|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/log-analysis-detecting-web-attacks/
课程评论:没有评论
## 课程总结:《Log Analysis - Detecting Web Attacks》 **课程目标:** 本课程旨在教授学员如何通过分析Web服务器和认证服务(如SSH、FTP)的日志,识别并追踪针对Web应用程序和服务的恶意攻击。学员将学习到攻击模式、日志分析的基础知识、常用工具和技术,并掌握解读日志信息的核心技能,从而提升在网络安全和系统管理方面的实用能力。 **核心内容:** * **日志的重要性与基础:** 深入理解日志数据中蕴含的巨大价值,以及日志在事件追踪和安全分析中的关键作用。 * **Web服务器日志分析:** * 学习Apache、Nginx和Microsoft IIS等主流Web服务器的日志结构和默认存储位置。 * 识别Web服务器日志中的恶意流量和攻击模式。 * **认证服务日志分析:** * 了解SSH和FTP等认证服务日志的特点。 * 识别针对认证服务的暴力破解等攻击迹象。 * **攻击与防御双重视角:** * 模拟攻击者的行为,制造恶意流量。 * 扮演防御者角色,利用多种工具分析日志,直观感受攻击发生时的日志表现。 * **实践操作与环境搭建:** * 搭建测试环境,包含攻击者和受害者机器。 * 生成正常和恶意流量,并通过实操分析日志。 * **最佳实践与问题排查:** * 学习OWASP等安全标准推荐的日志记录最佳实践,确保日志记录的全面性和有效性。 * 培养通用的日志分析思维,能够快速定位系统问题和安全事件。 **课程特色:** * **理论与实践相结合:** 兼顾日志分析的理论知识和实操技能。 * **动手能力培养:** 通过搭建环境、模拟攻击和日志分析,获得宝贵的实践经验。 * **直观的学习体验:** 能够直观地看到攻击在日志中的体现,加深对攻击模式的理解。 * **实用的技能提升:** 帮助学员为日常安全和管理任务增强实用技能。 **适合人群:** * 想要了解Web应用程序攻击模式的开发者。 * 希望掌握攻击检测基本原理和工具的网络管理员。 * 旨在提升分析和定位攻击能力的安全专业人士。 * 任何希望通过日志分析增强系统安全性和管理效率的IT从业者。 通过本课程的学习,学员将能够建立起对日志分析的扎实基础,并自信地识别和响应潜在的网络攻击。
Some Important Questions.Are you curious on how an attack pattern looks when a web application is under a malicious attack?Are you interested in knowing the basics of attack detection and what tools and techniques are used when we want to detect an attack on a web application or an authentication service like SSH or FTP?Do you want to develop a basic skillset on reading and deciphering the interesting information in logs & add value to your existing skills?You could be an application developer, a network administrator, a security professional who would like to gain the skills to detect and pinpoint attacks by malicious actors and protect your web applications.About the courseThis course is designed with a sole purpose to educate learners about the immense value the web server and authentication logs or logs in general store and how the information in these logs can be helpful to detect any ongoing attack that your webserver or authentication service might be under. Or an attack that already have taken place. This course explains the basics of web servers and how the logging is done on the web servers default logging locations. We also explain about the structure of logs & default logging locations for the widely used web servers - Apache, Nginx & Microsoft IIS. Authentication servers like SSH & FTP as these too often come under bruteforce attack.Course teaching methodologyWe focus on both theoretical & practical aspects of log analysis. So we work in both the ways - as an attacker who would try to attack the application / SSH / FTP services & a defender, who will analyse the logs using multiple tools and visualise how the logs of an application under attack can look like.We setup a test environment with a victim machine and an attacker machine and generate both normal and malicious traffic and then use the generated logs to investigate the common attack pattern and learn the typicality of an attack and educate ourselves on how the attacks look in the logs and appreciate how logs store valuable information which is often overlooked.This will ensure that learners will get hands-on experience on the concept of log analysis and utilise this basic skillset in their day-to-day security or administrative tasks & activities.We also discuss about the best practices from multiple standard sources that can be implemented to ensure that the logging is done at an optimum level and stay vigilant.By the end of the course, you will gain a foundational understanding on:Grasp the basics of logging concepts, its importance and standard log formats & log storage location for web servers like Apache, Nginx & Microsoft IIS. Authentication services like SSH & FTP.Identify the Malicious traffic that gets logged and ascertain if the application / service is under active attack or has been attacked and learn about the potential point of attack.Gain a broad insight on best logging practices as per the OWASP guidelines and develop an understanding on ways in which you can implement a robust logging for your IT assets.Gain an overall thought process for analysing any of the logs of system and troubleshoot and pinpoint an issue.