, fokuserte vi på å hjelpe bedrifter inn i nettverksæraen. Som et resultat av dette er vi blitt dotten i .com. Vi leverer systemer og programvare som oppfyller kravene til skalerbarhet og påliteligheten som er nødvendig for å drive den elektroniske markedsplassen.

Telefon: 23 36 96 50
Hjemmeside: Klikk her

Flere kurs fra Sun Microsystems

Tips en venn




© Agentgruppen AS - Orgnr 984 246 595 MVA - Fekjan 13, 1394 Nesbru - Tlf: 417 65 300

Vi tar ikke ansvar for innhold som tilhører våre medlemmer. Dette gjelder kursoppføringer, artikler og eksterne lenker.