Cyber Security

From KENET Training
Revision as of 12:21, 12 March 2014 by Admin (talk | contribs) (Timetable)
Jump to: navigation, search

Cyber Security Workshop

Security within the campus network has become an area that the network and system administrators need to focus more on. This workshop will focus on empowering the system administrators on how to secure the services and servers within the campus and also empower the network administrators on how to secure the campus network.

REGISTRATION CLOSED

Objective

This training will enable the network and system administrators run secure services within the campus network.

Who Should Attend?

This course is designed for system and network administrators who are interested in learning and implementing best practices for running a secure and stable campus network.

Prerequisites

I.A laptop with wireless capability

II.IPv4 addressing and general network concepts

III. Knowledge of UNIX and/or Linux

IV. At least three years’ experience as a systems / network administrator in a medium to large campus network

V. Residential


Target Group:

Systems/Network Administrators in charge of security;

Timetable

Day 8.30-10.30 10.30-10.50 10.50-13.00 1300-1400 1400-1600 1600-1620 1620-1800
Monday Welcome and registrationFundamentals of security [[1]] Tea Break Attacks and Threats [[2]] Lunch Switching security [[3]] Tea Break Switching security
Tuesday Application and Network Attacks Tea Break Application and Network Attacks Lab [[4]] Lunch Network Security and Defense [[5]] Tea Break Network Security and Defense Lab [[6]] Wireless Security [[7]]
Wednesday Host, Application, and Data Security Presentation [[8]] Tea Break Host, Application, and Data Security Mod Security [[9]] Ip tables[[10]] SSH keys [[11]] Lunch Digital Certificates & PKI [[12]] Tea Break Digital Certificates & PKI Lab 1 [[13]] Lab 2 [[14]]
Thursday Web/Software application security Tea Break Web/Software application security Lunch Vulnerability Assessment and Mitigating Attacks Tea Break Vulnerability Assessment and Mitigating Attacks
Friday Access Control and Physical (Environmental) Security Tea Break Access Control and Physical (Environmental) Security Lunch Closing ceremony and certificate Tea Break

Course content

Security Fundamentals

Confidentiality

Integrity

Availability

Attacks and Threats

Worms & Trojans

Malware and Social Engineering Attacks

Attacks Using Malware

Social Engineering Attacks

Switching security

Port Security

Understanding Switch Security Issues

Protecting Against VLAN Attacks

Protecting Against Spoofing Attacks

Securing Network Services

Secure Network Switches to Mitigate Security Attack

Application and Network Attacks

Application Attacks

Rogue DHCP Server protection

Web Application Attacks

Client-Side Attacks

Buffer Overflow Attacks

Network Attacks

Denial of Service (DoS)

Interception

Poisoning

Attacks on Access Rights

Network Security and Defense

Security Through Network Devices

Security Through Network Technologies

Network Address Translation (NAT)

Network Access Control (NAC)

Security Through Network Design Elements

Demilitarized Zone (DMZ)

Subnetting

Virtual LANs (VLANs)

Remote Access

Wireless Network Security

Host, Application, and Data Security

Securing Devices.

Physical Security

Hardware Security

Securing the Operating System Software

Securing with Anti-Malware Software

Monitoring System Logs

Application Security

Digital Certificates & PKI

Introduction to cryptography/symmetric and public key cryptography

Digital certificates

Digital signatures

Public Key Infrastructure

Web/Software application security

web applications vulnerabilities

Cross Site Scripting

SQL Injection

Denial of Service

Code Execution

Local File include

General web application security recommendations

Guard against malicious user input

Vulnerability Assessment and Mitigating Attacks

Assessment Techniques

Assessment Tools

Vulnerability Scanning?

Penetration Testing

Creating a Security Posture

Configuring Controls

Hardening

Reporting

Access Control and Physical (Environmental) Security

Identification

Authorization

Authentication

Accounting

Cyber Law

Legal regulations

Investigations and Compliance