|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/f5-asm-basics-part1/
课程评论:没有评论
**课程名称: WAF BASICS- Part1(Web应用防火墙基础 - 第一部分)** **课程概述:** 本课程旨在为参与者提供关于如何部署、调优和维护应用安全管理器(ASM)以保护其Web应用程序免受HTTP类攻击的实用知识。课程内容涵盖讲座、动手实验和对不同ASM组件的讨论。 **核心内容:** * **应用流量基础:** 从应用流量流动的基本原理讲起,帮助学习者理解ASM如何应对攻击,以及如何将ASM作为一款WAF(Web应用防火墙)产品进行探索。 * **ASM组件及功能:** 深入讲解ASM的各个组件,包括: * 应用流量流(Application Traffic Flow) * BIG-IP的初始设置 * F5上的基本流量处理组件 * HTTP头部详解 * OWASP Top 10安全模型 * **安全策略部署与调优:** * 在ASM中部署初始安全策略(Initial security policy)的方法。 * 如何有效地调优(Tuning)安全策略。 * 攻击签名(Attack Signatures)的应用与管理。 **学习目标:** 通过本课程,学习者将能够: * 理解Web应用流量的流动过程。 * 掌握ASM的基本概念和工作原理。 * 学会部署和配置ASM以保护Web应用程序。 * 能够有效地调优ASM安全策略以提高防护能力。 * 了解OWASP Top 10等常见的Web应用安全威胁。
The Application Security Manager course gives participants a functional understanding of how to deploy, tune, and operate Application Security Manager (ASM) to protect their web applications from HTTP-based attacks.The course includes lecture, hands-on labs, and discussion about different ASM components.This course starts right from the fundamentals of application traffic flow and will help you understand how does ASM behave to attacks and how can you start exploring ASM as a WAF product.The course includes lecture, hands-on labs, and discussion about different ASM components.In this course we will be discussing below topics: Application Traffic Flow.Initial setup of BIG-IP Basic traffic processing components on F5HTTP header and explanation of OWASP Top 10 Security Model Ways to deploy initial security policy on ASM.Tuning of your policyAttack Signatures