
SSFIPS Securing Cisco Networks with Sourcefire Intrusion Prevention System Study Guide
Description
Alles über E-Books | Antworten auf Fragen rund um E-Books, Kopierschutz und Dateiformate finden Sie in unserem Info- & Hilfebereich.
More details
Other editions
Additional editions

Persons
Content
- Intro
- SSFIPS: Securing Cisco Networks with Sourcefire Intrusion Prevention System
- Acknowledgments
- About the Authors
- Contents at a Glance
- Contents
- Introduction
- Assessment Test
- Chapter 1 Getting Started with FireSIGHT
- Industry Terminology
- Cisco Terminology
- FirePOWER and FireSIGHT
- Out with the Old.
- Appliance Models
- Hardware vs. Virtual Devices
- Device Models
- Defense Center Models
- FireSIGHT Licensing
- License Dependencies
- Network Design
- Inline IPS
- Passive IPS
- Router, Switch, and Firewall
- Policies
- The User Interface
- Initial Appliance Setup
- Setting the Management IP
- Initial Login
- Summary
- Hands-on Lab
- Review Questions
- Chapter 2 Object Management
- What Are Objects?
- Getting Started
- Network Objects
- Individual Network Objects
- Network Object Groups
- Security Intelligence
- Blacklist and Whitelist
- Sourcefire Intelligence Feed
- Custom Security Intelligence Objects
- Port Objects
- VLAN Tag
- URL Objects and Site Matching
- Application Filters
- Variable Sets
- File Lists
- Security Zones
- Geolocation
- Summary
- Hands-on Lab
- Exam Essentials
- Review Questions
- Chapter 3 IPS Policy Management
- IPS Policies
- Default Policies
- Policy Layers
- Creating a Policy
- Policy Editor
- Summary
- Hands-on Labs
- Hands-on Lab 3.1: Creating an IPS Policy
- Hands-on Lab 3.2: Viewing Connection Events
- Exam Essentials
- Review Questions
- Chapter 4 Access Control Policy
- Getting Started with Access Control Policies
- Security Intelligence Lists
- Blacklists, Whitelists, and Alerts
- Security Intelligence Page Specifics
- Configuring Security Intelligence
- Access Control Rules
- Access Control UI Elements
- Rule Categories
- A Simple Policy
- Saving and Applying
- Summary
- Hands-on Lab
- Exam Essentials
- Review Questions
- Chapter 5 FireSIGHT Technologies
- FireSIGHT Technologies
- Network Discovery Policy
- Discovery Information
- User Information
- Host Attributes
- Summary
- Hands-on Labs
- Hands-on Lab 5.1: Configuring a Discovery Policy
- Hands-on Lab 5.2: Viewing Connection Events
- Hands-on Lab 5.3: Viewing the Network Map
- Hands-on Lab 5.4: Creating Host Attributes
- Exam Essentials
- Review Questions
- Chapter 6 Intrusion Event Analysis
- Intrusion Analysis Principles
- False Positives
- False Negatives
- Possible Outcomes
- The Goal of Analysis
- The Dashboard and Context Explorer
- Intrusion Events
- An Introduction to Workflows
- The Time Window
- The Analysis Screen
- The Caveat
- Rule Comment
- Summary
- Hands-on Lab
- Exam Essentials
- Review Questions
- Chapter 7 Network-Based Malware Detection
- AMP Architecture
- SHA-256
- Spero Analysis
- Dynamic Analysis
- Retrospective Events
- Communications Architecture
- File Dispositions
- File Disposition Caching
- File Policy
- Advanced Settings
- File Rules
- File Types and Categories
- File and Malware Event Analysis
- Malware Events
- File Events
- Captured Files
- Network File Trajectory
- Context Explorer
- Summary
- Hands-on Lab
- Exam Essentials
- Review Questions
- Chapter 8 System Settings
- User Preferences
- Event Preferences
- File Preferences
- Default Time Windows
- Default Workflows
- System Configuration
- System Policy
- Health
- Health Monitor
- Health Policy
- Health Events
- Blacklist
- Health Monitor Alerts
- Summary
- Hands-on Lab
- Hands-on Lab 8.1: Creating a New System Policy
- Hands-on Lab 8.2: Viewing Health Information
