Linux Course » LP004 Linux in a Nutshell : Security Administration

  Course Code:   LP004       
  Duration:  4 Days Pricing :  22,300 Baht (VAT Included)
  Course Description  
 

The course will teach students how to use local and network security. This is a course for those responsible for the configuration, managing and setup of Linux system security e.g. kernel security, data security, file system security, password security, ACLs, SELinux, network services security, TCPWrappers, Linux-based firewall with iptables and Virtual Private Networking.


Course Audience

This course is designed for experienced Linux and networking professionals who are responsible for configuring and maintaining security for Linux systems.


Prerequisites Knowledge

Linux in a Nutshell : Essentials course (LP001), Linux in a Nutshell : System Administration course (LP002) and Linux in a Nutshell : Network Administration course (LP003) or equivalent experience with Linux operating system.


Purpose

This course is designed to teach the students how to manage and implement local and network security for Linux system.

Goal

Upon completion of this course, students should be able to:

 
  • Discuss network and local system security and place the firewall therein
  • Install and harden Linux system
  • System monitoring
  • Understand PAM authentication
  • Securing the kernel, file systems and data
  • Manage TCPWrappers for securing services
  • SELinux administration
  • Configure iptables packet filtering and Network Address Translation
  • Configure Virtual Private Networking
  • Configure and use hacker’s tools
  • Detect and counter firewall intrusions

  • Course contents

    1.  Introduction to Security and Firewall
     
  • Definition of security
  • Security policy
  • Type of attack
  • Principles of security
  • Security practices
  • Hackers, crackers and script kiddies
  • Motivation of hackers and crackers
  • What you have to lose
  • What is a firewall?
  • Position of a firewall
  • Virtual Private Networking
  • Network security techniques and usage
  • 2.  PAM Authentication
     
  • Authentication
  • PAM
  • Password security
  • Password policy
  • Utilities and authentication
  • PAM troubleshooting
  • 3.  System Monitoring
     
  • Introduction to system monitoring
  • File system analysis
  • System log file
  • Log file analysis
  • Monitoring process
  • Process monitoring utilities
  • System activity reporting
  • Limiting process
  • Process accounting tools
  • 4.  Installing and Securing Linux
     
  • Installing Linux
  • Applying patches
  • Kernel recompilation
  • Hardening Linux
  • User account considerations
  • Disabling services
  • Filesystem Hardening
  • Access Control Lists (ACLs)
  • Kernel tuning and configuration options
  • 5.  Securing Services
     
  • System V startup control
  • Securing the services
  • TCPWrappers configuration
  • Securing xinetd
  • Securing DNS
  • Securing Mail
  • 6.  Securing Data
     
  • Fundamentals of encryption
  • The need for encryption
  • Symmetric encryption
  • Asymmetric encryption
  • Public Key Infrastructure (PKI)
  • Digital certificates
  • 7.  SELinux Administration
     
  • Security Enhanced Linux (SELinux)
  • SELinux targeted policy
  • SELinux installation options and control
  • Controlling SELinux
  • SELinux contexts
  • Troubleshooting SELinux
  • 8.  Securing Network
     
  • Packet filtering overview
  • Network Address Translation
  • Kernel-level firewall implementation with iptables
  • Protection against spoofed addresses
  • IP masquerading
  • FWBuilder
  • 9.  Virtual Private Networking
     
  • Virtual Private Network concepts
  • Virtual Private Network solutions
  • IPSec
  • 10.  Hacker’s Tools
     
  • Sniffers
  • Ethereal
  • Nmap
  • Nessus
  • 11.  Detecting and Countering Firewall Intrusions
     
  • Detecting attack attempts
  • Filesystem integrity checking with Tripwire
  • Network intrusion detection systems with Snort
  • Logfile monitoring with Swatch
  • Countering attacks
  • Deception
  •  
      PREV   NEXT  
    TOP