|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/snort-intrusion-detection-rule-writing-and-pcap-analysis/
课程评论:没有评论
Coursera 课程:Snort 入侵检测、规则编写与 PCAP 分析 本课程由 Jesse Kurrus 主讲,是一门 **100% 实践驱动**的课程(除初步介绍外),旨在教授 **Snort 入侵检测系统**的**规则编写**和**PCAP 文件分析**。 **先决条件:** * VirtualBox(免费开源) * Security Onion 虚拟机(免费开源) * Kali Linux 虚拟机(免费开源) * Windows 7 虚拟机(可免费用于开发目的) **课程亮点:** 课程通过一系列动手实验,让学员深入理解 Snort 的各项功能。核心内容涵盖: * **基础环境搭建:** 学习如何在 VirtualBox 中部署 Security Onion。 * **Snort 规则编写:** 掌握针对不同攻击(如 Boleto 恶意软件、SSH、FTP)编写有效的 Snort 规则。 * **PCAP 文件分析:** 学习如何分析网络流量捕获文件(PCAP),识别恶意活动。 * **规则质量评估:** 通过“Dumbpig”等工具,学习评估和优化 Snort 规则的质量。 * **规则参数运用:** 深入理解并运用 `offset` 和 `depth` 等 Snort 规则参数。 * **实战攻击与防御:** 通过对已知漏洞(如 Eternalblue、Heartbleed)的利用和 Snort 规则的分析,提升实战能力。 **动手实验列表:** 1. 使用 VirtualBox 设置 Security Onion 2. Boleto 恶意软件的 Snort 规则编写和 PCAP 分析 3. 使用 Dumbpig 评估 Snort 规则质量 4. 在 Snort 规则中利用 Offset 和 Depth 5. 使用 VirtualBox 设置 Kali Linux 6. Snort 规则编写(SSH 和 FTP) 7. 设置 Windows 7 Eternalblue 易受攻击虚拟机 8. Windows 7 Eternalblue 漏洞利用及 Snort/PCAP 分析 9. Eternalblue PCAP 分析和 Snort 规则编写 10. 设置 Ubuntu Server 12.04 易受攻击虚拟机 11. Ubuntu Server 12.04 Heartbleed 漏洞利用及 Snort/PCAP 分析 12. Heartbleed PCAP 分析和 Snort 规则编写 本课程适合所有希望提升网络安全技能,特别是专注于入侵检测和防御的专业人士和学习者。
Hello everybody. My name is Jesse Kurrus, and I'll be your professor for the duration of the Snort Intrusion Detection, Rule Writing, and PCAP Analysis course. This course will consist of written material to go over on your own pace, and labs to reinforce the concepts from the provided resources. To follow along with these labs, you'll need a VirtualBox, Security Onion, Kali Linux, and Windows 7 VMs. These are all free and open source, including the Windows 7 VM which is available free for development purposes. This course is 100% hands-on, save for the initial introduction. Please be prepared to follow along with these labs. The following are the hands-on labs. Please refer to the course for full descriptions: Lab 1: Setting up Security Onion with VirtualBoxLab 2: Boleto Malware Snort Rule Writing and PCAP AnalysisLab 3: Vetting Snort Rule Quality with DumbpigLab 4: Utilizing Offset and Depth in a Snort RuleLab 5: Kali Linux Setup with VirtualBoxLab 6: Snort Rule Writing (SSH and FTP)Lab 7: Windows 7 Eternalblue Vulnerable VM VirtualBox SetupLab 8: Windows 7 Eternalblue Exploitation and Snort/PCAP AnalysisLab 9: Eternalblue PCAP Analysis and Snort Rule WritingLab 10: Ubuntu Server 12.04 Vulnerable VM VirtualBox SetupLab 11: Ubuntu Server 12.04 Heartbleed Exploitation and Snort/PCAP AnalysisLab 12: Heartbleed PCAP Analysis and Snort Rule Writing