SECB455: Intrusion Detection and Response

Description:Setup and configuration of intrusion detection and response systems in a network; Attack generation (e.g. denial-of-service and sniffing attacks) and configuration of the intrusion detection system (IDS) to detect the attacks; Misuse and anomaly detection; Network attacks (e.g. denial of service, sniffing attacks, buffer overflow.); Fundamental limits of intrusion detection; Statistical techniques; Signature and pattern matching techniques; Artificial intelligence techniques
Credit Hours.:3
Text Book: Network Intrusion Detection (3rd Edition), Stephen Northcutt, Judy Novak, Publisher: Sams; 3 edition
Coordinator: Zouheir Trabelsi
Topics Outline:
  1. Networking hacking
  2. Internet addressing & Subnet networks
  3. Vulnerabilities of the ARP protocol
  4. Sniffers in shared network & Sniffers detection techniques
  5. ARP spoofing and Man-in-the-middle attack
  6. Sniffers in switched network & Sniffers detection techniques
  7. Vulnerabilities of the IP protocol
  8. Vulnerabilities of the ICMP protocol Vulnerabilities of the TCP and UDP protocols
  9. Common attacks: Buffer overflow, Unicode, NetBios attacks, SMTP relay, etc. .Information gathering and vulnerabilities discovery processes
  10. Automatic vulnerabilities scanners and port scanner: GFI languard scanner and NetScanTools .Denial of service (DoS)attacks
  11. NetsScreen IDS (1) NetScreen IDS (2)
  12. IDS sensor
  1. Identify the most common networks attacks
  2. Analyze counter measures of network attacks
  3. Perform security auditing and vulnerability assessment.
  4. Create new attack signatures.
  5. Integrate IDS/IPS sensors.
Mapping of Topics Outline to Outcomes
 1 2 3 4 5 6 7 8 9 10 11 12
Pre-requisiteSECB358: Network Border Controls
Co-requisite SECB432: Networks Security Lab
Volume of the Course that Contributes to CIT Students Outcomes(SOs)
a b c d e f g h i j k l m n
0% 8% 4% 0% 0% 0%0% 0% 6% 8% 24% 24% 8% 13%
