> > > SSFSNORT

Securing Cisco Networks with Open Source Snort (SSFSNORT)

Course Description Schedule Course Outline Lab Topology
 

Course Overview

Securing Cisco® Networks with Open Source Snort™ is an instructor-led course offered by Learning Services High-Touch Delivery. It is a lab-intensive course that introduces students to the open source Snort technology as well as rule writing. You will learn how to build and manage a Snort system using open source tools, plug-ins, and the Snort rule language to help manage, tune, and deliver feedback on suspicious network activity.

This course combines lecture materials and hands-on labs throughout to make sure that you are able to construct a solid, secure Snort installation and write Snort rules using proper syntax and structure.

Who should attend

This course is designed for technical professionals who need to know how to deploy open source intrusion detection systems (IDS) and intrusion prevention systems (IPS), as well as write Snort rules. The primary audience for this course includes:
  • Security administrators
  • Security consultants
  • Network administrators
  • System engineers
  • Technical support personnel using open source IDS and IPS
  • Channel partners and resellers

Class Prerequisites

  • Technical understanding of TCP/IP networking and network architecture
  • Proficiency with Linux and UNIX text editing tools (vi editor is suggested but not required)

What You Will Learn

Upon completion of this course, you should be able to:
  • Understand what Snort is and its basic architectural components
  • Understand Snort’s dynamic plug-in capapbilities
  • Understand the different modes of Snort operation
  • Perform installation and configuration of the Snort system
  • Install and configure Snorby
  • Configure and tune the Snort pre-processors
  • Understand rule maintenance and techniques to keep rules current
  • Create Snort rules using both simple and advanced rule-writing techniques
  • Monitor performance of a Snort deployment

Outline: Securing Cisco Networks with Open Source Snort (SSFSNORT)

  • Module 1: Intrusion Sensing technology, Challenges, and Sensor Deployment
  • Module 2: Introduction to Snort Technology
  • Module 3: Snort Installation
  • Module 4: Cofiguring Snort for Database Output and Graphical Analaysis
  • Module 5: Operating Snort
  • Module 6: Snort Configuration
  • Module 7: Configuring Snort Preprossors
  • Module 8: Keeping Rules Up to Date
  • Module 9: Budilidng a Distributed Snort Instalation
  • Module 10: Basic Rule Syntax and Usage
  • Module 11: Buildling a Snort IPS Installation
  • Module 12: Rule Optimization
  • Module 13: Using PCRE in Rules
  • Module 14: Basic Snort Tuning
  • Module 15: Using Byte_Jump/Test/Extract Rule Options
  • Module 16: Protocol Modeling Concepts and Using Flowbits in Rule Writing
  • Module 17: Case Studies in Rule Writing and Packet Analysis

Classroom Training

Duration 4 days

Price
  • United States: US$ 4,000
  • Cisco Learning Credits: 40 CLC
Enroll now
Online Training

Duration 4 days

Price
  • United States: US$ 4,000
  • Cisco Learning Credits: 40 CLC
Enroll now