|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/fortisiem-for-network-administrators-hands-on/
课程评论:没有评论
课程名称:FortiSIEM面向网络管理员的实践课程 概述: 随着数字化转型在各个行业的迅速发展,攻击面不断扩大,使安全管理变得愈加复杂。安全团队面临着来自众多安全设备产生的大量警报和信息的困扰,同时网络安全技能缺口也使问题更加严重。为了保护基础设施、应用程序和终端设备(包括物联网设备),需要实时可视化所有设备和基础设施。FortiSIEM是一种强大的安全信息和事件管理(SIEM)解决方案,结合了用户和实体行为分析(UEBA)功能,提供可视性、关联性、自动响应和修复能力,构建一个可扩展的单一解决方案。该解决方案降低了网络和安全运营管理的复杂性,有效释放资源,提高了漏洞检测能力,并有助于防止安全 breaches。 课程内容: 此课程将帮助学员了解FortiSIEM的基础概念,包括: - FortiSIEM的归一化处理流程 - FortiSIEM如何接收和收集日志 - 将不同设备连接到FortiSIEM - 用户和角色的管理 - 使用SNMP和SSH - FortiSIEM中的手动和自动发现 - 安装代理(Windows和Linux) - 事件管理和仪表盘创建 通过本课程,学员将获得丰富的FortiSIEM实操经验,学习如何在网络环境中安装、配置和管理FortiSIEM。本课程采用情境驱动的教学方法,以步骤指导的方式,帮助学员克服文档中的困惑,并较少依赖死板的幻灯片。完成课程后,学员将能够创建自定义仪表盘以分析日志,提升对网络环境安全的整体掌控力。
As digital transformation sweeps through every industry, the attack surface grows dramatically (and constantly), making security management increasingly difficult. Security teams struggle to keep up with the deluge of alerts and other information generated by their multitude of security devices. And the cybersecurity skills gap only makes this more difficult.Infrastructure, applications, and endpoints (including IoT devices) must all be secured. This requires visibility of all devices and all the infrastructure in real-time. Organizations also need to know what devices represent a threat and where. FortiSIEM is a Powerful Security Information and Event Management (SIEM) with User and Entity Behavior Analytics (UEBA).FortiSIEM brings together visibility, correlation, automated response, and remediation in a single, scalable solution. It reduces the complexity of managing network and security operations to effectively free resources, improves breach detection, and even prevent breaches. What's more is that our architecture enables unified data collection and analytics from diverse information sources including logs, performance metrics, security alerts, and configuration changes. FortiSIEM combines the analytics traditionally monitored in separate silos of the security operations center (SOC) and network operations center (NOC) for a more holistic view of the security and availability of the business.In addition, FortiSIEM UEBA leverages machine learning and statistical methodologies to baseline normal behavior and incorporate real-time, actionable insights into anomalous user behavior regarding business-critical data. By combining telemetry that is pulled from endpoint sensors, network device flows, server and applications logs, and cloud APIs, FortiSIEM is able to build comprehensive profiles of users, peer groups, endpoints, applications, files, and networks. FortiSIEM UEBA behavioral anomaly detection is a low-overhead but high-fidelity way to gain visibility of end-to-end activity, from endpoints to on-premises servers and network activity, to cloud applications.The documentation of FortiSIEM is so confusing and I have tried to share my experience in FortiSIEM, tried not to be boring course from the slides. All the course is based on the scenario and I have explained step by step in FortiSIEM rather than slides. You gain much information on how to install, configure, manage FortiSIEM in your network environment. Upon successful completion, the student will be able to:- FortiSIEM basic concept- Understand the process of normalization in FortiSIEM- Understand how FortiSIEM receives and collects logs- Connect different devices to FortiSIEM- Users and Roles- Working with SNMP, SSH- Manual and auto Discovery in FortiSIEM- Agent Installation( Windows- Linux ) - Incidents and dashboard- Create custom dashboards in FortiSIEM to analyze logs