Software Engineering Institute Carnegie Mellon

Course Offerings
Prices
Locations, Travel, and Lodging
Courses FAQ
Privacy Information (FERPA)
Registration
Contact Information
Credentials Program
SEI Certification

Advanced Incident Handling

Dates

2008* Prices (USD)

Remaining 2008 Dates
November 17-21, 2008 (CIC Bldg. Pittsburgh, PA)



2009 Dates
May 11-15, 2009 (CIC Bldg. Pittsburgh, PA)
July 13-17, 2009 (SEI Frankfurt, Germany)
September 21-25, 2009 (SEI Arlington, VA)
December 7-11, 2009 (CIC Bldg. Pittsburgh, PA)

Course Registration
Software Engineering Institute
Carnegie Mellon University
Pittsburgh, PA 15213-3890
Phone: 412 / 268-7388
FAX: 412 / 268-7401
Questions: courseregistration@sei.cmu.edu

To Register: 2008 Click Here

To Register: 2009 Click Here

This course may also be offered by arrangement at customer sites. E-mail training-info@cert.org or call +1 412-268-9564 for details.

*Course dates and fees are subject to change.

U.S.
Course Fee:
Industry: $2750
Government: $2200
Academic: $2200

International
Course Fee:
$5500

    Register for
2008 Dates


  Register for
2009 Dates

Course Description

 

This five-day course, designed for computer security incident response team (CSIRT) technical personnel with several months of incident handling experience, addresses techniques for detecting and responding to current and emerging computer security threats and attacks that are targeted at a variety of operating systems and architectures.

Building on the methods and tools discussed in the Fundamentals of Incident Handling course, this course provides guidance that incident handlers can use in responding to system compromises at the privileged (root or administrator) level. Through interactive instruction, facilitated discussions, and group exercises, instructors help participants identify and analyze a set of events and then propose appropriate response strategies.

Participants work as a team throughout the week to handle a series of escalating incidents that are presented as part of an ongoing scenario. Work includes team analysis of information and presentation of findings and response strategies. Participants also review broader aspects of CSIRT work such as computer forensics, artifact analysis; vulnerability handling; and the development of advisories, alerts, and management briefings.

This course is part of the curriculum for the CERT-Certified Incident Handler program. Before registering for this course, participants are encouraged to attend the companion course, Fundamentals of Incident Handling.

Audience   ·    Prerequisites    ·    Objectives   ·    Logistics

 

AUDIENCE

  • current computer security incident response team (CSIRT) technical staff with three to six months incident handling experience
  • system and network administrators responsible for identifying and responding to security incidents

PREREQUISITES
Before registering for this course, it is recommended that participants attend the Fundamentals of Incident Handling course. It is also recommended that participants have the following:

  • at least three to six months of incident handling experience
  • an understanding of Internet services and protocols
  • experience with the administration of Windows and Unix systems
  • an understanding of basic programming concepts
  • experience with various types of computer security attacks, response strategies, incident handling tools

It is recommended but not required that participants also have experience programming in C, Perl, Java, or similar languages.

TOPICS

  • understanding issues and challenges in handling privilege compromise incidents
  • detecting, analyzing, and responding to various types of malicious activity such as the use of rootkits, botnets, and distributed denial of service attacks
  • responding to insider threats and attacks
  • handling major computer security events and incidents
  • understanding the role of computer forensic analysis in incident handling
  • performing artifact analysis
  • understanding the fundamental causes of vulnerabilities
  • analyzing and coordinating response to reported vulnerabilities
  • publishing effective CSIRT information

OBJECTIVES
This course will help participants to

  • detect and characterize various attack types
  • understand the complexity of and effectively respond to privileged and major events and incidents within your CSIRT
  • gain a practical understanding of various methods for analyzing artifacts left on a compromised system
  • explore new developments in the area of computer forensics
  • obtain practical experience in the analysis of vulnerabilities and the coordination of vulnerability handling tasks
  • formulate effective advisories, alerts, and management briefings

Course Materials
Participants will receive a course notebook and a CD containing the course materials.

LOGISTICS

Class Schedule
This five-day course meets at the following times:
Days 1-4, 9:00 a.m.-5:00 p.m.
Day 5, 9:00 a.m.-3:00 p.m.

Hotel and Travel Information
Information about traveling to the SEI offices is available on our Travel and Lodging Web pages.

Questions about this course?
Please see our Frequently Asked Questions Web page for answers to some of the more common inquiries about SEI Education and Training.

If you need more information, contact us via e-mail at training-info@cert.org or telephone at +1 412-268-9564.



 

 

Related Products and Services

 

Courses
Managing Computer Security Incident Response Teams (CSIRTs)
Creating a Computer Security Incident Response Team
Fundamentals of Incident Handling
Information Security for Technical Staff
Advanced Information Security for Technical Staff

Publications
Handbook for Computer Security Incident Response Teams (CSIRTs), Second Edition
Defining Incident Management Processes for CSIRTs
The Critical Success Factor Method: Establishing a Foundation for Enterprise Security Management
Organizational Models for CSIRTs Handbook
State of the Practice of CSIRTs
Incident Management Capability Metrics Version
Incident Management Mission Diagnostic Method
Outsourcing Managed Security Practices
Insider Threat Study: Illicit Cyber Activity in the Banking and Finance Sector
Insider Threat Study: Computer System Sabotage in Critical Infrastructure Sectors
CSIRT Services List
rlogin: The Untold Story
Governing for Enterprise Security
Managing for Enterprise Security
First Responders Guide to Computer Forensics

Events
Annual Computer Security Incident Handling Conference, sponsored by FIRST.ORG, Inc.

Related Podcasts
Tackling Security at the National Level: A Resource for Leaders
The Real Secrets of Incident Management

Related Podcasts
A New Look at the Business of IT Education
Business Resilience: A More Compelling Argument for Information Security
Compliance vs. Buy-in
Computer Forensics for Business Leaders: Building Robust Policies and Processes

Other Related Information
CSIRT Development Information
CERT-Certified Incident Handler Certification
CERT Training and Education

Course Registration

 

  Register for 2008 Dates

  Register for 2009 Dates
 

^
TOP