Checkpoint Threat Prevention

所在平台: Udemy

课程主页: https://www.udemy.com/course/checkpoint-threat-prevention/

课程评论:没有评论

第一个写评论        关注课程

课程简介

**课程名称:** Checkpoint 威胁防护 **课程概述:** 本课程将深入学习如何利用 Checkpoint 防火墙来保护网络安全。Checkpoint 的威胁防护解决方案提供多层级、事前及事后感染的防御方法,以及一个统一的平台,帮助企业安全地检测和阻止现代恶意软件。 **课程内容:** 本课程将重点介绍以下软件刀片(Software Blades)的配置与使用: * **应用程序控制 (Application Control):** 控制和管理网络中的应用程序使用。 * **URL 过滤 (URL Filtering):** 阻止访问已知的恶意网站和不当内容。 * **反机器人 (Anti-Bot):** 检测并阻止网络中的机器人活动,防止其与命令与控制服务器通信,减少机器人攻击造成的损害。 * **防病毒 (Anti-Virus):** 在网关处实时检测和阻止恶意软件,在用户受到影响之前进行防护。 * **入侵防护系统 (IPS):** 提供全面的入侵检测和防御,保护网络免受恶意流量、网络钓鱼、服务器漏洞利用和零日攻击的威胁。 * **数据防泄漏 (Data Loss Prevention):** 防止敏感数据通过网络泄露。 * **内容感知 (Content Awareness):** 识别和分类网络流量中的内容,实现更精细的安全策略。 * **威胁模拟 (Threat Emulation):** 在隔离的虚拟沙箱环境中运行可疑文件,以检测和阻止未知恶意软件,并将新发现的威胁信息共享到 ThreatCloud。 * **威胁提取 (Threat Extraction):** 移除文件中的潜在可利用内容,重建安全文件,确保业务流程的连续性。 * **Infinity 威胁防护 (Infinity Threat Prevention):** 整合 Checkpoint 的各项安全能力,提供端到端的威胁防护。 **核心理念:** 每个软件刀片都提供独特的网络防护能力。当它们协同工作时,就能构成一个强大的威胁防护解决方案。通过共享恶意攻击数据,软件刀片能够相互协作,确保网络安全。 **重点技术介绍:** * **IPS:** 提供对恶意和不需要的网络流量的全面防护,重点关注应用程序和服务器漏洞,以及野外攻击(Exploit Kits)和恶意攻击者的威胁。 * **反机器人:** 对主机上的机器人感染进行事后检测,通过阻止机器人与命令与控制(C&C)的通信来防止其造成的损害。反机器人软件刀片持续从 ThreatCloud(一个对抗网络犯罪的协作网络)接收更新,并通过关联多种检测方法来发现感染。 * **防病毒:** 在网关处实现事前检测和阻止恶意软件。防病毒软件刀片持续从 ThreatCloud 接收更新,并通过关联多种检测引擎,在用户受影响前检测并阻止恶意软件。 * **威胁模拟:** 一种创新的解决方案,能够快速检查文件并在虚拟沙箱环境中运行它们,以发现恶意行为。发现的恶意软件将被阻止进入网络。威胁模拟服务会向 ThreatCloud 报告,并自动与其他客户共享新识别的威胁信息。 * **威胁提取:** 提供针对入站恶意内容的防护。提取能力可以移除潜在可利用的内容,包括活动内容和嵌入式对象,重建文件以消除潜在威胁,并及时向用户提供经过净化的内容,以保持业务流程。为了移除可能的威胁,该刀片会创建一个文件的安全副本,同时检查原始文件是否存在潜在威胁。

课程评论(0条)

课程详情

In this Checkpoint Threat Prevention course, we would learn how to protect the network using Checkpoint's Firewall. CheckPoint's Threat Prevention solution offers a multi-layered, pre-infection and post-infection defense approach and a consolidated platform that enables enterprise security to detect and block modern malware.In this course, we would learn how to configure the following blades: Application Control, URL Filtering, Anti-bot, Antivirus, IPS, Data Loss Prevention, Content Awareness, Threat Emulation, Threat Extraction and Infinity Threat Prevention. Topics Include: * Anti-bot * Antivirus * IPS * Threat Emulation * Threat Extraction * Infinity Threat Prevention * Data Loss Prevention* Content Awareness * Application Control * URL Filtering Each Software Blade gives unique network protections. When combined, they supply a strong Threat Prevention solution. Data from malicious attacks are shared between the Threat Prevention Software Blades and help to keep your network safe.IPS: A complete IPS cyber security solution, for comprehensive protection against malicious and unwanted network traffic, which focuses on application and server vulnerabilities, as well as in-the-wild attacks by exploit kits and malicious attackers. Anti-Bot: Post-infection detection of bots on hosts. Prevents bot damages by blocking bot C & C (Command and Control) communications. The Anti-Bot Software Blade is continuously updated from ThreatCloud, a collaborative network to fight cybercrime. Anti-Bot discovers infections by correlating multiple detection methods. Antivirus: Pre-infection detection and blocking of malware at the gateway. The Anti-Virus Software Blade is continuously updated from ThreatCloud. It detects and blocks malware by correlating multiple detection engines before users are affected. Threat Emulation: This innovative solution quickly inspects files and runs them in a virtual sandbox to discover malicious behavior. Discovered malware is prevented from entering the network. The Emulation service reports to the ThreatCloud and automatically shares the newly identified threat information with other customers. Threat Extraction: Protection against incoming malicious content. The extraction capability removes exploitable content, including active content and embedded objects, reconstructs files to eliminate potential threats, and promptly delivers sanitized content to users to maintain business flow. To remove possible threats, the blade creates a safe copy of the file, while the inspects the original file for potential threats.

课程标签

0人关注该课程

主题相关的课程