From the course: CCNA Cybersecurity (200-201) v1.2 Cert Prep
Unlock this course with a free trial
Join today to access over 25,200 courses taught by industry experts.
Module 4: Network traffic analysis and interpretation
From the course: CCNA Cybersecurity (200-201) v1.2 Cert Prep
Module 4: Network traffic analysis and interpretation
(bright music) - [Narrator] In this module, we're diving into network traffic analysis and interpretation. And by analyzing traffic flowing through our network, we not only can better spot active intrusions, but it can also help us to verify our defenses such as our firewalls, our IDS, and our IPS sensors. It can help make sure that they're working as expected. And also in this module, we're going to check out DPI, or deep packet inspection. We'll compare net flow summaries of traffic with full packet captures and talk about when we should use each one, and we'll examine what's going on with the various fields in our protocol headers. And we'll also see how regular expressions, or Regex, can be used to zero in on suspicious patterns within a very large traffic log. We're going to be doing some demos with Wireshark as well. We'll begin by capturing a Telenet session and seeing if we can find the password inside of that capture traffic, because after all Telenet is in clear text. Then…
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.
Contents
-
-
-
-
-
-
(Locked)
Module 4: Network traffic analysis and interpretation1m 18s
-
(Locked)
Security event sources5m 26s
-
(Locked)
Alert classification4m 6s
-
(Locked)
Deep packet inspection (DPI)3m 53s
-
(Locked)
Comparing traffic-capture methods and NetFlow analysis4m 30s
-
Wireshark PCAP file analysis for Telnet flow2m 56s
-
(Locked)
Wireshark PCAP file analysis for malware infection8m 56s
-
(Locked)
Interpreting protocol headers7m 20s
-
(Locked)
Artifact elements7m 37s
-
(Locked)
Regular expressions5m 32s
-
(Locked)
-
-
-