Please enable JavaScript to view this page.

Implementing Network Security

CST 152

Implementing Network Security

CST 152

Course Description

Prerequisite: CST 150. Provides knowledge and the practical experience necessary to evaluate, implement, and manage secure information transferred over computer networks. Includes network security, intrusion detection, types of attacks, methods of attacks, security devices, basics of cryptography, and organizational security elements. (15-30)

Outcomes and Objectives

Discuss network defense fundamentals.

Objectives:

  • Discuss TCP/IP networking.
  • Discuss the threats to network security.
  • Discuss goals of network security.
  • Discuss using network defense technologies in layers.
  • Discuss the impact of defense.

Discuss strengthening and managing firewalls.

Objectives:

  • Discuss managing firewalls to improve security.
  • Discuss Check Point NGX.
  • Discuss Microsoft ISA Server.
  • Discuss managing and configuring IP tables.

Discuss strengthening defense through ongoing management.

Objectives:

  • Discuss security event management.
  • Discuss security auditing.
  • Discuss managing an IDS.
  • Discuss improving defense in-depth.
  • Discuss keeping pace with network needs.
  • Discuss maintaining your own knowledge base.

Discuss security policy design: risk analysis.

Objectives:

  • Discuss the fundamental concepts of risk analysis.
  • Discuss the approaches to risk analysis.
  • Discuss risk analysis as an ongoing process.
  • Discuss deciding how to minimize risk.

Discuss network traffic signatures.

Objectives:

  • Discuss understanding signature analysis.
  • Discuss detecting traffic signatures.
  • Discuss identifying suspicious events.
  • Discuss using the Common Vulnerabilities and Exposures (CVE) Standard.

Discuss Virtual Private Network (VPN) Concepts.

Objectives:

  • Discuss what VPNs are and why establish them.
  • Discuss VPN core activity 1: Encapsulation.
  • Discuss VPN core activity 2: Encryption.
  • Discuss VPN core activity 3: Authentication.
  • Discuss the advantages and disadvantages of VPNs.

Discuss VPN implementation.

Objectives:

  • Discuss designing a VPN.
  • Discuss configuring VPNs.
  • Discuss using VPNs with firewalls.
  • Discuss adjusting packet-filtering rules for VPNs.
  • Discuss auditing VPNs and VPN policies.

Discuss intrusion detection system concepts.

Objectives:

  • Describe intrusion detection system components.
  • Discuss intrusion detection through the 7 steps.
  • Discuss options for implementing intrusion detection systems.
  • Discuss the evaluation of intrusion detection systems.

Discuss intrusion detection and incident response.

Objectives:

  • Discuss developing IDS filter rules.
  • Discuss developing a Security Incident Response Team (SIRT).
  • Discuss how to respond: the incident response process.
  • Discuss dealing with false alarms.
  • Discuss dealing with legitimate security alerts.

Discuss choosing and designing firewalls.

Objectives:

  • Discuss firewalls in general.
  • Discuss approaches to packet filtering.
  • Discuss creating rules and establishing restrictions.
  • Discuss designing firewall configurations.
  • Compare software and hardware firewalls.

Discuss firewall topology.

Objectives:

  • Discuss securing network perimeters.
  • Discuss choosing a bastion host.
  • Discuss working with proxy servers.
  • Discuss using NAT.
  • Discuss authenticating users.