• Home
  • Southern New Hampshire University
  • Network Defense CYB-310-T5690
  • Identifying & Analyzing Network Host Intrusion Detection System Alerts

Identifying & Analyzing Network Host Intrusion Detection System Alerts

Southern New Hampshire University CYB 310 Module Four Lab Worksheet Complete this worksheet by replacing the bracketed phrases in the Response column with the relevant information. Lab: Identifying & Analyzing Network Host Intrusion Detection System Alerts 1 Southern New Hampshire University Prompt In the lab, "Analyzing Network Events Using Snorby," Step 18, take a screenshot of the alert window showing signature information and TCP header information. Snorby PON SORED BY If threat stack Response Welcome Administrator Selings | Log out Dashboard Evers Sermons Search Listing Sessions (67 uriqueundasolod sessiong) Hotkeys Claunity Eventi's) 3 Filler Options Sereser Source P Security Onion. 10.1.1.10 Destination IP 203.0.113.2 Socurty Onion- 10.1.1.10 203.0.113.2 Securty Orion- 203.6.113.2 10.1.1.10 Security-Orion- 10.1.1.10 203.0.113.2 SURICATA TLS error message encountered 12:32 AM Security-Orion- 203.0.113.2 192.160.1.5 Becurty Onion- 203.9.113.2 192.168.1.50 Security Orion. 203.0.113.2 10.1.1.5 Security-Orion- 203.0.113.2 192.168.1.1 Security-Orion- 10.1.1.10 203.0.1132 GPL WEB_SERVER 403 Forbidden 12:33 AM Securty-Onion- 10.1.1.10 203.0.113.2 Security-Onion- 203.0.113.2 10.1.1.10 2 Securty-Orion- 203.0.1132 10.1.1.10 1 Security-Onion- 203.6.1132 10.1.1.1 1 Security-Onion- 203.0.113.2 192.168.1.1 OPL SHELLCODE x86 ing abx NOCP 12:22 AM 2 Security-Onion- 203.0.113.2 10.1.1.1 ET SCAN NMAP OS Detecten Probe Security-Orion- 203.0.113.2 192.168.1.1 ET SCAN NMAP OS Delection Probe Securty Onion- 203.0.1132 10.1.1.1 E Security Onion. 203.0.113.2 192.168.1.1 SURICATA ICMPAt unknown code 1 Securty-Orion- 203.0.113.2 192.168.1.5 Event Signature ET SCAN Non Allowed Host Tried to Connect to MySQL Server 12:38 AM ET SCAN Non-Allowed Host Tried to Connect to MySQL Server 12:20 AM SURICATA TLS error message encountered 12:32 AM ET SCAN Nmap Scripting Engine User-Agent Delected (Nmap .. 12:22 AM ET SCAN Nmap Scripting Engine User-Agent Detected (Nmap. 12:32 AM ET SCAN Nmap Scripting Engine User Agent Defected (Nmap. 12:12 AM ET SCAN Nmap Scripting Engine User-Agent Detected Qimap ... 12:30 AM GPL WEB_SERVER 403 Forbidden 12:22 AM ET SCAN Nmap Scripting Engine User-Agent Delected (Nmap ... 12:32 AM ET POLICY Suspicious inbound to mySQL port 2006 12:32 AM OPL SHELLCODE x86 ing abx NOCP 12:32 AM 12:22 AM 12:32 AM SURICATA ICMP/4 unknown code 12:52 AM 12:32 AM GPL SHELLCODE x86 inc etx NOCP 12:22 AM ) It looks like you haven't started Firefox in a while. Do you want to clean k uo for a fresh. liko.now exporianco? And by the way. welcome back! Snorby My Quove [0) [threat stack Roset Firefox Welcome Administrator | Satings | Log out Dashboard Events Sensors SoMuch Administration Listing Sessions (67uniqueundlod session) Hotkeys Classify Event(s) Filter Options Ser. Senaoe Source D Dudiination IP 2 Security-Cmos- 10.1.1.11 2030.1132 ET SCAN Non-Atowed Host Tried to Connect to MySCL Server IP Header Information Event Signature 12:38 AM Vewy Al Seusers Sensiom Padiet Captare Options Ewert Expert Options Permaink Destasatia Csam 10.1.1.10 203.0.113.2 4 121 31580 0 31014 Signature Information A&g Ression Letialy (72.681) 1 2011490 2 Category 7.34% Query Signature Database View Rule TCP Header Information See Part Det Por TAFEL 3906 801 2420923143 636157682 8 Payload 24 181 1245 0000000: 44 00 00 00 ff 6a 04 48 6f 000001A: 69 73 20 66 61 74 20 61 66 0000034: 74 61