Securing Cisco Networks with Open Source Snort (SSFSNORT)
Duration: 4 Days (32 Hours)
Securing Cisco Networks with Open Source Snort (SSFSNORT) Course Overview:
What you’ll learn in this course
The Securing Cisco Networks with Open Source Snort (SSFSNORT) v3.0 course provides comprehensive training on deploying Snort® in various implementations, ranging from small-scale to enterprise-level environments. Participants will gain proficiency in installing, configuring, and operating Snort as both an Intrusion Detection System (IDS) and an Intrusion Prevention System (IPS). The course includes hands-on practice in installing and configuring Snort, utilizing additional software tools, defining rules to enhance the Snort environment, and various other topics to enhance your understanding and skills in using Snort effectively.
How you’ll benefit
This course will help you:
● Learning how to implement Snort, an open-source, rule-based, intrusion detection and prevention system
● Gain leading-edge skills for high-demand responsibilities focused on security
Who should enroll
● Security administrators
● Security consultants
● Network administrators
● System engineers
● Technical support personnel
● Channel partners and resellers
Technology areas
● Security
● Cyber Operations
Objectives
After taking this course, you should be able to:
● Define the use and placement IDS/IPS components.
● Identify Snort features and requirements.
● Compile and install Snort.
● Define and use different modes of Snort.
● Install and utilize Snort supporting software.
Outline
● Detecting Intrusions with Snort 3.0
◦ History of Snort
◦ IDS
◦ IPS
◦ IDS vs. IPS
◦ Examining Attack Vectors
◦ Application vs. Service Recognition
● Sniffing the Network
◦ Protocol Analyzers
◦ Configuring Global Preferences
◦ Capture and Display Filters
◦ Capturing Packets
◦ Decrypting Secure Sockets Layer (SSL) Encrypted Packets
● Architecting Nextgen Detection
◦ Snort 3.0 Design
◦ Modular Design Support
◦ Plug Holes with Plugins
◦ Process Packets
◦ Detect Interesting Traffic with Rules
◦ Output Data
● Choosing a Snort Platform
◦ Provisioning and Placing Snort
◦ Installing Snort on Linux
● Operating Snort 3.0
◦ Topic 1: Start Snort
◦ Monitor the System for Intrusion Attempts
◦ Define Traffic to Monitor
◦ Log Intrusion Attempts
◦ Actions to Take When Snort Detects an Intrusion Attempt
◦ License Snort and Subscriptions
● Examining Snort 3.0 Configuration
◦ Introducing Key Features
◦ Configure Sensors
◦ Lua Configuration Wizard
● Managing Snort
◦ Pulled Pork
◦ Barnyard2
◦ Elasticsearch, Logstash, and Kibana (ELK)
● Analyzing Rule Syntax and Usage
◦ Anatomy of Snort Rules
◦ Understand Rule Headers
◦ Apply Rule Options
◦ Shared Object Rules
◦ Optimize Rules
◦ Analyze Statistics
● Use Distributed Snort 3.0
◦ Design a Distributed Snort System
◦ Sensor Placement
◦ Sensor Hardware Requirements
◦ Necessary Software
◦ Snort Configuration
◦ Monitor with Snort
● Examining Lua
◦ Introduction to Lua
◦ Get Started with Lua
Lab Outline
● Capture and Analyze Packets
● Initiate the Snort Installation
● Complete an Installation of Snort
● Configure and Run Snort
● Tweak the Installation
● Rapid Deployment with Lua
● Integrate Snort Optimizers
● Analyze Rule Syntax
● Hello World Lua Style
To fully benefit from this course, you should have the following knowledge and skills:
● Technical understanding of TCP/IP networking and network architecture
● Basic familiarity with firewall and IPS concepts
This is the recommended Cisco course that may help you meet these prerequisites:
● Implementing and Administering Cisco Solutions (CCNA)
Discover the perfect fit for your learning journey
Choose Learning Modality
Live Online
- Convenience
- Cost-effective
- Self-paced learning
- Scalability
Classroom
- Interaction and collaboration
- Networking opportunities
- Real-time feedback
- Personal attention
Onsite
- Familiar environment
- Confidentiality
- Team building
- Immediate application
Training Exclusives
This course comes with following benefits:
- Practice Labs.
- Get Trained by Certified Trainers.
- Access to the recordings of your class sessions for 90 days.
- Digital courseware
- Experience 24*7 learner support.
Got more questions? We’re all ears and ready to assist!