- Exam Essentials
- Review Questions
- Chapter 9 Account Management
- User Account Management
- Internal versus External User Authentication
- User Privileges
- Predefined User Roles
- Creating New User Accounts
- Managing User Role Escalation
- Configuring External Authentication
- Creating Authentication Objects
- Summary
- Hands-on Lab
- Hands-on Lab 9.1: Configuring a User in the Local Database
- Hands-on Lab 9.2: Configuring Permission Escalation
- Exam Essentials
- Review Questions
- Chapter 10 Device Management
- Device Management
- Configuring the Device on the Defense Center
- NAT Configuration
- Virtual Private Networks
- Point-to-Point VPN
- Star VPN
- Mesh VPN
- Advanced Options
- Summary
- Hands-on Labs
- Hands-on Lab 10.1: Creating a Device Group
- Hands-on Lab 10.2: Renaming the Device
- Hands-on Lab 10.3: Modifying the Name of the Inline Interface Set
- Exam Essentials
- Review Questions
- Chapter 11 Correlation Policy
- Correlation Overview
- Correlation Rules, Responses, and Policies
- Correlation Rules
- Rule Options
- Responses
- Correlation Policy
- White Lists
- Traffic Profiles
- Summary
- Hands-on Lab
- Exam Essentials
- Review Questions
- Chapter 12 Advanced IPS Policy Settings
- Advanced Settings
- Preprocessor Alerting
- Application Layer Preprocessors
- SCADA Preprocessors
- Transport/Network Layer Preprocessors
- Specific Threat Detection
- Detection Enhancement
- Intrusion Rule Thresholds
- Performance Settings
- External Responses
- Summary
- Hands-on Lab
- Hands-on Lab 12.1: Modifying the HTTP Configuration Preprocessor
- Hands-on Lab 12.2: Enabling Inline Normalization
- Hands-on Lab 12.3: Demonstrating the Validation of Preprocessor Settings on Policy Commit
- Exam Essentials
- Review Questions
- Chapter 13 Creating Snort Rules
- Overview of Snort Rules
- Rule Headers
- The Rule Body
- Writing Rules
- Using the System GUI to Build a Rule
- Summary
- Exam Essentials
- Review Questions
- Chapter 14 FireSIGHT v5.4 Facts and Features
- Branding
- Simplified IPS Policy
- Network Analysis Policy
- Why Network Analysis?
- Access Control Policy
- General Settings
- Network Analysis and Intrusion Policies
- Files and Malware Settings
- Transport/Network Layer Preprocessor Settings
- Detection Enhancement Settings
- Performance/Latency Settings
- SSL Inspection
- SSL Objects
- New Rule Keywords
- File_type
- Protected_content
- Platform Enhancements
- International Enhancements
- Minor Changes
- Summary
- Appendix Answers to Review Questions
- Index
- Advert
- EULA
System requirements
File format: PDF
Copy-Protection: Adobe-DRM (Digital Rights Management)
System requirements:
- Computer (Windows; MacOS X; Linux): Install the free reader Adobe Digital Editions prior to download (see eBook Help).
- Tablet/smartphone (Android; iOS): Install the free app Adobe Digital Editions or the app PocketBook before downloading (see eBook Help).
- E-reader: Bookeen, Kobo, Pocketbook, Sony, Tolino and many more (only limited: Kindle).
The file format PDF always displays a book page identically on any hardware. This makes PDF suitable for complex layouts such as those used in textbooks and reference books (images, tables, columns, footnotes). Unfortunately, on the small screens of e-readers or smartphones, PDFs are rather annoying, requiring too much scrolling.
This eBook uses Adobe-DRM, a „hard” copy protection. If the necessary requirements are not met, unfortunately you will not be able to open the eBook. You will therefore need to prepare your reading hardware before downloading.
Please note: We strongly recommend that you authorise using your personal Adobe ID after installation of any reading software.
For more information, see our eBook Help page.