課堂由導師以講座形式教授課程理論及進行眾多的商業實習,而實習時段由學員親自進行商業實習。
1 Overview of Intrusion Prevention System
1.1 Introduction to Intrusion Detection and Preventation
1.2 Cisco Instrusion Detection Appliances Products
2 Signature and Actions
2.1 Signature Types
2.2 Signature Trigger
2.2.1 Pattern Detection
2.2.2 Anomaly-based Detection
2.2.3 Behaviour-basd Detection
2.3 Signature Actions
2.3.1 Generate Alerts
2.3.2 Log the activities
2.3.3 Drop the suspicious packets
2.3.4 Block future activities
2.3.5 Reset TCP connections
3 Basic Sensor Inialization
3.1.1 Display the IDS information
3.1.2 Display the IDS current configuration
3.2 Erase all current configuration
3.3 Reboot the devices
3.4 Default Configuration of Sensor
3.5 實習: Configure Hostname, IP address and Subnet mask in the Sensor
3.6 Case Study: Configure Hostname, IP address and Subnet mask in the Sensor in 6.x
3.7 實習: Access to web interface of Sensor
3.8 Case Study: Access to web interface of Sensor 6.x
3.9 實習: Configure NTP on Sensor
3.10 Case Study: Configure NTP on Sensor 6.x
3.11 實習: Configure Telnet Server in Sensor
3.12 Case Study: Configure Telnet Server in Sensor 6.x
3.13 SNMP Configuration
3.14 Case Study: Configure SNMP in Sensor (Version 6.x)
4 Sensor Interfaces
4.1 Command and Control Interface
4.2 Sensing Interface
4.3 Promiscuous Mode
4.4 實習: Configure sensing interface and interface group
4.5 Case Study: Enable senor physical interface in IPS software 6.x
4.6 Inline Mode
4.7 Case Study: Enable Inline VLAN-Pair interfaces in IPS software 6.x
4.8 Case Study: Enable Inline VLAN Group (Promiscuous) in IPS software 6.x
5 Virtual Sensor
5.1 Case Study: Configure Virtual Sensor in Promiscuous interface for IPS Software 6.x
5.2 Case Study: Configure Virtual Sensor in Inline VLAN-Pair subinterface for IPS Software 6.x
5.3 Case Study: Configure Virtual Sensor in Inline VLAN-group subinterface for IPS Software 6.x
6 Basic Signature Tuning
6.1 實習: Enable ICMP echo reply (2000) signature
6.2 實習: Enable ICMP echo request (2004) signature by using console commands
6.3 Case Study: Enable ICMP echo request (2004) and echo reply (2000) signature in IPS Software 6.x
7 SPAN (Switched Port Analyzer)
7.1 Local SPAN
7.2 實習: Local SPAN
7.3 Remote SPAN
7.4 實習: Remote SPAN
8 Event Counting and Summarization Concepts
8.1 Event Counting
8.2 Event Summarization
9 Custom Signature
9.1 實習: Custom Signature
9.2 Case Study: Configure Custom Signature for IPS Software 6.x
10 IP Logging
10.1 實習: Enable IP Logging for ICMP Host Flooding Signature
10.2 實習: Copy the log file to FTP Server
10.3 Manual IP Logging for a Specific IP Address
10.4 實習: Manual IP Logging
10.5 Stopping Active IP Logs
10.6 實習: Stopping Active IP Logs
10.7 Case Study: IP Logging in IPS Software 6.x
10.8 Case Study: Stopping the Active IP Logging
11 Attack Response Controller (ARC) technologues.
11.1 Attack Response Controller (ARC) for blocking
11.1.1 Type of Blocking
11.1.2 Blocking Devices
11.2 Attack Response Controller (ARC) for Rate Limiting
11.3 Case Study: Configure Blocking by Sensor telnet connection in IPS Software 6.x
11.4 Case Study: Configure Blocking by Sensor SSH DES connection in IPS Software 6.x
11.5 Case Study: Configure Blocking by Sensor SSH 3DES connection in IPS Software 6.x
11.6 Case Study: Configure Rate Limiting by Sensor in IPS Software 6.x
11.7 Case Study: Custom Host Blocking in IPS Software 6.x
11.8 實習: Configure and Troubleshooting Sensor Blocking (Telnet)
11.9 實習: Configure Sensor Blocking (SSH - DES)
11.10 實習: Configure Sensor Blocking (SSH - 3DES)
11.11 實習: Configure Sensor Host Blocking Directly
11.12 實習: Configure Sensor Network Blocking Directly
12 Risk Rating Calculation
13 Event Processing Procedures
14 IDS Version 4.x – Alarm Channel System Variables
15 IDS Version 4.x –Alarm Channel Event Filters
15.1 實習: Create Event Filter
16 IP Fragment Reassembly
16.1 Case Study: IP Fragment Reassembly in IPS Software 6.x
16.2 實習: Configure IP Fragment Reassembly
17 TCP Fragment Reassembly
17.1 實習: Configure TCP Fragment Reassembly
18 Sensor Administration
18.1 Sensor Setup.
18.2 實習: Sensor setup
18.3 Change the IDM access port
18.4 實習: Change to IDM port to 9999
18.5 Password Recovery
18.6 Case Study: Performing Password Recovery
19 Sensor User Mangement
19.1 實習: Create users with different privileges.
19.2 Case Study: Configure Service Privilege Account in IPS Software 6.x
19.3 Creating a Banner Login
19.4 Case Study: Banner Login
19.5 Terminating (結束) CLI Sessions
19.6 Case Study: Terminating CLI Sessions
19.7 Configure the time of the Sensor
19.8 實習: Backup and Restore the current-configuraiton
20 Packet Capturing and displaying
20.1 Case Study: Displaying Live Packet
20.2 Case Study: Capture Live Packet
21 Obtaining Statistics from the Sensor
22 Displaying Tech Support Information
22.1 實習: Save the Tech Support to the FTP Server as a HTML file
23 Anomly Detection (AD)
23.1 AD Zones
23.2 Anomaly Detection Modes
23.3 Commands used to perform AD configuration
24 Summary of the IDM
25 Final Conclusion |