|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/counterintelligence-101-certificate-crash-course/
课程评论:没有评论
课程名称:反情报101认证速成课程 课程概述: 反情报是任何全面安全方案的重要组成部分。反情报活动旨在抵御间谍活动、破坏、敌对组织的招募或暗杀等风险。虽然反情报通常与情报机构、政府组织或军事活动相关联,但企业同样可以通过将反情报纳入其安全策略中受益。在网络安全领域,反情报用于支持信息安全的三大要素:保密性、可用性和完整性(CIA)。许多组织实践反情报的不同方面,但常常使用其他名称,如数据丢失防护(DLP)、恶意软件逆向工程和网络取证等。 反情报工作的方式: 反情报活动可分为集体、防御性和进攻性三类。集体反情报努力专注于了解对手,包括其信息收集方式、攻击向量及使用工具等。防御性反情报活动致力于保障信息安全,防止对手窃取或破坏信息。进攻性反情报活动则侧重于将攻击转化为机会,通过使用虚假信息来获得优势。 虽然大多数信息技术(IT)安全管理员通常进行防御性和集体反情报,但对进攻性反情报的价值并不总是得到理解。通过正确的实施,欺骗技术可以用来改善集体、防御和进攻反情报。欺骗技术利用诱饵(如蜜罐和虚拟蜜罐)来误导攻击者,延迟或阻止其深入网络并达到预定目标。通过观察攻击者在攻击中使用的战术、技术和程序,防御者可以获得宝贵的见解,并将其融入防御策略中。 完成该课程后,将获得定制的完成证书。
Counterintelligence is an integral part of any comprehensive security program. Counterintelligence activities are conducted to protect against espionage, sabotage, recruitment hostile organizations, or assassinations. Counterintelligence is often associated with intelligence agencies, government organizations or the military but businesses also benefit from including CI in their approach to security. In cybersecurity, counterintelligence is used to support the information security triad of Confidentiality, Availability, and Integrity (CIA). Many organizations practice aspects of CI, but refer to it by different names, including data loss prevention (DLP), malware reverse engineering and Network forensics.How counterintelligence worksCounterintelligence activities can be categorized as being either collective, defensive or offensive. Collective CI efforts focus on learning who the adversary is, how they collect information, what attack vectors they are targeting and what tools they are using. Defensive CI efforts focus on securing information and preventing an adversary from stealing or destroying it. Offensive CI activities focus on turning an attack into an opportunity to gain an advantage by using disinformation.While most information technology (IT) security administrators routinely conduct defensive CI and collective CI, the value of using offensive CI is not always understood. With the right implementation, deception technology can be used to improve collective, defensive and offensive CI. Deception technology uses decoys, such as honeypots and virtual honeypots, to misdirect an attack and delay or prevent the attacker from going deeper into the network and reaching the intended target. By observing the tactics, techniques and procedures attackers use in their attack, defenders can gain valuable insight that can be incorporated into their defenses. A custom certificate of completion will be available upon completion of this course.