It is impossible to overstress the importance of security, and as a more recent addition: privacy, in NREN networks. But while the importance of security and privacy is widely recognised, training in these areas has often been aimed at the security personnel tasked with handling incidents, while the system and network administration seems to have been neglected.

The “Operational Network Security” training programme has been created as a result of collating experiences and conducting discussions with security offices and network operators.

Its aim is to address a number of common security risks that NRENs face in their day-to-day operations: authentication, logging, audit, privacy, 1st Hop security, DNS security and protection from Distributed Denial-of-Service attack.

Training events have been offered live throughout 2020 / 21. Previously run sessions are available for viewing on GÉANTTV

Operating System Privacy and Security

  • 1. Operating System Telemetry – configuring protection in Windows 10

    (slides) (recording)
    The session provides an insight into the telemetry mechanism Windows uses for data collection and how it can be configured to the needs of an organisation. It also explores additional ways to make Windows 10 more privacy friendly.

  • 2. Logging and Audit – Log management and audit strategies

    (slides) (recording)
    All IT users know about log files and many of them, and not only system administrators, even regularly look at application logs, syslog entries, or Windows Eventlogs. However, without sound processes in place for analysing these logs, their value is significantly reduced.

    The session provides an insight into log management as well as audit strategies and some practical tips for configuring windows & Linux logging/audit settings and understanding the need for central log collection and examination.

  • 3. File Integrity Monitoring (FIM) for detecting security incidents

    (slides) (recording)
    Detecting malicious changes to operating system files early and thoroughly is vital to the handling of security incidents. Programs to look out for such changes however are rarely used, although these have been around for a long time and their usefulness is unequivocally recognised. This seems rooted in the assumption that it is difficult and time-consuming to operate such programs properly.

    The session introduces the concept of file integrity monitoring (FIM) and gives practical tips to participants on how to plan and start adopting FIM in their organisation. It also includes a live demonstration of one of the latest open source FIM solutions ‘Wazuh’.

  • 4. Network 1st Hop Security

    (slides) (recording)
    Configuring end-user systems for accessing directly attached networks is being facilitated through use of automatic configuration protocols such as DHCP or IPv6 Router Discovery. Also, for operation on attached links, finding the corresponding link-layer address to an ip-address is done using protocols such as ARP or IPv6 Neighbor Discovery.

    While these protocols are vital to the operation of the network, they inherit a number of security risks, which are also explored in this session, as well as ways to mitigate some security risks.

  • 5. Authentication Methods – how to avoid common pitfalls

    (slides) (recording)
    Authentication is the basis for any kind of secure system. Unfortunately, it is also easy to get wrong, and getting it wrong fundamentally breaches a system’s security.

    The session provides an overview of authentication methods and outlined the most important and relevant approaches in more detail to help participants avoid the most common pitfalls in this area.

Client Privacy and Security

  • 1. Browser Security and Privacy

    (slides) (recording)
    Web-browsers have long been ubiquitous as providing a window onto the internet, with their versatility being a key factor in their success. But web browsers can also be (mis)used for tracking the activities of their users. Not surprisingly, the security of browsers and the privacy of those who use them have become one of the most important topics in information security.

    For Firefox and Chromium-based browsers, the session gives an introduction on how to secure them and how to avoid providing unnecessary personal data to websites or browser vendors. Participants are also shown how to avoid being tracked on their personal trail across the internet.

  • 2. E-Mail Security and Privacy

    (slides) (recording)
    One of the oldest practical uses of the Internet is email. Most of us use it on a daily basis, and e-mail has become one of the most important tools of business. Email has also become one of the most universal and persistent sources of privacy and security headaches.

    The webinar gives an overview of the many challenges that email introduces and provides approaches of how to effectively deal with some of its more common issues.

  • 3. Instant Messaging Security and Privacy

    (slides) (recording)
    From the Microsoft Messenger and Internet Relay Chat of the nineties to the more current WhatsApp and Discord, instant messengers pre-date the World Wide Web, and while the client programs have changed and gained functionality, their usage shows no sign of decline.

    Session participants are shown how to secure instant messenger clients and how to avoid common privacy pitfalls.

  • 4. Videoconferencing Security and Privacy

    (slides) (recording)
    Videoconferencing has been around for some time, but its use has increased manifold during the COVID-19 pandemic. With employees being locked down in their home offices, videoconferences have replaced business meetings and entire business trips, allowing the illusion of face-to-face interaction. This comes with the burden of an unknown impact on the privacy and confidentiality of the conversations, as well as the security of the client applications.

