Network Level Cyber Attack Detection

所在平台: Udemy

课程主页: https://www.udemy.com/course/network-level-cyber-attack-detection/

课程评论:没有评论

第一个写评论        关注课程

课程简介

Coursera课程《网络层网络攻击检测》 该课程旨在教授学员如何创建数据包来模拟恶意软件行为,深入讲解L7协议的报文深度检测方法,以及Snort和Suricata的安装与配置。学员将学习编写自定义IPS/IDS签名关键字,以有效检测各类网络攻击。课程还会介绍使用Remnux进行基础动态恶意软件分析技术,并指导如何使用蜜罐(Honeypot)来检测内部威胁,以及利用osquery分析终端的网络套接字。 学员将熟练使用Wireshark和Tshark分析pcap文件,并根据分析结果生成自定义规则,以检测包括勒索软件、钓鱼域名、SSH、DNS、ICMP隧道、零日漏洞利用代码、公开漏洞利用、文件传输、数据泄露、SQL注入、包含型Web攻击以及Web Shell在内的多种攻击形式。

课程评论(0条)

课程详情

In this course students will learn creating packets with scapy for simulating the malware behaivours, I am gonna teach you L7 protocols deep packet inspection methods, Snort and Suricata installation, keywords for writing custom IPS / IDS signatures for detecting attacks, some basic dynamic malware analysis techniques with Remnux, Honeypot usage, osquery and more. You use wireshark and tshark for analyzing pcap files and generate custom rules. In this training you will write rules for detecting, ransomwares, phishing domains, SSH, DNS, ICMP tunnels, zero day exploit codes, public exploits, file stransfers, data exfiltration, sql injection, inclusion web attacks and web shells also we use Honeypots for detecting internal threats. You will learn osquery for analysing network sockets in endpoint.

课程标签

0人关注该课程

主题相关的课程