Linux Administration 3

Course Description

This two-day class is designed for system administrators responsible for keeping their systems, data and networks secure. Modern computing and communication have made the jobs of such administrators particularly challenging. On the other hand there have been several innovations in tools and techniques that allow administrators to successfully ward off attacks of all nature. During this class we will cover various types of security issues, and work on collaborative labs identifying possible exploits and their fixes.

 

Overview

This class is a unique hands-on course designed to give administrators practical experience with obscure and difficult security tasks in a supportive learning environment. Theoretical knowledge is given before and after the class so lectures can focus on the important issues that administrators will face while securing their network, designing reflexive defenses, protecting users, data and services, providing incident response and performing rudimentary forensics.

 

This class is a fast-paced course and assumes basic Linux system & network administration expertise. There is substantial lecture work with continuous hands-on training.

 

Outline
Introduction to Linux Security
  • Review of Pre-Read material
  • System orientation
Security Policies and Practices
  • Top Security Mistakes
  • Risks Assessment
  • SSH, SSL, Configuring OpenSSH
  • Tripwire & AIDE - Change control
  • Authentication: Kerberos, LILO password
Locking down access to a system
  • User Access, Program Access, Network Access
  • Scanning & protecting log files
  • Security related kernel extensions
Firewalls
  • Types of firewall architectures
  • Implementation and administration of firewalls
  • Select firewall reviews
  • VPN on the firewall
Internet Network Security Strategies
  • Phases of Internet adoption in an organization
  • Threats & Preventions based on different phases
  • Common attack methodologies
  • Firewall, Intrusion Detection Systems, Sniffers, Port scanners
Exploits and Defenses
  • Specific attacks & defenses
  • Malicious code, Root kits, Buffer overflows, Nessus
  • Security Auditor's Research Assistant (SARA)
Cryptography
  • Fundamentals of cryptography
  • Cryptography algorithms
  • IPSEC and VPN
  • Configuring FreeS/WAN
Application specific security issues
  • Evaluating applications for security
  • CGI, DNS, Sendmail, other network services