Learn about the tools and techniques used for analyzing traffic passing over the network. This learning path covers identification and analysis of benign and malicious traffic, examples and case studies of extracting intelligence from traffic data, considerations when building a network monitoring program, and techniques for collecting and analyzing traffic data.
Start out on this course by taking a look at what network traffic analysis is and some of its major applications. This introductory module describes network traffic analysis and discusses its applications for monitoring the functionality of networked systems and performing incident response investigations.
Das ist alles enthalten
10 Videos
Infos zu Modulinhalt anzeigen
10 Videos•Insgesamt 46 Minuten
Welcome to network traffic analysis•5 Minuten
What is network traffic analysis?•6 Minuten
Functionality monitoring•8 Minuten
Incident response life cycle•4 Minuten
Preparation•4 Minuten
Detection and analysis•4 Minuten
Containment•5 Minuten
Eradication•4 Minuten
Recovery•1 Minute
Post-incident response•5 Minuten
Fundamentals of networking
Modul 2•1 Stunde abzuschließen
Moduldetails
In order to identify anomalous or malicious traffic in a network, it’s necessary to first understand what’s normal. This module discusses the fundamentals of networking, including the OSI model, the differences between TCP, UDP and ICMP and their intended uses, and the purposes of common high-level protocols like HTTP and SMTP.
Das ist alles enthalten
18 Videos
Infos zu Modulinhalt anzeigen
18 Videos•Insgesamt 56 Minuten
Fundamentals of networking•3 Minuten
The OSI Model•5 Minuten
Basic network protocols•4 Minuten
Internet protocol (IP)•4 Minuten
Transmission control protocol (TCP)•6 Minuten
User datagram protocol (UDP)•3 Minuten
Internet control message protocol (ICMP)•5 Minuten
Wireshark is probably the most commonly used tool for network traffic analysis and will be used throughout this learning path. This module introduces some of the useful features of Wireshark and shows what the protocols discussed in the previous course look like in practice and how the various layers work together to make networking possible.
Das ist alles enthalten
14 Videos
Infos zu Modulinhalt anzeigen
14 Videos•Insgesamt 105 Minuten
Introduction to Wireshark•7 Minuten
Features of Wireshark•26 Minuten
IP demo•12 Minuten
TCP demo•8 Minuten
UDP demo•5 Minuten
ICMP demo•4 Minuten
ARP demo•6 Minuten
DNS demo•9 Minuten
FTP demo•5 Minuten
HTTP demo•7 Minuten
IRC demo•4 Minuten
SMTP demo•5 Minuten
SSH demo•3 Minuten
TFTP demo•4 Minuten
Alternatives to Wireshark
Modul 4•1 Stunde abzuschließen
Moduldetails
Wireshark is probably the most popular tool for network traffic analysis. However, it is not the only one available. This module provides an introduction to some alternatives to Wireshark, covering some of the most useful and unique features of Terminal Shark (Wireshark’s command-line equivalent), CloudShark and NetworkMiner.
Das ist alles enthalten
3 Videos
Infos zu Modulinhalt anzeigen
3 Videos•Insgesamt 32 Minuten
Network mapper demo•17 Minuten
Terminal shark demo•9 Minuten
CloudShark Demo•5 Minuten
Network traffic intelligence collection
Modul 5•2 Stunden abzuschließen
Moduldetails
A common use of network traffic analysis is for performing incident response activities. The purpose of these actions is to extract useful intelligence from network captures that can help to inform the rest of the investigation. This module demonstrates how to extract certain types of useful data from a network capture file.
Das ist alles enthalten
8 Videos
Infos zu Modulinhalt anzeigen
8 Videos•Insgesamt 104 Minuten
Intelligence collection•6 Minuten
Network mapping demo•12 Minuten
Content deobfuscation demo•15 Minuten
Credential capture demo•10 Minuten
TLS decryption demo•17 Minuten
Web proxy demo•17 Minuten
Online tools demo 1•21 Minuten
Online tools demo 2•7 Minuten
Common network threats
Modul 6•1 Stunde abzuschließen
Moduldetails
An organization can be attacked over the network in a variety of different ways. However, some methods are more common than others. In this module, you will see what scanning, data exfiltration, DDoS attacks and attacks against IoT devices look like in a network capture in a series of demonstrations.
