Syllabus
Techniques for Network Protection: Firewalls, packet filter and stateful firewalls, application aware firewalls, personal firewalls, Proxies, NAT, Intrusion Detection System-Snort, Signature and Anomaly based detection- Evasion and poisoning attacks, Honeypots and Honeynets, Network Log management- syslog or SPLUNK; RBAC, Network reconnaissance-Nmap and vulnerability audits-openVAS; DNS-Dig tool: DNS based attacks, Phishing, DNSSEC-DS and NSEC records; Network based malware attacks: Remote access Trojan-Poison Ivy and Domain name generation algorithm based Botnets; LAN attacks: ARP Cache poisoning, MAC flooding, Man in the middle attacks, Port Stealing, DHCP attacks, VLAN hopping, Password Cracking-John the Ripper ; Secure Network Communication: SCP, SSH, SSL3.0, TLS 1.2, STARTTLS, IPSec, VPN and Secure HTTP; Understanding the dark web, TOR traffic, Attacks on SSL/TLS: SSL stripping, Drown and Poodle attack; Encrypting and Signing Emails: PGP- GPG/openPGP, DKIM and SPF; Single Sign On (SSO)-OAUTH and OPENID; Network packet creation and Manipulation using scapy and dpkt libraries; SDN Security