Literature Review
Project for Winter 2021 RM2
---------------------------
Supervisor: Dale Lindskog
Project goal: enhance a pentesting lab and associated documentation
Students, upon entering RM2, with be given a pentesting lab design
document, created by a previous group of RM2 students, and which they
will be implementing during the Winter 2021 semester. That existing
document will describe a network design, the placement and description
of various vulnerable and attacking systems, various planned recipes
for attacks, and some detection and network traffice analysis of these
attacks.
This Fall 2020 RM1 group's project will, in Winter 2021 RM2, be to
enhance this existing design of a pentesting lab, including, possibly,
DoS attacks, intrusion prevention, incident response capabilities, or
botnets. The project will be broken down into a number of
interrelated and coordinated sub-projects with a smaller number of
participants.
Specific knowledge and skills:
Students should study Metasploit as background to the exploits they
will encounter in the existing design document. But in addition,
students should study one or more of the following:
- Intrusion detection, and especially with Snort
- Intrusion prevention, especially with Snort
- Incident response with Google Rapid Response
- Anomoly detection, especially with Bro
- Network scanning and vulnerability assessment, especially with Nmap and
OpenVAS/Nessus
- Incident analysis tools, especially GRR Rapid Response, and Volatility
Framework
It will be important to study, not just theory, but a reasonable
number of the tools mentioned above, since it is these tools that
partcipants will be working with. There is some flexibility with
regard to breadth of study. Students may choose to study a broader
variety of these technologies, but less deeply, or choose to
investigate more deeply a smaller number.