Linux Security
As Linux continues to gain ground in the enterprise and DoD market, learn how to secure this open-source operating system. Combining quality lecture with hands-on labs, UASCE's class will provide you with the tools and knowledge to secure various flavors the Linux operating system. Special focus will be placed on Red Hat and other flavors by class request.
*NOT available on AKO/SmartForce/SkillSoft
TEXTBOOK AND TABLE OF CONTENTS
Linux Server Security, 2nd Edition by Michael D. Bauer
1. Threat Modeling and Risk Management
Components of Risk
Simple Risk Analysis: ALEs
An Alternative: Attack Trees
Defenses
2. Designing Perimeter Networks
Types of Firewall and DMZ Architectures
Deciding What Should Reside on the DMZ
Allocating Resources in the DMZ
The Firewall
3. Hardening Linux and Using iptables
OS Hardening Principles
Automated Hardening with Bastille Linux
4. Secure Remote Administration
Why It's Time to Retire Cleartext Admin Tools
Secure Shell Background and Basic Use
Intermediate and Advanced SSH
5. OpenSSL and Stunnel
Stunnel and OpenSSL: Concepts
6. Securing Domain Name Services (DNS)
DNS Basics
DNS Security Principles
Selecting a DNS Software Package
Securing BIND
djbdns
7. Using LDAP for Authentication
LDAP Basics
Setting Up the Server
LDAP Database Management
Types of Security Problems
Server Location
Server Installation
Database Operation
. Securing Internet Email
Background: MTA and SMTP Security
Using SMTP Commands to Troubleshoot and Test SMTP Servers
Securing Your MTA
Sendmail
Postfix
Mail Delivery Agents
A Brief Introduction to Email Encryption
10. Securing Web Servers
Web Security
The Web Server
Web Content
Web Applications
Layers of Defense
11. Securing File Services
FTP Security
Other File-Sharing Methods
12. System Log Management and Monitoring
syslog
Syslog-ng
Testing System Logging with logger
Managing System Logfiles with logrotate
Using Swatch for Automated Log Monitoring
Some Simple Log-Reporting Tools
13. Simple Intrusion Detection Techniques
Principles of Intrusion Detection Systems
Using Tripwire
Other Integrity Checkers
Snort
Resources