Course Description
Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) are essential aspects of network security. Leading IDS and IPS products such as Snort and Suricata can help you detect malicious activity in your network, but to use them effectively, it is important to know how to install, update, and customize them. There are also network traffic monitoring tools, such as tcpdump and Wireshark, that can help you actively gather and analyze packets from your network connection for malicious behavior. By learning about these specific tools, the fundamentals of Defense in Depth, and the OSI and TCP/IP models, you will be well on your way to begin working in the cybersecurity field.
In this course on Intrusion and Prevention basics, you will learn basic network defense and how to install and configure an IDS and IPS. We will explore Defense-in-Depth, IDS and IPS Technologies, and other networking tools such as Wireshark and tcpdump. By the end of this course, you will be able to better mitigate and block network security threats.
What You'll Learn
- Defend networks by applying the principles of Defense-in-Depth and basic network architecture
- Install and configure IDS and IPS solutions such as Snort and Suricata
- Configure intrusion alerting along with block and allow listing
- Capture and analyze network packets using tools like Wireshark and tcpdump
- Apply networking fundamentals including the TCP/IP and OSI models
- Explore additional defenses such as honeypots, log offloading, PfSense, and CISA Einstein
Key Takeaways
- Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) are essential aspects of network security.
- Leading IDS and IPS products such as Snort and Suricata can help detect malicious activity, but must be properly installed, updated, and customized to be effective.
- Network traffic monitoring tools such as tcpdump and Wireshark help actively gather and analyze packets for malicious behavior.
- Learning these tools alongside the fundamentals of Defense in Depth and the OSI and TCP/IP models prepares you to begin working in the cybersecurity field.
- By the end of the course you will be able to better mitigate and block network security threats.
Frequently Asked Questions
What will I learn in this course?
You will learn basic network defense and how to install and configure an IDS and IPS, exploring Defense-in-Depth, IDS and IPS technologies, and networking tools such as Wireshark and tcpdump.
Which intrusion detection and prevention tools does this course cover?
The course covers leading IDS and IPS products such as Snort and Suricata, including their configuration and alerting, as well as traffic monitoring tools like tcpdump and Wireshark.
Who is this course for?
It is for those wanting to begin working in the cybersecurity field, teaching the fundamentals of Defense in Depth, the OSI and TCP/IP models, and core IDS/IPS and packet capture tools.
What skills will I gain from this course?
You will gain skills in Computer Network Defense, Intrusion Detection Systems, Intrusion Detection and Prevention, Intrusion Prevention Systems, Network Intrusion Detection and Prevention, and Network Security.
What additional topics are included beyond IDS and IPS configuration?
The course also covers PfSense, Snort and Suricata alerting, block and allow listing, offloading logs, honeypots, CISA Einstein, and the TCP/IP and OSI models.










