SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsWe've long heard OSSEC was an excellent option for HIDS, but there is scarcity of detailed documentation on how to set up an OSSEC system. This paper will step through the installation, configuration, and use of OSSEC in a NETinVM environment. As a side effect, we will also see the benefits of having a NETinVM environment available for testing network attacks and defenses. We will very quickly review an OSSEC install (with some special considerations for the NETinVM environment), and jump right into developing an OSSEC policy. Once complete, we will develop a customized OSSEC configuration, based on our policy. To test our setup, we will launch an attack and see what OSSEC alerts are generated. Next, we will configure OSSEC to automatically respond to detected attacks and test the results.