Sound the Alarm: Detection and Response

所在平台: Coursera

课程主页: https://www.coursera.org/learn/detection-and-response

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:发出警报:检测与响应 课程概述:这是谷歌网络安全证书的第六个课程。该系列课程旨在为您提供申请入门级网络安全工作的所需技能。您将基于第五门谷歌网络安全证书课程中介绍的主题,深入学习。 在本课程中,您将重点关注事件检测与响应。您将定义安全事件,并解释事件响应生命周期,包括事件响应的角色和责任。 课程大纲: 1. **检测与事件响应介绍** - 本模块提供检测和事件响应的概述。学习者将探讨安全专业人员如何验证并响应恶意威胁。学习者还将熟悉事件响应的各个步骤,此概述将为下一个模块奠定基础。 2. **网络监控与分析** - 在此模块中,学习者将获得网络分析工具的概述,这些工具通常被称为“数据包嗅探器”。具体而言,学习者将进行网络嗅探并分析数据包中的恶意威胁。他们还将编写tcpdump和Wireshark中的常见过滤命令,以分析数据包捕获的内容。 3. **事件调查与响应** - 本模块中,学习者将探讨根据NIST框架进行的事件检测、调查、分析和响应的各个过程和程序。学习者将使用VirusTotal作为调查工具,分析可疑文件哈希的详细信息。学习者将认识到文档和证据收集在检测和响应阶段的重要性。最后,学习者将通过映射工件来重建事件的时间线,从而近似事件的 chronology。 4. **使用IDS和SIEM工具进行网络流量和日志分析** - 在本模块中,学习者将获得日志及其在入侵检测系统(IDS)和安全信息与事件管理工具(SIEM)中的作用的概念性概述。该模块将讨论IDS的一般概念以及它如何工作以检测攻击,然后重点介绍具体的IDS和SIEM产品,例如Suricata、Splunk和Google SecOps(Chronicle)。学习者将了解如何访问和浏览Suricata,并了解如何设置基本规则以提供恶意网络流量的警报、事件和日志。该模块最后将介绍Splunk和Google SecOps(Chronicle),展示它们的一些功能,包括搜索查询的常用命令。

课程大纲

Name:Introduction to detection and incident response

Description:This module provides an overview of detection and incident response. Learners will explore how security professionals verify and respond to malicious threats. Learners will also become familiar with the steps involved in incident response. This overview will be the foundation for the next module.

Name:Network monitoring and analysis

Description:In this module, learners will be provided with an overview of network analysis tools more commonly referred to as “packet sniffers”. In particular, learners will sniff the network and analyze packets for malicious threats. Learners will also craft common filtering commands in both tcpdump and Wireshark to analyze the contents of packet capture.

Name:Incident investigation and response

Description:In this module, Learners will explore the various processes and procedures in the stages of incident detection, investigation, analysis, and response as framed by NIST. They will utilize VirusTotal as an investigative tool to analyze the details of suspicious file hashes. Learners will recognize the importance of documentation and evidence collection during the detection and response stages. Finally, learners will approximate an incident’s chronology by mapping artifacts to reconstruct an incident’s timeline.

Name:Network traffic and logs using IDS and SIEM tools

Description:In this module, learners will be provided with a conceptual overview of logs and their role in intrusion detection systems (IDSs) and Security Information and Event Management tools (SIEMs). The module will discuss the general concept of an IDS and how it works to detect attacks before highlighting specific IDS and SIEM products, such as Suricata, Splunk and Google SecOps (Chronicle), respectively. Learners will then develop an understanding of how to access and navigate within Suricata and how basic rules are set up to provide alerts, events, and logs for malicious network traffic. This module will conclude with an introduction to Splunk and Google SecOps (Chronicle) and will showcase some of their features, including common commands for search queries.

课程评论(0条)

课程详情

This is the sixth course in the Google Cybersecurity Certificate. These courses will equip you with the skills you need to apply for an entry-level cybersecurity job. You’ll build on your understanding of the topics that were introduced in the fifth Google Cybersecurity Certificate course. In this course, you will focus on incident detection and response. You'll define a security incident and explain the incident response lifecycle, including the roles and responsibilities of incident response

课程标签

0人关注该课程

主题相关的课程