When you enroll in this course, you'll also be enrolled in this Specialization.
Learn new concepts from industry experts
Gain a foundational understanding of a subject or tool
Develop job-relevant skills with hands-on projects
Earn a shareable career certificate
There are 7 modules in this course
The course "Advanced Network Analysis and Incident Response" equips learners with critical skills for effectively managing and responding to cyber threats. Through a blend of theoretical concepts and hands-on practice, participants will delve into advanced network situational awareness, network packet analysis, and incident response strategies aligned with organizational security policies.
What sets this course apart is its comprehensive approach to both the technical and strategic aspects of cybersecurity. Learners will engage with both government-off-the-shelf (GOTS) and commercial-off-the-shelf (COTS) tools, gaining practical experience in analyzing network traffic and implementing effective incident response protocols. The curriculum also incorporates real-world scenarios through tabletop exercises and emphasizes the application of the NIST Cybersecurity Framework and the SANS Incident Response Cycle.
By completing this course, learners will enhance their ability to detect, analyze, and respond to incidents effectively, preparing them for challenges in the dynamic field of cybersecurity. Whether you're aiming to advance your career or reinforce your skills, this course provides the knowledge and confidence needed to excel in network analysis and incident response.
This course provides a comprehensive exploration of network analysis and incident response strategies, focusing on the differentiation between Network Situational Awareness and Intrusion Detection Systems. Students will learn to apply anomaly detection techniques and utilize various network packet analysis tools. The curriculum includes developing alarm systems through Graph Analysis and interpreting key performance metrics like ROC analysis. Emphasis is placed on evaluating incident response mechanisms and understanding the implications of Artificial Intelligence in cybersecurity. Participants will also gain practical skills in applying the NIST Cybersecurity Framework and the SANS Incident Response Cycle to real-world scenarios.
Differentiating Network Situational Awareness from NIDS•15 minutes
Applying Anomaly Detection to Large-Scale Network Analysis•15 minutes
Network Analysis•60 minutes
Network Packet Analysis
Module 3•11 hours to complete
Module details
This module introduces foundational concepts in Network Packet Analysis, providing insights into both government-off-the-shelf (GOTS) and commercial-off-the-shelf (COTS) tools used for analyzing network traffic.
What's included
4 readings3 assignments6 plugins
Show info about module content
4 readings•Total 480 minutes
Reading References•180 minutes
Reading References•180 minutes
Self-Reflective Reading: Network Forensic Investigation and Packet Analysis•60 minutes
Self-Reflective Reading: Challenges in Network Packet Collection and Analysis•60 minutes
3 assignments•Total 90 minutes
Introduction to Network Packet Analysis and Tools•15 minutes
Data Collection Techniques and the Role of Wireshark•15 minutes
Network Packet Analysis•60 minutes
6 plugins•Total 112 minutes
Introduction to Packet Analysis- Part 2: Network Protocols•5 minutes
Introduction to Packet Analysis- Part 3: UDP Packets•15 minutes
Introduction to Packet Analysis- Part 4: TCP Protocols•13 minutes
Introduction to Packet Analysis- Part 8 Capturing Network Traffic with TCPDump•14 minutes
Introduction to Packet Analysis- Part 8 Packet Analysis with Wireshark (Part 1)•30 minutes
Introduction to Packet Analysis- Part 8 Packet Analysis with Wireshark (Part 2)•35 minutes
ROC Analysis
Module 4•7 hours to complete
Module details
This module will guide students through the process of conducting ROC analysis on IDS data and interpreting various graphical representations, including event graphs, precision-recall (P-R) graphs, and thresholds.
What's included
6 videos3 readings3 assignments
Show info about module content
6 videos•Total 70 minutes
Introduction•6 minutes
Overview of ROC Analysis•11 minutes
Event Graphs and Thresholds•18 minutes
Multiple Confusion Matrices Based on IDS Configuration•23 minutes
Error Rates•6 minutes
ROC and P-R Graphs•6 minutes
3 readings•Total 280 minutes
Reading References•120 minutes
Reading References•120 minutes
Self-Reflective Reading: Deep Packet Inspection and Net Neutrality•40 minutes
3 assignments•Total 90 minutes
ROC Analysis and IDS Performance Metrics•15 minutes
Challenges and Advanced Concepts in IDS Evaluation•15 minutes
ROC Analysis•60 minutes
Response
Module 5•7 hours to complete
Module details
This module focuses on the importance of aligning response strategies with organizational security policies, while also evaluating the risks associated with automated responses.
What's included
5 videos4 readings3 assignments
Show info about module content
5 videos•Total 79 minutes
Introduction•3 minutes
Response Requirements•20 minutes
Response Types•17 minutes
IPS•20 minutes
Risks and Cautions for IPS•19 minutes
4 readings•Total 260 minutes
Reading References•90 minutes
Reading References•90 minutes
Self-Reflective Reading: Balancing Technical and Non-Technical Responses to Intrusions•40 minutes
Self-Reflective Reading: Responses to IDS Alerts and Network Threat Management•40 minutes
3 assignments•Total 90 minutes
Understanding IDS Response Mechanisms•15 minutes
Implementing Custom Firewall Logic•15 minutes
Response•60 minutes
Tabletop Exercise
Module 6•1 hour to complete
Module details
This course explores the complexities of intrusion detection and response in constrained environments.
What's included
1 video2 assignments
Show info about module content
1 video•Total 5 minutes
Introduction•5 minutes
2 assignments•Total 75 minutes
Understanding IDS Response Mechanisms•15 minutes
Tabletop Exercise•60 minutes
Cyber Security Incident Response Management
Module 7•9 hours to complete
Module details
This course delves into the application of the NIST Cybersecurity Framework (CSF) 2.0 and the SANS Incident Response Cycle in managing cyber incidents.
What's included
6 readings3 assignments4 plugins
Show info about module content
6 readings•Total 420 minutes
Reading References•120 minutes
Reading References•120 minutes
Cybersecurity and AI: The Challenges and Opportunities•20 minutes
Incident Response Principles•60 minutes
Self-Reflective Reading: The Role of AI in Cybersecurity•40 minutes
Self-Reflective Reading: Case Study Analysis and Cyber Incident Response•60 minutes
3 assignments•Total 90 minutes
Applying the NIST CSF 2.0 Core Functions and SANS Incident Response Cycle•15 minutes
Artificial Intelligence in Cybersecurity Incident Response•15 minutes
The mission of The Johns Hopkins University is to educate its students and cultivate their capacity for life-long learning, to foster independent and original research, and to bring the benefits of discovery to the world.
When will I have access to the lectures and assignments?
To access the course materials, assignments and to earn a Certificate, you will need to purchase the Certificate experience when you enroll in a course. You can try a Free Trial instead, or apply for Financial Aid. The course may offer 'Full Course, No Certificate' instead. This option lets you see all course materials, submit required assessments, and get a final grade. This also means that you will not be able to purchase a Certificate experience.
What will I get if I subscribe to this Specialization?
When you enroll in the course, you get access to all of the courses in the Specialization, and you earn a certificate when you complete the work. Your electronic Certificate will be added to your Accomplishments page - from there, you can print your Certificate or add it to your LinkedIn profile.
Is financial aid available?
Yes. In select learning programs, you can apply for financial aid or a scholarship if you can’t afford the enrollment fee. If fin aid or scholarship is available for your learning program selection, you’ll find a link to apply on the description page.