This cyber security course focusses on the network side of security. Technologies rather than specific products are studied focussing around the protection of networks using firewalls and VPNs.
Anyone working in the security field.
TCP/IP foundation for engineers
5 days
Denial of service, DDOS, data manipulation, data theft, data destruction, security checklists, incident response.
IP spoofing, SYN attacks, hijacking, reflectors and amplification, keeping up to date with new threats.
Hands on port scanning, use a “hacking” tool.
Windows, Linux, Log files, syslogd, accounts, data security.
Hands on Server hardening.
What is a firewall? Firewall benefits, concepts.
HAnds on launching various attacks on a target.
Packet filtering, SPI, Proxy, Personal. Software firewalls, hardware firewalls. Firewall products.
Hands on Simple personal firewall configuration.
Things to filter in the IP header, stateless vs. stateful filtering. ACLs. Advantages of packet filtering.
Hands on Configuring packet filtering firewalls.
Stateful algorithms, packet-by-packet inspection, application content filtering, tracks, special handling (fragments, IP options), sessions with TCP and UDP. Firewall hacking detection: SYN attacks, SSL, SSH interception.
Hands on SPI firewalls.
Circuit level, application level, SOCKS. Proxy firewall plusses and minuses.
Hands on Proxy firewalls.
Small office, enterprise, service provider, what is a DMZ? DMZ architectures, bastion hosts, multi DMZ. Virtual firewalls, transparent firewalls. Dual firewall design, high availability, load balancing, VRRP.
Hands on Resilient firewall architecture.
Configuration checklist, testing procedure, monitoring firewalls, logging, syslog.
Hands on Testing firewalls.
Encryption keys, Encryption strengths, Secret key vs Public key, algorithms, systems, SSL, SSH, Public Key Infrastructures.
Hands on Password cracking.
Types of authentication, Securid, Biometrics, PGP, Digital certificates, X.509 v3, Certificate authorities, CRLs, RADIUS.
Hands on Using certificates.
What is a VPN? What is an IP VPN? VPNs vs. Private Data Networks, Internet VPNs, Intranet VPNs, Remote access VPNs, Site to site VPNs, VPN benefits and disadvantages.
VPN components, VPN tunnels, tunnel sources, tunnel end points, tunnelling topologies, tunnelling protocols, which tunnelling protocol? Requirements of tunnels.
Overview, components, how it works, security, packet authentication, L2TP/IPsec, L2TP/PPP, L2 vs L3 tunnelling.
Hands on Implementing a L2TP tunnel.
AH, HMAC, ESP, transport and tunnel modes, Security Association, encryption and authentication algorithms, manual vs automated key exchange, NAT and other issues.
Hands on Implementing an IPsec VPN.
Layer 4 VPNs, advantages, disadvantages. SSL. TLS. TLS negotiation, TLS authentication. TLS and certificates.
Hands on Implementing a SSL VPN.
Introduction to MPLS, why use MPLS, Headers, architecture, label switching, LDP, MPLS VPNs, L2 versus L3 VPNs. Point to point versus multipoint MPLS VPNs. MBGP and VRFs and their use in MPLS VPNs.
Hands on Implementing a MPLS L3 VPN.
Hacking webservers, web applications, Wireless networks and mobile platforms. Concepts, threats, methodology.
Hands on Hacking tools and countermeasures.
"A good intro to a complex subject."
"Course was a real eye-opener to some of the barriers we encounter."
This structured course uses Instructor Led Training to provide the best possible learning experience. Small class sizes ensure students benefit from our engaging and interactive style of teaching with delegates encouraged to ask questions throughout the course. Quizzes follow each major section allowing checking of learning. Hands on sessions are used throughout to allow delegates to consolidate their new skills.