Security Auditing, Attacks, and Threat Analysis Course

Course Code: IN 282
Course Abstract: Security Auditing, Attacks, and Threat Analysis teaches students how to perform different phases of a security audit, including discovery and penetration, and how to prevent unauthorized users from controlling company networks. The course discusses how to use Windows 2000 and Linux to identify security issues and suggest industry-standard solutions. Students will also learn how to generate effective audit reports that can help organizations improve their security and become current with industry security standards.
Audience: This course is designed for Network server administrators, firewall administrators, systems administrators, application developers, and IT security officers.
Duration: 2 days
Learning Outcomes: Upon completion of this course, students will also learn how to generate effective audit reports that can help organizations improve their security and become current with industry security standards.
Course Topics:

Security Auditing
Introduction to Auditing
What is an Auditor?
What Does an Auditor Do?
Auditor Roles and Perspectives
Conducting a Risk Assessment
Risk Assessment Stages

Discovery Methods
Discovery
Security Scans
Enterprise-grade Auditing Applications
Scan Levels
Social Engineering
What Information Can You Obtain?

Auditing Server Penetration and Attack
Techniques
Network Penetration
Attack Signatures and Auditing
Common Targets
Routers
Databases
Web and FTP Servers
E-mail Servers
Naming Services
Compromising Services
Auditing for System Bugs
Auditing Trap Doors and Root Kits
Auditing Denial-Of-Service Attacks
Buffer Overflow
Combining Attack Strategies
Denial of Service and the TCP/IP Stack

Security Auditing and the Control
Phase
Network Control
Control Phases
UNIX Password File Locations
Control Methods
Auditing and the Control Phase

Intrusion Detection
Intrusion-Detection Systems
What is Intrusion Detection?
IDS Rules
False Positives
Intrusion-Detection Software
Intruder Alert
Purchasing an IDS
Auditing with an IDS

Auditing and Log Analysis
Log Analysis
Baseline Creation
Firewall and Router Logs
Operating System Logs
Filtering Logs
Suspicious Activity
Additional Logs
Log Storage
Auditing and Performance Degradation

Audit Results
Auditing Recommendations
Creating the Assessment Report
Improving Compliance
Security Auditing and Security Standards
Improving Router Security
Enabling Proactive Detection
Host Auditing Solutions
Replacing and Updating Services
Secure Shell (SSH)
SSH and DNS

Prerequisites: Participants must have passed the CIW Foundations, CIW Server Administrator, and CIW Internetworking Professional exams, and have completed the Network Security and Firewalls and Operating Systems Security courses or have equivalent skills.
Note: All fields are required
At the present time we do not offer training for individuals or groups less then 6 individuals. We apologize for any inconvenience.


We Value Your Privacy!

Ready to get started or in need of more information? Contact us today.

Go To Blog Virtual Learning