Learn about the tools and techniques used for analyzing traffic passing over the network. This learning path covers identification and analysis of benign and malicious traffic, examples and case studies of extracting intelligence from traffic data, considerations when building a network monitoring program, and techniques for collecting and analyzing traffic data.
Start out on this course by taking a look at what network traffic analysis is and some of its major applications. This introductory module describes network traffic analysis and discusses its applications for monitoring the functionality of networked systems and performing incident response investigations.
Inclus
10 vidéos
Afficher les informations sur le contenu du module
10 vidéos•Total 46 minutes
Welcome to network traffic analysis•5 minutes
What is network traffic analysis?•6 minutes
Functionality monitoring•8 minutes
Incident response life cycle•4 minutes
Preparation•4 minutes
Detection and analysis•4 minutes
Containment•5 minutes
Eradication•4 minutes
Recovery•1 minute
Post-incident response•5 minutes
Fundamentals of networking
Module 2•1 heure à terminer
Détails du module
In order to identify anomalous or malicious traffic in a network, it’s necessary to first understand what’s normal. This module discusses the fundamentals of networking, including the OSI model, the differences between TCP, UDP and ICMP and their intended uses, and the purposes of common high-level protocols like HTTP and SMTP.
Inclus
18 vidéos
Afficher les informations sur le contenu du module
18 vidéos•Total 56 minutes
Fundamentals of networking•3 minutes
The OSI Model•5 minutes
Basic network protocols•4 minutes
Internet protocol (IP)•4 minutes
Transmission control protocol (TCP)•6 minutes
User datagram protocol (UDP)•3 minutes
Internet control message protocol (ICMP)•5 minutes
Wireshark is probably the most commonly used tool for network traffic analysis and will be used throughout this learning path. This module introduces some of the useful features of Wireshark and shows what the protocols discussed in the previous course look like in practice and how the various layers work together to make networking possible.
Inclus
14 vidéos
Afficher les informations sur le contenu du module
14 vidéos•Total 105 minutes
Introduction to Wireshark•7 minutes
Features of Wireshark•26 minutes
IP demo•12 minutes
TCP demo•8 minutes
UDP demo•5 minutes
ICMP demo•4 minutes
ARP demo•6 minutes
DNS demo•9 minutes
FTP demo•5 minutes
HTTP demo•7 minutes
IRC demo•4 minutes
SMTP demo•5 minutes
SSH demo•3 minutes
TFTP demo•4 minutes
Alternatives to Wireshark
Module 4•1 heure à terminer
Détails du module
Wireshark is probably the most popular tool for network traffic analysis. However, it is not the only one available. This module provides an introduction to some alternatives to Wireshark, covering some of the most useful and unique features of Terminal Shark (Wireshark’s command-line equivalent), CloudShark and NetworkMiner.
Inclus
3 vidéos
Afficher les informations sur le contenu du module
3 vidéos•Total 32 minutes
Network mapper demo•17 minutes
Terminal shark demo•9 minutes
CloudShark Demo•5 minutes
Network traffic intelligence collection
Module 5•2 heures à terminer
Détails du module
A common use of network traffic analysis is for performing incident response activities. The purpose of these actions is to extract useful intelligence from network captures that can help to inform the rest of the investigation. This module demonstrates how to extract certain types of useful data from a network capture file.
Inclus
8 vidéos
Afficher les informations sur le contenu du module
8 vidéos•Total 104 minutes
Intelligence collection•6 minutes
Network mapping demo•12 minutes
Content deobfuscation demo•15 minutes
Credential capture demo•10 minutes
TLS decryption demo•17 minutes
Web proxy demo•17 minutes
Online tools demo 1•21 minutes
Online tools demo 2•7 minutes
Common network threats
Module 6•1 heure à terminer
Détails du module
An organization can be attacked over the network in a variety of different ways. However, some methods are more common than others. In this module, you will see what scanning, data exfiltration, DDoS attacks and attacks against IoT devices look like in a network capture in a series of demonstrations.
