Subject

Network Security Analysis

1. Course Title Network Security Analysis
Network security analysis
2. Code m23_s_062
3. Study Programme
4. Organizer of the study programme (unit, institute, department or division) Faculty of Computer Science and Engineering
5. Degree level (first, second, third cycle) Second cycle
6. Academic year / semester 10 / Summer
7. Number of ECTS credits 6
8. Teacher Христина Михајлоска Трпческа, Соња Филипоска
9. Prerequisites for enrolling in the course
10. Objectives of the course programme (competences) Со комплетирањето на содржината на предметот студентот ќе се стекне со знаење за изведување на крај-крај пенетрациско тестирање на мрежни системи, примена на стекнатото знаење, алатки и принципи за откривање и искористување на ранливостите на дадени целни организации.
11. Course content Професионално изведување на пенетрациско тестирање. Градење на инфраструктура за пенетрациско тестирање. Креирање на ефикасни тест сценарија и правила на игра. Детално следење на настаните со користење на соодветни алатки. Генерирање на извештаи за тестирањето. Работа на SOC. Длабинско скенирање. Tcpdump за тестирање. Користење на Nmap. Скенирање за ранливости. Грешно позитивна редукција. Манипулација на пакети. Енумерација на корисници. Тестирање, мониторирање на сервиси за време на скенирање. Различни типови на payload delivery. Искористување на ранливости. Компромитација на целни машини во клиент-сервер режим, ранливост на серверска страна и ескалации. Metasploit и Metapreter. DoS пенетрациско тестирање. Пенетрациско тестирање на routers и switches. Пенетрациско тестирање на firewall. Пенетрациско тестирање на веб апликации и e-mail. Пенетрациско тестирање на IDS.
12. Learning methods Lectures supported by slide presentations, interactive lectures, exercises (using equipment and software packages), teamwork, case studies, guest lecturers, independent preparation and defense of a project assignment and seminar paper, learning in an electronic environment (forums, consultations).
13. Total available time 6 ECTS x 30 hours = 180 hours
14. Distribution of available time 45 + 15 + 30 + 50 + 40 = 180 hours
15. Forms of teaching activities
15.1. Lectures - theoretical instruction 45 hours
15.2. Exercises (laboratory, auditory), seminars, teamwork 15 hours
16. Other forms of activities
16.1. Project assignments 50 hours
16.2. Independent assignments 30 hours
16.3. Home study 40 hours
17. Assessment method
17.1. Tests 45 points
17.2. Seminar paper / project (presentation: written and oral) 50 points
17.3. Activities and learning 10 points
17.4. Final exam 0 points
18. Grading criteria (points / grade)
up to 50 points5 (five) (F)
from 51 to 60 points6 (six) (E)
from 61 to 70 points7 (seven) (D)
from 71 to 80 points8 (eight) (C)
from 81 to 90 points9 (nine) (B)
from 91 to 100 points10 (ten) (A)
19. Requirement for obtaining a signature and taking the final exam completed activities
20. Language of instruction Macedonian and English
21. Method for monitoring the quality of teaching internal evaluation and survey mechanism
22. Literature
22.1. Required literature
1. Peter Kim | The Hacker Playbook 1-3 | Independently published | 2018
2. Gus Khawaja | Kali Linux Penetration Testing Bible | Wiley | 2021
3. Glen D. Singh | The Ultimate Kali Linux Book: Perform advanced penetration testing using Nmap, Metasploit, Aircrack-ng, and Empire, 2nd Edition | Packt Publishing | 2022
22.2. Additional literature
No. Author Title Publisher Year