Canada IT Courses
ExitCertified US




ExitCertified - Excellence in IT Certified Education
 
IT education classes
IT training feature sheet
 
   
 
start > courses and registration > training feature sheet
Enterprise Intrusion Analysis :: [SC-375]
 
 
 
 
sun microsystems certified training   this course works with savings passes
 
code. SC-375   length. 5 days
type. Instructor-Led   partner. Sun Microsystems
price.
$3,500 :: $2,975 GSA GOV.
 
 
The Enterprise Intrusion Analysis course provides students with the skills needed to discover and analyze enterprise intrusions in a UNIX environment.
 
course schedule  
 
There are currently no scheduled dates for this course. If you are interested in this course, request a course date with the links below.
   
Request course date Request on site training
 
who can benefit
 
 
Students who can benefit from this course are systems administrators and security administrators who are responsible for detecting and analyzing enterprise system intrusions.
 
prerequisites
 
 
o succeed fully in this course, students should be able to:

Demonstrate basic UNIX system and network administration skills
Demonstrate a basic understanding of Transmission Control Protocol/Internet Protocol (TCP/IP) networking
Demonstrate an intermediate understanding of network services: DNS, DHCP, SMTP, HTTP, and firewalls


 
skills gained
 
 
Upon completion of this course, students should be able to:

1. Detect an enterprise system intrusion
2. Analyze a compromised system for crucial information: attack time, attacker location, attcker modifications to the system
3. Corrolate multiple log files from different parts of the enterprise to determine attacker usage
4. Conduct an audit of file systems to determine attacker modifications
5. Describe modern attacker methodology with proof of concept examples




 
course content details  
 


  Module 1 - Enterprise Footprinting

Describe the principals of least privilege and disclosure
Describe how attackers use active fingerprinting using port scans, DNS and ICMP
Describe how attackers use passive fingerprinting using search engines
Describe how attackers enumerate services by collecting banner messages and protocol information
Describe how attackers use social engineering methods to gather information about an enterprise




  Module 2 - Unauthorized System Access

Describe how attackers gain unauthorized access through user accounts
Describe how attackers gain unauthorized access through software flaws
Explain the attacker methodology for locating vulnerable enterprise services and creating exploits
Describe a buffer overflow
Descirbe privilege escalation
Describe a Trojan horse as a means to escalate priviliges




  Module 3 - Securing root Access

Describe how attackers secure root access through backdoors on a system
Describe the following back doors: SUID shell, bound shell, and trusted hosts
Describe a file system root kit
Demonstrate how a file system root kit hides files, processes, and connections
Describe a kernel root kit
Demonstrate how a kernel rootkit captures all system activity




  Module 4 - Encrypting and Hiding Data on a System

Review encryption technology
Describe how attackers use cryptography to encrypt files
Demonstrate encryption using GnuPGP and OpenSSL
Describe digital steganography
Demonstrate how attackers hide files within files using digital steganography
Describe how attackers hide data withing unexpected parts of the file system
Demonstrate how attackers hide a file in file system metadata
Demonstrate how attackers use the loopback file system and extended attributes to hide data




  Module 5 - Enterprise Log Analysis

Identify the different types of enterprise services: like DNS, DHCP, SMTP, HTTP, and Firewalls
Identify available log files for enterprise services
Describe the relevant intrusion information in each log file
Examine enterprise log files to locate suspicious activity
Corrolate information from multiple log files to determine an intrusion




  Module 6 - Unauthorized System Access Intrusion Analysis

Identify default system access log files in the /var directory structure
Identify optional Basic Security Module (BSM) and system accounting log files
Describe log file formats and tools available to read the formats
Describe the relevant information in each log file
Corrolate information from multiple log files to determine unauthorized system access
Demonstrate how attackers modify log files to hide their presence on a system




  Module 7 - File System Intrusion Analysis

Define systems and utility trust
Locate backdoors on a UNIX System: alternate root accounts, bound shells, SUID shells, trusted host files
Locate file system root kits on a UNIX System
Discover hidden directories, replaced system commands, remote command utilities, and network sniffers
Describe automated file system analysis tools
Implement the rkhunter, chkrootkit, and Solaris Fingerprint Database to locate root kits




  Module 8 - System Memory Analysis

Describe the important types of intrusion data that resides in memory
Describe techniques to capture volatile memory data to a file system
Introduce memory analysis tools mdb and gdb
Demonstrate how to recovery data from memory using the mdb and gdb tools




  Module 9 - Incident Investigation Methodologies

Identify different types of intrusion scenarios
Apply a methodology based on an intrusion scenario
Collect the appropriate data (log files, file systems, and memory images) based on the intrusion scenario





 
Advanced training to the point.  Contact an expert training consultant to put together the best training package for your organization

Save on Sun Microsystems Training



find a course
 
phone us
 
view course schedule





Give your team direction.  Authorized IT education.

 
go to top
Sun Microsystems, Veritas, Oracle, Symantec, and Project Management IT Education Sun Microsystems, Veritas, Oracle, Symantec, and Project Management IT Education
© 2008 ExitCertified. All rights reserved.
terms of use and disclaimer :: privacy policy :: webmaster :: link to us
   
Sacramento Training :: 916.669.3970 | Las Vegas Training :: 1.800.803.EXIT (3948) | San Francisco Training :: 415.975.3948 | San Jose Training :: 408.288.EXIT (3948)
Phoenix, Arizona Training | Los Angeles, California Training | San Diego, California Training | Broomfield, Colorado Training | Fort Lauderdale, Florida Training
Tampa, Florida Training | Atlanta, Georgia | Downers Grove, Illinois | Kansas City, Kansas Training | Portland, Maine Training | Baltimore, Maryland Training | Burlington, Massachusetts Training
Troy, Detroit, Michigan Training | Minneapolis, Minesota Training | St. Louis, Missouri Training | Omaha, Nebraska Training | Edison, New Jersey Training | New York City, New York Training
Raleigh, North Carolina Training | Columbus, Ohio Training | Philadelphia, Pennsylvania Training | Nashville, Tennessee Training | Dallas, Texas Training
Houston, Texas Training | Hampton, Virginia Training | Madison, Wisconsin Training | Seattle, Washington Training

ExitCertified is a global provider of authorized technology training. Some of our popular course topic searches include:

Java Training | J2EE Training | JSP Training | Java Courses | Servlets Training | EJB Training | Struts Training | Networking Courses | Solaris Training
Red Hat Training | SUSE Training | XML Training | Oracle SQL | Oracle PL/SQL | DBA Training | DBA Certification | Oracle Certification
RedHat Training | Solaris Certification | Java Certification | Veritas Certification | PeopleSoft Training | 11g Training | 11g Certification
RedHat Courses | SQL Training | 10g Training | 9i Training | Application Development Training | Certified Training | Corporate Training
Government Training | Course Catalogue | Training Schedule | Certification Training | Project Management Training | Linux Training
Solaris 10 Training | Unix Training | NetBackup Training | Virus Protection Courses | Education Technology Newsletter | zSeries Training
s/390 Training | iSeries Training | DB2 Training | OS/400 Training | AIX Training | Rational Courses | PMI Training | Project Management Training
SeeBeyond Training | Java Composite Application Platform (JCAPS) Training | MySQL Training | MySQL Database Course | Hyperion Training | Fusion Middleware