This Program is designed to equip the student with the
essential skills, knowledge and experience about fundamentals
of Intrusion Detection Systems. IDS training courses are
designed to give you specific knowledge about techniques
and methods used by various IDS solutions. Configuration
and analysis exercises will be performed throughout this
class, with students having the opportunity to work with
both live and pre-captured data.
Course
outline:
Intrusion Detection Systems
Functions Of Intrusion Detection Systems
Benefits Of Intrusion Detection
Unrealistic Expectations About Intrusion-Detection
Are Firewalls Enough?
Types Of Intrusion Detection Systems
Network
Based Intrusion Detection
Host
Based Intrusion Detection
Intrusion Detection Methodology
Statistical
Anomaly-Based Ids
Intrusion
Detection Using Protocol Anomalies
Intrusion
Detection Using Traffic Anomalies
Signature-Based
Ids
Intrusion
Detection Using Stateful Signatures
The CIDF Model Of Intrusion Detection Systems
Limitations In Intrusion Detection Systems
Insertion
Evasion
Fragmentation
Avoiding
Defaults
Slow
Scans
Coordinated,
Low-Bandwidth Attacks
Address
Spoofing/Proxying
Pattern
Change Evasion
Denial
Of Service Attacks
Some Common Exploits
CGI
Scripts
Web
Server Attacks
Web
Browser Attacks
SMTP
(Sendmail) Attacks
DNS
Attacks
Sample
Ids Rules
Prerequisite:
The student should have a fundamental understanding of
the TCP/IP protocol suite
Materials:
Participants will receive a student course guide, which
includes training materials presented during the class.