Network Security Workshop PDF Print

Instructors:
Damien Holloway, Kunjal Trivedi, Merike Kaeo

Who should attend:

Network Operations and security staff at ISPs and Network Service Providers. People who are trying to learn ropes of establishing a functioning security system in their network core and edges. Any one else with interest in Security topics.

Pre-requisites:

This is an advanced course. Good familiarity with UNIX command line and system administration jobs. Knowledge of Layer 3 protocols, and command line of popular routers. Basic knowledge of security concepts is an added advantage.

What you will learn:
The ISP / NSP Security Workshop focuses on following components to provide comprehensive understanding and hands-on experience allowing you to gain valuable experience in network security best common practices, tools and techniques.

  • Network infrastructure security
  • Security services

For network infrastructure security, best common practice for protecting infrastructure including IP addressing, baseline building,
securing IGP and BGP routing protocols and router filtering techniques are covered in detail. Controlling access to the routers, collecting network telemetry information and control plane protection techniques are discussed.

A six step methodology for detecting and mitigating DDoS attacks on the infrastructure provides hands-on understanding on how to deal with such attacks. Anti-spoofing measures to combat IP spoofing attacks and Remotely Triggered Blackhole (RTBH) filtering to protect against infrastructure attacks hands-on practice provides easy to deploy tools on the SP networks.

The security services address designing, deploying and managing L3 Virtual Private Networks. A balanced discussion covering security of 3VPN provides good basis of evaluating the level of security for the business needs. Finally, a discussion of how managed security services such as IP VPN prepares SP networks for provisioning other security services

 



Abstracts
  • 32-bit ASNs
    Chris Malayter, Switch&Data, Co-author: Greg Hankins , Force10 Networks