NATO CCD COE will hold a course on Cyber Defence Monitoring Solutions from 17th to 21st of October and registration for the course is now open. This technical course will be instructed by Centre’s scientists, Mr. Risto Vaarandi and Captain Roman Palík.
During the course, a number of important Cyber Defence Monitoring techniques and solutions will be studied, focusing on event logging and collection with syslog protocol, regular expression language and its applications to system/network monitoring, event correlation, and finally network intrusion detection and prevention.
In addition many open-source monitoring solutions will be discussed, including the netfilter firewall and iptables utility, UNIX syslogd and syslog-ng event logging packages, Simple Event Correlator, Snort IDS/IPS. Each module of the course consists of a presentation from the lecturer which is followed by a hands-on session.
Participants of the course are expected to have a good understanding of TCP/IP networking and work experience in UNIX environments (editing files with vi editor, knowledge of common UNIX utilities and UNIX shell). At best the students should have experience in administrating Linux based systems, understand the main networking protocols (e.g ARP, IP, ICMP, TCP, UDP, DNS, HTTP), have some experience with web technologies (like HTML, PHP, Javascript). Previous programming experience is not required, programming skills in any standard language would be helpful.
Other courses held by NATO CCD COE this Autumn:
Botnet Infiltration Training 26 - 30 September, 2011 (registration is closed)
IT Systems Attack and Defence 3 – 7 October, 2011 (registration is closed)
Security Events Management 24 - 25 October, 2011 (admission opens on 19 September)
Please note that the NATO CCD COE courses are primarily targeted to our sponsoring nations but representatives from other countries are welcome in case slots remain available. Please contact Major Leo Oja for more information (leo.oja at ccdcoe.org).