Course

Credit Type:
Course
ACE ID:
DDCI-0014
Version:
4
Organization's ID:
LA
Location:
Online
Length:
5 days (50 hours)
Minimum Passing Score:
70
ACE Credit Recommendation Period:
Credit Recommendation & Competencies
Level Credits (SH) Subject
Upper-Division Baccalaureate 6 Network Analysis
Description

Objective:

The course objective is for students to explain log analysis methodology; explain benefits of log analysis in an intrusion investigation; analyze and evaluate log files; and extract information from log files.

Learning Outcomes:

  • Determine the begin and end time of a log file.
  • Describe the logs found on computer systems and network devices.
  • Describe the common attributes of log file contents.
  • Identify relevant tools used in time normalization.
  • Describe the technology approaches to parsing and analyzing data from logs.
  • Identify diverse types of binary logs.
  • Perform a search of a Windows event log with GUI tools.
  • Identify the types of statistical data that Wireshark can present.
  • Create statistics about HTTP GET requests.
  • Use TCPdump command options to filter output.
  • Describe web server log formats.
  • Describe FTP server log formats.
  • Describe Syslog log format.
  • Define intrusion detection system (IDS) logs.
  • Assess log file size.
  • Identify Linux commands for filtering and searching.
  • Use regular expressions to create search patterns.
  • Use Excel to perform searches of log files.
  • Create and use PivotTables in Excel.
  • Use intrusion keywords to search log files.
  • Analyze text logs for intrusion artifacts
  • List the benefits of log analysis in an intrusion investigation.
  • Describe the common attributes of log file content.
  • Identify time skew and time bias.
  • Describe technology options for performing log analysis.
  • Perform extraction of data from binary logs.
  • Perform a search of a network traffic capture with GUI tools.
  • Perform a search of a network traffic capture with command-line tools.
  • Identify the filters that can be used to narrow a search.
  • Export statistical data from Wireshark.
  • Use TCPdump to read a binary capture and redirect the output to a text file.
  • Display the contents of a text log.
  • Use basic regular expressions.
  • Convert log files into CSV format.
  • Adjust date and time to account for time bias and skew.
  • List the primary tasks of log analysis.
  • Describe the features of modern logging infrastructure.
  • Describe features of data formats.
  • Describe the types of information found in logs.

General Topics:

  • Process logs from Windows and Linux operating systems, firewalls, intrusion detection systems, and web and email servers
  • Assemble evidence found in logs to assist in tasks ranging from building a case to recognizing an intrusion
Instruction & Assessment

Instructional Strategies:

  • Audio Visual Materials
  • Coaching/Mentoring
  • Computer Based Training
  • Practical Exercises

Methods of Assessment:

  • Examinations
  • Quizzes
Supplemental Materials
Equivalencies

Other offerings from DC3 Cyber Training Academy