Learn about the tools and techniques used for analyzing traffic passing over the network. This learning path covers identification and analysis of benign and malicious traffic, examples and case studies of extracting intelligence from traffic data, considerations when building a network monitoring program, and techniques for collecting and analyzing traffic data.
Start out on this course by taking a look at what network traffic analysis is and some of its major applications. This introductory module describes network traffic analysis and discusses its applications for monitoring the functionality of networked systems and performing incident response investigations.
涵盖的内容
10个视频
显示有关单元内容的信息
10个视频•总计46分钟
Welcome to network traffic analysis•5分钟
What is network traffic analysis?•6分钟
Functionality monitoring•8分钟
Incident response life cycle•4分钟
Preparation•4分钟
Detection and analysis•4分钟
Containment•5分钟
Eradication•4分钟
Recovery•1分钟
Post-incident response•5分钟
Fundamentals of networking
第 2 单元•小时 后完成
单元详情
In order to identify anomalous or malicious traffic in a network, it’s necessary to first understand what’s normal. This module discusses the fundamentals of networking, including the OSI model, the differences between TCP, UDP and ICMP and their intended uses, and the purposes of common high-level protocols like HTTP and SMTP.
涵盖的内容
18个视频
显示有关单元内容的信息
18个视频•总计56分钟
Fundamentals of networking•3分钟
The OSI Model•5分钟
Basic network protocols•4分钟
Internet protocol (IP)•4分钟
Transmission control protocol (TCP)•6分钟
User datagram protocol (UDP)•3分钟
Internet control message protocol (ICMP)•5分钟
Common network protocols•1分钟
Address resolution protocol (ARP)•3分钟
Domain name system (DNS)•5分钟
File transfer protocol (FTP)•2分钟
Hypertext transfer protocol (HTTP)•3分钟
Internet relay chat (IRC)•2分钟
Simple mail transfer protocol (SMTP)•1分钟
Simple network management protocol (SNMP)•2分钟
Secure shell (SSH)•2分钟
Trivial file transfer protocol (TFTP)•1分钟
Transport layer security (TLS)•4分钟
Hands-on traffic analysis in Wireshark
第 3 单元•小时 后完成
单元详情
Wireshark is probably the most commonly used tool for network traffic analysis and will be used throughout this learning path. This module introduces some of the useful features of Wireshark and shows what the protocols discussed in the previous course look like in practice and how the various layers work together to make networking possible.
涵盖的内容
14个视频
显示有关单元内容的信息
14个视频•总计105分钟
Introduction to Wireshark•7分钟
Features of Wireshark•26分钟
IP demo•12分钟
TCP demo•8分钟
UDP demo•5分钟
ICMP demo•4分钟
ARP demo•6分钟
DNS demo•9分钟
FTP demo•5分钟
HTTP demo•7分钟
IRC demo•4分钟
SMTP demo•5分钟
SSH demo•3分钟
TFTP demo•4分钟
Alternatives to Wireshark
第 4 单元•小时 后完成
单元详情
Wireshark is probably the most popular tool for network traffic analysis. However, it is not the only one available. This module provides an introduction to some alternatives to Wireshark, covering some of the most useful and unique features of Terminal Shark (Wireshark’s command-line equivalent), CloudShark and NetworkMiner.
涵盖的内容
3个视频
显示有关单元内容的信息
3个视频•总计32分钟
Network mapper demo•17分钟
Terminal shark demo•9分钟
CloudShark Demo•5分钟
Network traffic intelligence collection
第 5 单元•小时 后完成
单元详情
A common use of network traffic analysis is for performing incident response activities. The purpose of these actions is to extract useful intelligence from network captures that can help to inform the rest of the investigation. This module demonstrates how to extract certain types of useful data from a network capture file.