    The webinar provides an overview of security and privacy issues with popular videoconferencing clients and services and shows how to address them.

  • 5. Office Security and Privacy

    (slides) (recording)
    Many people regularly use programs such as MS Office. Having started as simple text-editing programs, modern Office suites have turned into highly complex applications. They are available on every operating system, including mobile OSs, and are quickly evolving into cloud-based applications, allowing for convenient collaboration. However, the growing complexity of these programs has introduced a number of problems related to both privacy and security.

    The talk offers participants an insight into common privacy issues and security risks and provides some practical tips to address them.

Domain Name System (DNS) protection

  • 1. Introduction to DNS and its Security Challenges – meet the problems

    (slides) (recording)
    The Domain Name System (DNS) is one of the core services of the Internet as we know it today. DNS was designed in 1983 and has been a critical part of the Internet infrastructure ever since.

    This session gives an overview of how DNS works and, crucially, what the security implications of its design and operation are.

  • 2. DNS for Network Defence – Using DNS to protect and observe

    (slides) (recording)
    DNS is not only used for the mapping of names to IP addresses and vice versa.

    This module shows several use cases using information provided by DNS servers that can be used to protect the local network from malicious activities, such as SPAM or drive-by infections. This is followed by a block on monitoring DNS queries to collect information about ongoing intruder activity on an organisation's network.

  • 3. DNSSEC – Protecting the integrity of the Domain Naming System

    (slides) (recording)
    Although hampered by slow adoption, DNSSEC has proven to deal effectively with the integrity problems of DNS.

    This module introduces the general concepts of DNSSEC and provided a practical example by implementing DNSSEC in a local zone.

  • 4. DNS Privacy Protocols – Encrypted DNS queries for privacy protection

    (slides) (recording)
    With the integrity of DNS taken care of by DNSSEC, inspection of DNS query data has been used by various actors on the internet for both good and bad purposes. "DNS over TLS" (DoT) and "DNS over HTTPS" (DoH) have been created as ways to mitigate the latter, while unfortunately also interfering with the former.

    The module gives insights into the workings and configuration of DoT and DoH and explains the trade-offs organisations' network administrators have to make between security and privacy, as well as showing how some of these can be dealt with.

Distributed Denial of Service (DDoS) protection

  • 1. Introduction to DDoS Attacks – An overview of motivation and modus operandi of attackers

    (slides) (recording)
    DDoS attacks have been around for more than 20 years now, and over this time, they have gained in power, now reaching several terabits in bandwidth, enough to knock off ISPs. While the actual DDoS attacks have changed very little, the orchestration of the attacks, the deployment of their components and the motives of attackers have evolved.

    The course gives participants an overview of the attacks, the attackers, and their motivation and modus operandi.

  • 2. Details of Selected DDoS Attacks – How the attacks work from a technical perspective

    (slides) (recording)
    While DDoS attacks have become more powerful and easier to start for attackers, the technical details of DDoS attacks have been remarkably consistent over the last 20 years.

    This course provides participants with an in-depth view of the technical details of the most common DDoS mechanisms: amplification and reflection and the services being exploited for them.

  • 3. DDoS Detection – How to know if you are under attack or partake in an attack

    (slides) (recording)
    DDoS Detection may in theory sound simple, i.e., when you can't access your systems, that means you're under attack. However, this may also happen due to technical problems or misconfigurations. And what if we want to detect attacks before falling victim to them?

    The course shows participants the various ways in which DDoS attacks are detected on the internet.

  • 4. DDoS Mitigation – What you can do against them?

    (slides) (recording)
    Mitigating a DDoS attack, especially a large-scale one, can seem like a daunting task, especially where there is a determined attacker and when several sites are affected.

    The course shows some simple but proven techniques to combat DDoS attacks as well as to avoid unintentionally partaking in one.

Vulnerability Management (3 Submodules)

Vulnerabilities, in software and sometimes even in hardware, are open gates attackers can utilize to gain access to private systems and networks. Worse, they have become a fact IT managers and administrators have to deal with, ever accompanied by the concern that a single critical vulnerability has been overlooked that will later be exploited.

Submodule 1

Vulnerability Management addresses this problem with a systematic approach to make this a reliable and reoccurring process. This module gives an overview of standards, details how to distribute security advisories among your constituency and how to plan and roll out patches in your organization.

