Cisco®Securing Cisco Networks with Open Source Snort (SSFSNORT) v3.0

The Securing Cisco Networks with Open Source Snort (SSFSNORT) v3.0 course shows you how to deploy Snort® in small to enterprise-scale implementations. You will learn how to install, configure, and operate Snort in Intrusion Detection System (IDS) and Intrusion Prevention System (IPS) modes. You’ll practice installing and configuring Snort, utilize additional software tools and define rules to configure and improve the Snort environment, and more

Cisco®Securing Cisco Networks with Open Source Snort (SSFSNORT) v3.0

Skip to Available Dates

Learning Objectives

After taking this course, you should be able to:

  • Define the use and placement IDS/IPS components.
  • Identify Snort features and requirements.
  • Compile and install Snort.
  • Define and use different modes of Snort.
  • Install and utilize Snort supporting software.

     

    Course Details

    Course Outline

    1 - Detecting Intrusions with Snort 3.0
  • History of Snort
  • IDS
  • IPS
  • IDS vs. IPS
  • Examining Attack Vectors
  • Application vs. Service Recognition
  • 2 - Sniffing the Network
  • Protocol Analyzers
  • Configuring Global Preferences
  • Capture and Display Filters
  • Capturing Packets
  • Decrypting Secure Sockets Layer (SSL) Encrypted Packets
  • 3 - Architecting Nextgen Detection
  • Snort 3.0 Design
  • Modular Design Support
  • Plug Holes with Plugins
  • Process Packets
  • Detect Interesting Traffic with Rules
  • Output Data
  • 4 - Choosing a Snort Platform
  • Provisioning and Placing Snort
  • Installing Snort on Linux
  • 5 - Operating Snort 3.0
  • Topic 1: Start Snort
  • Monitor the System for Intrusion Attempts
  • Define Traffic to Monitor
  • Log Intrusion Attempts
  • Actions to Take When Snort Detects an Intrusion Attempt
  • License Snort and Subscriptions
  • 6 - Examining Snort 3.0 Configuration
  • Introducing Key Features
  • Configure Sensors
  • Lua Configuration Wizard
  • 7 - Managing Snort
  • Pulled Pork
  • Barnyard2
  • Elasticsearch, Logstash, and Kibana (ELK)
  • 8 - Analyzing Rule Syntax and Usage
  • Anatomy of Snort Rules
  • Understand Rule Headers
  • Apply Rule Options
  • Shared Object Rules
  • Optimize Rules
  • Analyze Statistics
  • 9 - Use Distributed Snort 3.0
  • Design a Distributed Snort System
  • Sensor Placement
  • Sensor Hardware Requirements
  • Necessary Software
  • Snort Configuration
  • Monitor with Snort
  • 10 - Examining Lua
  • Introduction to Lua
  • Get Started with Lua
  • Actual course outline may vary depending on offering center. Contact your sales representative for more information.

    Who is it For?

    Target Audience

    Security administrators

    Security consultants

    Network administrators

    System engineers

    Technical support personnel

    Channel partners and resellers

    Other Prerequisites

    To fully benefit from this course, you should have the following knowledge and skills:

    Technical understanding of TCP/IP networking and network architecture

    Basic familiarity with firewall and IPS concepts

    Cisco®Securing Cisco Networks with Open Source Snort (SSFSNORT) v3.0

    Call | This course is CLC-Eligible
    Course Length : 4 Days

    There are currently no scheduled dates for this course. Please contact us for more information.

    Need Help Picking the Right Course? Give us a call! 800-201-0555