Simulate industry practices for using open-source

Assignment Help Computer Network Security
Reference no: EM133873595 , Length: word count:2000

Introduction to Cyber Security

Assessment - Proactive Security Measures

Type - Simulation and Report

Task

Demonstrate your understanding of key cyber security concepts aligned with learning outcomes LO2, LO3, and LO4. You will utilise open-source cyber security tools to assist an organisation with the Preparation stage of the Incident Response Lifecycle.

LO2: Identify vulnerabilities and threats pertaining to the IT infrastructure of organisations.
LO3: Recommend risk mitigation strategies to address cyber security vulnerabilities and threats.
LO4: Analyse privacy, legal, ethical and security issues and solutions related to the IT infrastructure and use of technologies in organisations.

Assessment Description

This assessment is designed to simulate industry practices for using open-source cyber security tools for network security and threat detection. You will apply hands-on skills using the Elasticsearch, Logstash, Kibana (ELK) Stack, as well as Snort, which functions as both an intrusion detection system and intrusion prevention system (IDS/IPS).

This assessment is completed in two parts:

Part A: Tool configuration
Conduction during your Week 12 workshop.
You will configure security tools to meet four (4) specific objectives within 2.5 hours. These objectives would have been covered in Workshops 9 and 10.
At the end of the session, you will present your configurations to your learning facilitator for verification.

Part B: Documentation
The report must include screenshots of configurations and brief explanations detailing how each objective was achieved.

Assessment Instructions

Preparation
Ensure you have your laptop with VirtualBox installed and a Linux Mint set up with ELK Stack and Snort. You should already have these tools from Workshops 9 and 10. Get online assignment help from Ph.D. experts!
Review Workshops 9 and 10 to understand:
The purpose of each tool
How to configure them to meet security objectives
Configuration - (Part A: In-Class Assessment)
Arrive early to your Week 12 class to settle in and receive final instructions. Ensure your laptop is fully charged.
You will be assigned four (4) objectives to configure.
For each objective:
Identify the relevant tool.
Configure the tool to meet the objective.
Once you have completed all four objectives, present your configurations to your learning facilitator.
After presenting, take clear screenshots of your work. Each screenshot must also capture:
The time and date (visible in your taskbar)
A text editor displaying your name and student number
Documentation - (Part B: myKBS Submission)
Compile your screenshots into a Microsoft Word file.
Separate the screenshots per objective and then provide a brief description of the configuration and what the outcome would be (i.e. How does the configuration meet the objective?).

Assessment

Configure any four (4) out of the following objectives:
1. Configure Snort to generate an alert if more than 3 failed SSH login attempts occur within 10 minutes.
2. Modify Snort to drop HTTP requests that attempt to access to example.com.
3. Configure Snort to trigger an alert when an HTTP POST request includes a file larger than 500KB.
4. Set up an ELK log filter in Kibana to only display logs where HTTP status code = 404.
*5. Create a chart in Kibana to display the top 10 source IPs generating the most logs.
*6. Set up an ELK alert to trigger when there are more than 5 failed logins from the same IP within 15 minutes.
*7. Modify a Logstash pipeline to extract source IP, HTTP method, and response code from logs.
*8. Configure ELK to automatically delete logs older than 7 days to save disk space.

Note: need only last four parts.

Reference no: EM133873595

Questions Cloud

Examine the specialized instruments and precautions taken : Examine the specialized instruments and precautions taken by surgical technologists in ophthalmologic surgery.
Developed an advocacy plan for a policy change : Imagine you have developed an advocacy plan for a policy change that you are proposing. Who might you want on your team, and how would you contact them?
Determined by natural history of the disease : You were introduced to the occupation of epidemiology along with their methods. The methods used are determined by the natural history of the disease
Provide support steps for a direct support professional : Provide support steps for a direct support professional for monitoring Chest compressions vest, oxygen, nebulizer and suction machine in a group home setting.
Simulate industry practices for using open-source : Simulate industry practices for using open-source cyber security tools for network security and threat detection - Elasticsearch, Logstash, Kibana (ELK) Stack
How this might be applied in your future career as a nurse : How are vagueness, ambiguity and generality used in politics or in law in order to achieve a desired outcome?
Which changes is retrogressive : The nurse explains to a client who recently gave birth that the client will undergo both retrogressive and progressive change. Which change(s) is retrogressive?
Provide rationale for the primary diagnosis : Provide a rationale for the primary diagnosis. Include CPT codes for the office visit, preventive exam, and any procedures
What did the crittenden report reveal : According to Pres. Clinton, what were the two components of Don't Ask, Don't Tell that made it an "honorable compromise"?

Reviews

Write a Review

Computer Network Security Questions & Answers

  An overview of wireless lan security - term paper

Computer Science or Information Technology deals with Wireless LAN Security. Wireless LAN Security is gaining importance in the recent times. This report talks about how vulnerable are wireless LAN networks without any security measures and also talk..

  Computer networks and security against hackers

This case study about a company named Magna International, a Canada based global supplier of automotive components, modules and systems. Along with the company analysis have been made in this assignment.

  New attack models

The Internet evolution is and is very fast and the Internet exposes the connected computers to attacks and the subsequent losses are in rise.

  Islamic Calligraphy

Islamic calligraphy or Arabic calligraphy is a primary form of art for Islamic visual expression and creativity.

  A comprehensive study about web-based email implementation

Conduct a comprehensive study about web-based email implementation in gmail. Optionally, you may use sniffer like wireshark or your choice to analyze the communication traffic.

  Retention policy and litigation hold notices

The purpose of this project is to provide you with an opportunity to create a document retention policy. You will also learn how to serve a litigation hold notice for an educational institute.

  Tools to enhance password protection

A report on Tools to enhance Password Protection.

  Analyse security procedures

Analyse security procedures

  Write a report on denial of service

Write a report on DENIAL OF SERVICE (DoS).

  Phising email

Phising email It is multipart, what are the two parts? The HTML part, is it inviting the recepient to click somewhere? What is the email proporting to do when the link is clicked?

  Express the shannon-hartley capacity theorem

Express the Shannon-Hartley capacity theorem in terms of where is the Energy/bit and is the psd of white noise.

  Modern symmetric encryption schemes

Pseudo-random generators, pseudo-random functions and pseudo-random permutations

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd