Literature Review

profilekiran sandhu
Fall2020ISSM538literaturereviewareasDrDaleDaleLindskog.pdf

Project for Winter 2021 RM2

---------------------------

Supervisor: Dale Lindskog

Project goal: enhance a pentesting lab and associated documentation

Students, upon entering RM2, with be given a pentesting lab design

document, created by a previous group of RM2 students, and which they

will be implementing during the Winter 2021 semester. That existing

document will describe a network design, the placement and description

of various vulnerable and attacking systems, various planned recipes

for attacks, and some detection and network traffice analysis of these

attacks.

This Fall 2020 RM1 group's project will, in Winter 2021 RM2, be to

enhance this existing design of a pentesting lab, including, possibly,

DoS attacks, intrusion prevention, incident response capabilities, or

botnets. The project will be broken down into a number of

interrelated and coordinated sub-projects with a smaller number of

participants.

Specific knowledge and skills:

Students should study Metasploit as background to the exploits they

will encounter in the existing design document. But in addition,

students should study one or more of the following:

- Intrusion detection, and especially with Snort

- Intrusion prevention, especially with Snort

- Incident response with Google Rapid Response

- Anomoly detection, especially with Bro

- Network scanning and vulnerability assessment, especially with Nmap and

OpenVAS/Nessus

- Incident analysis tools, especially GRR Rapid Response, and Volatility

Framework

It will be important to study, not just theory, but a reasonable

number of the tools mentioned above, since it is these tools that

partcipants will be working with. There is some flexibility with

regard to breadth of study. Students may choose to study a broader

variety of these technologies, but less deeply, or choose to

investigate more deeply a smaller number.