Saturday, June 18, 2011

GSE Lab plan……

With the GSE written out of the way it’s time to focus on preparing for the lab. My plan, which will go to hell over the summer as work and personnel stuff take over, but it’s my plan anyway.
The first part of my plan is to go over several books, which I have been trying to do for a longtime. Here is a list of the following books I plan to review:
  • The Tao of Network Security Monitoring
  • Extrusion Detection
  • Counterhack Reloaded
  • Wireshark Network Analysis
  • Hacking Exposed
Although the list is long I spend almost two hours daily travelling to and from the office on public transportation so I have plenty of “free time”.

However the lab is not about book smarts, it’s about the ability to get stuff done. To make sure my skills are up to speed, review tools I never or often use I plan on creating a lab. The lab that I plan to build will consist of the following systems:
  • Linux (Ubuntu) – Firewall, IDS, IPS
  • Windows 2008 Server – Domain Controller
  • Windows 2003 Server – Domain Controller
  • Windows 7 Ultimate – Workstation
  • Windows XP SP3 – Workstation
  • Linux (Fedora 12) – Linux Server, www, ftp, smtp
  • BackTrack4 – Attacking System
I plan to record all network traffic in the lab for later analysis. This network traffic will include “normal” and “abnormal” traffic. I will be attacking the various systems to create security incidents, than investigate the incidents. I plan to use only the tools covered in the material.

So there is my plan for preparing for the lab. Will it be enough, I don’t know but it should cover all of the defined GSE objectives and if I meet those I will pass. 

1 comment:

  1. Dennis,

    Great post... I, and several others, have recently attended, tested and passed several SANS courses/certifications, and some of us are working on the GSE. We have been sent to different parts of the globe, and I put together a quick site to collaborate. Not much now, but it will come along. Please visit digital gravity.net and contribute if you want. I will post the link to your blog...thanks for the information...

    grvty

    ReplyDelete

 
Site Meter