涵盖的内容
8个视频
显示有关单元内容的信息
8个视频•总计104分钟
Intelligence collection•6分钟
Network mapping demo•12分钟
Content deobfuscation demo•15分钟
Credential capture demo•10分钟
TLS decryption demo•17分钟
Web proxy demo•17分钟
Online tools demo 1•21分钟
Online tools demo 2•7分钟
Common network threats
第 6 单元•小时 后完成
单元详情
An organization can be attacked over the network in a variety of different ways. However, some methods are more common than others. In this module, you will see what scanning, data exfiltration, DDoS attacks and attacks against IoT devices look like in a network capture in a series of demonstrations.
涵盖的内容
4个视频
显示有关单元内容的信息
4个视频•总计76分钟
Scanning demo•22分钟
Data exfiltration demo•18分钟
DDOS attack demo•18分钟
IoT attack demo•18分钟
Traffic analysis case studies
第 7 单元•小时 后完成
单元详情
Different types of incident response investigations lend themselves to network-based analysis to different degrees. This module consists of a series of demonstrations where analysis of network traffic is used to infer information about different types of malware, including remote access Trojans (RATs), fileless malware, network worms and multi-stage infections.
涵盖的内容
4个视频
显示有关单元内容的信息
4个视频•总计66分钟
RAT demo•13分钟
Fileless case study•16分钟
Worm demo•14分钟
Multistage malware demo•23分钟
Data collection for network traffic analysis
第 8 单元•小时 后完成
单元详情
In order to investigate a network traffic capture, it is first necessary to capture it. This module discusses methods and considerations for data collection of network traffic. Topics include considerations for deployment of monitoring appliances and the use of virtualization and deception for data collection.
涵盖的内容
4个视频
显示有关单元内容的信息
4个视频•总计60分钟
Data collection•5分钟
Monitoring appliance deployment•18分钟
Virtualization for network traffic analysis•13分钟
Deceptive technologies•24分钟
Data analysis for network traffic analysis
第 9 单元•小时 后完成
单元详情
Having access to network traffic data is of very limited value without the ability to analyze it. In this module, you will learn about connection-based analysis, statistical analysis and event-based analysis, their relative pros and cons for different monitoring situations, and tools and techniques for performing them effectively.
涵盖的内容
9个视频
显示有关单元内容的信息
9个视频•总计144分钟
Data analysis•5分钟
Tools for data analysis•11分钟
Scapy demo•21分钟
Data analysis techniques•4分钟
Connection analysis•9分钟
Statistical analysis•22分钟
Event-based analysis•42分钟
YARA demo•18分钟
Snort demo•12分钟
Network traffic analysis for incident response project
第 10 单元•小时 后完成
单元详情
In this project, you will need to apply your knowledge and use common network traffic analysis tools to solve multiple challenges. Each challenge involves examining a network traffic capture file containing evidence of malicious activity, such as malware infection, data exfiltration and C2 (command-and-control) communications. You’ll need to find leaked credentials, analyze an attempted DDoS attack, extract files from captures and even more.
Infosec believes knowledge is power when fighting cybercrime. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and privacy training to stay cyber-safe at work and home. Learn more at infosecinstitute.com.
When will I have access to the lectures and assignments?
To access the course materials, assignments and to earn a Certificate, you will need to purchase the Certificate experience when you enroll in a course. You can try a Free Trial instead, or apply for Financial Aid. The course may offer 'Full Course, No Certificate' instead. This option lets you see all course materials, submit required assessments, and get a final grade. This also means that you will not be able to purchase a Certificate experience.
What will I get if I purchase the Certificate?
When you purchase a Certificate you get access to all course materials, including graded assignments. Upon completing the course, your electronic Certificate will be added to your Accomplishments page - from there, you can print your Certificate or add it to your LinkedIn profile.
Is financial aid available?
Yes. In select learning programs, you can apply for financial aid or a scholarship if you can’t afford the enrollment fee. If fin aid or scholarship is available for your learning program selection, you’ll find a link to apply on the description page.