Prerequisites: COMP 401 and COMP 400B.
This course will cover techniques for detecting the unusual usage patterns that typically signal a break-in. The course will also consider differences in detection of local intruders versus intrusion over networks. Finally issues in the prosecution of those breaking in to computers, particularly evidentiary issues are explored.
Outcomes: Students will learn to configure ID systems (eg, snort) and analyze their output; They will also understand both network-based and host-based monitoring techniques.
This course will cover techniques for detecting the unusual usage patterns that typically signal a break-in. The course will also consider differences in detection of local intruders versus intrusion over networks. Finally issues in the prosecution of those breaking in to computers, particularly evidentiary issues are explored.
Outcomes: Students will learn to configure ID systems (eg, snort) and analyze their output; They will also understand both network-based and host-based monitoring techniques.