Technology-related risks have become a major concern in our society. Organisations are increasingly reliant on technology to survive in the midst of digital transformation. In this context, it is essential to put in place robust security measures to tackle increasingly sophisticated threats. The Course in Cybersecurity Incident Management and Malware Analysis It focuses on developing the knowledge and skills required for professional practice in the management of security incidents.
Cybersecurity Incident Management and Malware Analysis
Introduction
Objectives
- To learn about the intrusion detection and prevention systems (IDS/IPS).
- Learn how to to implement and roll out the IDS/IPS systems.
- Recognise the Malware detection and containment systems.
- To understand the security incident response procedure.
- Understanding the process for reporting and managing intrusion attempts.
- Learn how to carry out a computer forensics.
Table of Contents
TEACHING UNIT 1. INTRUSION DETECTION AND PREVENTION SYSTEMS (IDS/IPS)
General concepts of incident management, intrusion detection and prevention
Identification and characterisation of system performance data
The most common IDS architectures
List of the different types of IDS/IPS by location and functionality
Security criteria for determining the location of IDS/IPS systems
TEACHING UNIT 2. IMPLEMENTATION AND DEPLOYMENT OF IDS/IPS SYSTEMS
Preliminary analysis
Defining policies to block intrusion attempts in IDS/IPS systems
Analysis of events recorded by the IDS/IPS
List of IDS/IPS audit logs
Establishing the required levels of updating, monitoring and testing for the IDS/IPS
TEACHING UNIT 3. MALWARE CONTROL
Malware detection and containment systems
Malware control tools
Security criteria for configuring malware protection tools
Identifying the requirements and techniques for updating malware protection tools
List of audit logs for malware protection tools
Setting up monitoring and testing of malware protection tools
Malware analysis using disassemblers and controlled execution environments
TEACHING UNIT 4. RESPONSE TO SECURITY INCIDENTS
Procedure for collecting information relating to security incidents
An overview of the various techniques and tools used for the analysis and correlation of security information and events
Intrusion verification process
Nature and functions of national and international CERT-type incident management bodies
TEACHING UNIT 5. THE PROCESS OF NOTIFICATION AND MANAGEMENT OF INTRUSION ATTEMPTS
Definition of responsibilities
Classification of incidents arising from intrusion attempts
Establishment of the incident detection process and incident logging tools
Determining the required level of intervention based on the foreseeable impact
Establishment of the system resolution and recovery process
Procedure for reporting the incident to third parties
TEACHING UNIT 6. COMPUTER FORENSICS
General concepts and objectives of forensic analysis
An Explanation of Lockard’s Principle
Guide to the collection of electronic evidence
Guide to the analysis of electronic evidence collected
Guide to selecting forensic analysis tools