This video defines what intrusion and security events are and explains their role in network forensics.
- [Instructor] Examining network logs … and searching for a series of related security events … to detect an intrusion after a cybersecurity incident … is a passive approach in network forensics. … A more active way is to monitor network traffic in real time … to catch attacks while they are underway. … We call this more proactive method … active intrusion detection. … One of the well-known open source … active intrusion detection system or IDS is Snort. … Both Linux and Windows versions are available … for installation. … Once installed, Snort starts capturing packets … and inspecting them for known attack data patterns … which we call signatures. … Snort also supports both predefined and user-defined rules. … Rules rely on the protocol a packet is associated with … and where it's originated from and going … and are therefore different from signatures … that are unique fingerprints in packets. … I have Snort installed on my Linux virtual machine. … Before we do anything, let's check the details …
- Goals of network forensics
- Using a syslog and Microsoft Log Parser
- Investigating network traffic
- How protocol analysis works
- ARP and DNS poisoning
- Working with network forensics tools
- Using packet sniffers
Skill Level Intermediate
Learning Cryptography and Network Securitywith Lisa Bock1h 45m Intermediate
Insights from a Cybersecurity Professionalwith Mike Chapple32m 15s Intermediate
What you should know2m 11s
1. Understanding Network Forensics
2. Preparing for a Network Forensics Investigation
3. Investigating Network Events
4. Investigating Network Traffic
5. Network Forensics Tools
Next steps1m 15s
- Mark as unwatched
- Mark all as unwatched
Are you sure you want to mark all the videos in this course as unwatched?
This will not affect your course history, your reports, or your certificates of completion for this course.Cancel
Take notes with your new membership!
Type in the entry box, then click Enter to save your note.
1:30Press on any video thumbnail to jump immediately to the timecode shown.
Notes are saved with you account but can also be exported as plain text, MS Word, PDF, Google Doc, or Evernote.