Das ist alles enthalten
4 Videos
Infos zu Modulinhalt anzeigen
4 Videos•Insgesamt 76 Minuten
Scanning demo•22 Minuten
Data exfiltration demo•18 Minuten
DDOS attack demo•18 Minuten
IoT attack demo•18 Minuten
Traffic analysis case studies
Modul 7•1 Stunde abzuschließen
Moduldetails
Different types of incident response investigations lend themselves to network-based analysis to different degrees. This module consists of a series of demonstrations where analysis of network traffic is used to infer information about different types of malware, including remote access Trojans (RATs), fileless malware, network worms and multi-stage infections.
Das ist alles enthalten
4 Videos
Infos zu Modulinhalt anzeigen
4 Videos•Insgesamt 66 Minuten
RAT demo•13 Minuten
Fileless case study•16 Minuten
Worm demo•14 Minuten
Multistage malware demo•23 Minuten
Data collection for network traffic analysis
Modul 8•1 Stunde abzuschließen
Moduldetails
In order to investigate a network traffic capture, it is first necessary to capture it. This module discusses methods and considerations for data collection of network traffic. Topics include considerations for deployment of monitoring appliances and the use of virtualization and deception for data collection.
Das ist alles enthalten
4 Videos
Infos zu Modulinhalt anzeigen
4 Videos•Insgesamt 60 Minuten
Data collection•5 Minuten
Monitoring appliance deployment•18 Minuten
Virtualization for network traffic analysis•13 Minuten
Deceptive technologies•24 Minuten
Data analysis for network traffic analysis
Modul 9•2 Stunden abzuschließen
Moduldetails
Having access to network traffic data is of very limited value without the ability to analyze it. In this module, you will learn about connection-based analysis, statistical analysis and event-based analysis, their relative pros and cons for different monitoring situations, and tools and techniques for performing them effectively.
Das ist alles enthalten
9 Videos
Infos zu Modulinhalt anzeigen
9 Videos•Insgesamt 144 Minuten
Data analysis•5 Minuten
Tools for data analysis•11 Minuten
Scapy demo•21 Minuten
Data analysis techniques•4 Minuten
Connection analysis•9 Minuten
Statistical analysis•22 Minuten
Event-based analysis•42 Minuten
YARA demo•18 Minuten
Snort demo•12 Minuten
Network traffic analysis for incident response project
Modul 10•3 Stunden abzuschließen
Moduldetails
In this project, you will need to apply your knowledge and use common network traffic analysis tools to solve multiple challenges. Each challenge involves examining a network traffic capture file containing evidence of malicious activity, such as malware infection, data exfiltration and C2 (command-and-control) communications. You’ll need to find leaked credentials, analyze an attempted DDoS attack, extract files from captures and even more.
Infosec believes knowledge is power when fighting cybercrime. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and privacy training to stay cyber-safe at work and home. Learn more at infosecinstitute.com.
When will I have access to the lectures and assignments?
To access the course materials, assignments and to earn a Certificate, you will need to purchase the Certificate experience when you enroll in a course. You can try a Free Trial instead, or apply for Financial Aid. The course may offer 'Full Course, No Certificate' instead. This option lets you see all course materials, submit required assessments, and get a final grade. This also means that you will not be able to purchase a Certificate experience.
What will I get if I purchase the Certificate?
When you purchase a Certificate you get access to all course materials, including graded assignments. Upon completing the course, your electronic Certificate will be added to your Accomplishments page - from there, you can print your Certificate or add it to your LinkedIn profile.
Is financial aid available?
Yes. In select learning programs, you can apply for financial aid or a scholarship if you can’t afford the enrollment fee. If fin aid or scholarship is available for your learning program selection, you’ll find a link to apply on the description page.