Cisco Network Security: Intrusion Detection and Prevention
1h 11mIntermediate2018-07-19
Authors

Lisa Bock
Security ambassador with a broad range of IT skills and knowledge
Course details
A network must be able to quickly recognize threats. Intrusion detection and intrusion prevention systems (IDS/IPS) provide organizations with a proactive approach to monitoring their network, enabling them to take action against possible threats. In this course, join security ambassador Lisa Bock as she provides an overview of intrusion detection and intrusion prevention systems and explains how they detect and mitigate common attacks. She covers detection and signature engines, triggering actions and responses, and deploying an IOS-based IPS. In addition, she goes over some practical applications of these systems, including honeypot-based intrusion detection and the EINSTEIN system from the Department of Homeland Security..
Learning objectives
Managing the threat landscape
IPS versus IDS
Detection and signature engines
IDS signature files
Blacklists and whitelists
Managing IPS alarms
Deploying IOS-based IPS
Using IDS and honeypots
Learning objectives
Managing the threat landscape
IPS versus IDS
Detection and signature engines
IDS signature files
Blacklists and whitelists
Managing IPS alarms
Deploying IOS-based IPS
Using IDS and honeypots
Skills covered
Cisco RoutersCiscoNetwork SecurityNetwork AdministrationCybersecurityCert PrepNetwork and System Administration
Concepts
0. Introduction
- 01 - Welcome
- 02 - What you need to know
- 03 - Packet Tracer and exercise files
- 04 - Prepare for the CCNA Security Exam (210-260)
1. IDS and IPS Overview
- 05 - Managing the threat landscape
- 06 - Overview and benefits of IDS and IPS
- 07 - IPS versus IDS
- 08 - Host-based versus network IDS
- 09 - Prerequisites and restrictions for IPS
2. Detection and Signature Engines
- 10 - Monitoring the network
- 11 - Signature-based IDS
- 12 - Sweep scan
- 13 - Anomaly-based IDS
- 14 - Reputation-based IDS
- 15 - Policy-based IDS
3. Decisions and Actions
- 16 - IDS signature files
- 17 - Trigger actions and responses
- 18 - Blacklist and whitelist
- 19 - Managing IPS alarms
4. Deploying an IOS-Based IPS
- 20 - Analyze the flow
- 21 - Implementing an IPS
- 22 - Configure an IPS
5. Practical Applications
- 23 - Monitoring and analyzing
- 24 - Syslog
- 25 - Using IDS and honeypots
- 26 - The EINSTEIN system
Conclusion
- 27 - Summary