Inclus
4 vidéos
Afficher les informations sur le contenu du module
4 vidéos•Total 76 minutes
Scanning demo•22 minutes
Data exfiltration demo•18 minutes
DDOS attack demo•18 minutes
IoT attack demo•18 minutes
Traffic analysis case studies
Module 7•1 heure à terminer
Détails du module
Different types of incident response investigations lend themselves to network-based analysis to different degrees. This module consists of a series of demonstrations where analysis of network traffic is used to infer information about different types of malware, including remote access Trojans (RATs), fileless malware, network worms and multi-stage infections.
Inclus
4 vidéos
Afficher les informations sur le contenu du module
4 vidéos•Total 66 minutes
RAT demo•13 minutes
Fileless case study•16 minutes
Worm demo•14 minutes
Multistage malware demo•23 minutes
Data collection for network traffic analysis
Module 8•1 heure à terminer
Détails du module
In order to investigate a network traffic capture, it is first necessary to capture it. This module discusses methods and considerations for data collection of network traffic. Topics include considerations for deployment of monitoring appliances and the use of virtualization and deception for data collection.
Inclus
4 vidéos
Afficher les informations sur le contenu du module
4 vidéos•Total 60 minutes
Data collection•5 minutes
Monitoring appliance deployment•18 minutes
Virtualization for network traffic analysis•13 minutes
Deceptive technologies•24 minutes
Data analysis for network traffic analysis
Module 9•2 heures à terminer
Détails du module
Having access to network traffic data is of very limited value without the ability to analyze it. In this module, you will learn about connection-based analysis, statistical analysis and event-based analysis, their relative pros and cons for different monitoring situations, and tools and techniques for performing them effectively.
Inclus
9 vidéos
Afficher les informations sur le contenu du module
9 vidéos•Total 144 minutes
Data analysis•5 minutes
Tools for data analysis•11 minutes
Scapy demo•21 minutes
Data analysis techniques•4 minutes
Connection analysis•9 minutes
Statistical analysis•22 minutes
Event-based analysis•42 minutes
YARA demo•18 minutes
Snort demo•12 minutes
Network traffic analysis for incident response project
Module 10•3 heures à terminer
Détails du module
In this project, you will need to apply your knowledge and use common network traffic analysis tools to solve multiple challenges. Each challenge involves examining a network traffic capture file containing evidence of malicious activity, such as malware infection, data exfiltration and C2 (command-and-control) communications. You’ll need to find leaked credentials, analyze an attempted DDoS attack, extract files from captures and even more.
Inclus
2 vidéos2 lectures1 devoir
Afficher les informations sur le contenu du module
Infosec believes knowledge is power when fighting cybercrime. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and privacy training to stay cyber-safe at work and home. Learn more at infosecinstitute.com.
Pour quelles raisons les étudiants sur Coursera nous choisissent-ils pour leur carrière ?
Felipe M.
Étudiant(e) depuis 2018
’Pouvoir suivre des cours à mon rythme à été une expérience extraordinaire. Je peux apprendre chaque fois que mon emploi du temps me le permet et en fonction de mon humeur.’
Jennifer J.
Étudiant(e) depuis 2020
’J'ai directement appliqué les concepts et les compétences que j'ai appris de mes cours à un nouveau projet passionnant au travail.’
Larry W.
Étudiant(e) depuis 2021
’Lorsque j'ai besoin de cours sur des sujets que mon université ne propose pas, Coursera est l'un des meilleurs endroits où se rendre.’
Chaitanya A.
’Apprendre, ce n'est pas seulement s'améliorer dans son travail : c'est bien plus que cela. Coursera me permet d'apprendre sans limites.’
When will I have access to the lectures and assignments?
To access the course materials, assignments and to earn a Certificate, you will need to purchase the Certificate experience when you enroll in a course. You can try a Free Trial instead, or apply for Financial Aid. The course may offer 'Full Course, No Certificate' instead. This option lets you see all course materials, submit required assessments, and get a final grade. This also means that you will not be able to purchase a Certificate experience.
What will I get if I purchase the Certificate?
When you purchase a Certificate you get access to all course materials, including graded assignments. Upon completing the course, your electronic Certificate will be added to your Accomplishments page - from there, you can print your Certificate or add it to your LinkedIn profile.
Is financial aid available?
Yes. In select learning programs, you can apply for financial aid or a scholarship if you can’t afford the enrollment fee. If fin aid or scholarship is available for your learning program selection, you’ll find a link to apply on the description page.