Course Overview
Who should attend
- Security administrators
- Security consultants
- Network administrators
- System engineers
- Technical support personnel
- Channel partners and resellers
Prerequisites
- Technical understanding of TCP/IP networking and network architecture
- Working knowledge of how to use and operate Cisco Sourcefire® Systems or open source Snort
- Working knowledge of command-line text editing tools, such as the vi editor
- Basic rule-writing experience is suggested
Course Objectives
- Understand rule structure, rule syntax, rule options, and their usage
- Configure and create Snort rules
- Understand the rule optimization process to create efficient rules
- Understand preprocessors and how data is presented to the rule engine
- Create and implement functional Regular Expressions in Snort rules
- Design and apply rules using byte_jump/test/extract rule options
- Understand the concepts behind protocol modeling to write rules that perform better