  • 1. Vulnerability Management Process and Standards

    (slides) (recording)
    The task of dealing with Vulnerabilities in Software, and sometimes even in Hardware, has gone from an ad hoc, emergency activity to a continuous, planned task that has become one of the building blocks of reliable, secure systems and networks.

    This webinar will give an overview of the existing standards and will cover some of the key elements, like CVE and CVSS, in depth, that will be referenced throughout the coming webinars on vulnerability management.

  • 2. Vulnerability Information – How to gather and distribute security advisories to your constituency

    (slides) (recording)
    Before one can address with vulnerabilities, one needs to be aware of them: their existence, their consequences, and what to do about them. While CSIRTs and PSIRTs take care of the initial steps in researching and publishing information, the task of actually forwarding this information to the administrators responsible for vulnerable systems, is something that every organisation has to deal with themselves.

    This webinar will show how this task can be dealt with and what information should be included in a security advisory.

  • 3. Patch Management – How to roll out and track security fixes to your systems

    (slides) (recording)
    'Patching' is the name given to the process of replacing vulnerable software with a corrected version. However, the sheer number of patches that has to be applied constantly has led to the requirement to automate and track the application of patches.

    This webinar will give an overview of the process of applying patches and what tools can be used to automate the task.

Submodule 2

Scanning for vulnerabilities in your organisations network is considered one of the key aspects of vulnerability management. In this three-webinar sub-module, different scanning and testing approaches are covered. From scanning the system inside-out or from the outside to simulating actual attacks (pentesting), the attendees will be taken through the introductory steps of conducting and supervising scans and pentests.

  • 1. Looking into the Network – How to scan local systems for vulnerabilities and misconfigurations

    (slides) (recording)
    Today's systems are so complex that it's almost impossible to run a system without vulnerabilities and misconfigurations. And although there are plenty of benchmarks, baselines, and hardening guides available, it is difficult to apply them to the local environment.

    This webinar will introduce some of the most useful frameworks and tools for local vulnerability scanning.

  • 2. Network Vulnerability Scanning – Looking from afar

    (slides) (recording)
    In order to stay ahead of the threats to a large infrastructure, it is crucial to maintain a clear picture of whether there are vulnerabilities in the components deployed and, if so, which ones. Scanning systems through the network is one way of gaining insight into this issue.

    This webinar will provide an introduction to the concepts of network scanning, its benefits, and its drawbacks, as well as offer some practical examples.

  • 3. Penetration Tests – How does your network stand up against real attacks?

    (slides) (recording)
    No matter how much scanning for vulnerabilities and security process evaluating is done, one question remains: is this really enough against real attacks? Short of experiencing an attack in real life, penetration tests try to answer this question by conducting attacks in a controlled manner.

    This webinar will give managers and administrators an introduction to the standards and workflow of penetration tests to help in planning and supervising penetration tests carried out on their networks.

Submodule 3

Looking for vulnerabilities in existing systems and services has become a common practice, however, vulnerability scanning covers only software packages from established sources and only those vulnerabilities that are already known. But what about vulnerabilities you don't know about yet? What about software that is developed in-house. This sub-module will give an introduction into the topics of code audits and vulnerability disclosure, covering two main aspects of vulnerability management for software that you are responsible for. Concluding will be an introduction into Breach and attack simulation, a relatively new approach to assess the risks and consequences of existing vulnerabilities in your network.

  • 1. Code Audits

    (slides) (recording)
    Software without bugs or vulnerabilities doesn't exist. If your organization runs software development teams they will likely have heard of things like secure software development lifecycles and the like.

    This webinar will introduce some basic concepts as well as tools that help developers finding bugs before the software goes into production.

  • 2. Vulnerability Disclosure

    (slides) (recording)
    So you have found vulnerabilities in other people's code. Or other people have found vulnerabilities in your code. Either way: How to handle the situation? In the long run, trying to keep information about the vulnerability under wraps is unlikely to work.

    In this module, we will cover some aspects and strategies of how to approach this issue.

  • 3. Breach and Attack Simulation – Matching attacker behaviour with vulnerabilities

    (slides) (recording)
    Breach and Attack Simulation (BAS) is a relatively new approach to vulnerability assessment that goes beyond simple scoring of vulnerabilities by also taking the modus operandi of adversaries into account.

    This webinar will give an introduction into the topic and present some open source tools to do BAS.

Skip to content