校際選修

115-1 選課時程

進行中

  • 初選第一階段 6/15/2026
  • 初選第二階段 6/22/2026
  • 校際選修 8/24/2026
  • 初選第三階段 8/31/2026
  • 開學後加退選 9/7/2026
  • 逾期加退選 9/21/2026
選課資源

企業網路安全

Enterprise Cybersecurity

學期
109-2
學分
3 學分
當期課號
1164
永久課號
DCP3126
開課單位
資訊工程學系
授課教師
謝續平
校區
光復
類別
選修
上課時間表
週一
週四
3
10:10–11:00
企業網路安全
EC329
2 節連堂
4
11:10–12:00
7
15:30–16:20
企業網路安全
EC329

* 根據陽明交大上課時間表所列

概述

鑑於國際駭客組織有計畫的犯罪,企業遭受前所未有網路攻擊威脅,面臨嚴峻的企業經營挑戰。針對性進階持續威脅(APT: Advanced Persistence Threat)、逐步滲透的駭客組織型犯罪,商業間諜與內賊(Insider Threat)的竊取資料防不勝防。這類行為沒有惡意特徵碼,傳統的邊界防禦機制(perimeter defense)力有未逮。了解你的敵人,才能作最有效的防禦(Understanding your enemies to prioritize defense),具有網絡視覺化和管控力(Visibility and Control)的新世代全面防禦-資安態勢感知(Situation Awareness)-成為關鍵。本課程探討現今企業經營面臨的資安挑戰,解析新世代企業資安治理,涵蓋:(一)資安威脅現況(二)前瞻防禦策略(三)資安成熟度評估和防禦策略(四)如何建構強健資安管控與團隊。課程將穿插案例分享,從實例中討論與解析,並經由圓桌討論,交換心得。本課程範圍以企業網路整體安全為主軸,經由學習各式各樣的開源軟體與自動化工具,分析大量系統行為紀錄(System logs)與網路行為(Network Flows),分析使用者行為(UEBA: User and Entity Behavior Analytics)感知與視覺化網路威脅,排定防禦優先順序,將模糊的網路虛擬世界實體化,及早發現攻擊行為以及攻擊途徑,甚至預警,切斷攻擊鏈,進而有效的管理。這是目前網路安全實務的新趨勢,非常適合大學部學生從動手中學習。本課程以大學部學士班為講授對象,簡介傳統網路防禦機制,因應新型APT網路攻擊的Mitre ATT&CK framework,NIST Cybersecurity Framework、ISO 27001相關資安風險評量標準,進而介紹更為主動、積極的「網路威脅分析」方法與機制。本課程將指導學生使用自動化工具,從動手實作中學習。 This quote from The Art of War is very relevant to today's digital battlefield: "If you know the ene-my and yourself, you will win hundreds of battles." Conventional perimeter defense, such as fire-walls and intrusion detection systems (IDS), provides the first layer of enterprise protection, but can be evaded. According to a recent study, it took an average company 170 days to detect an ad-vanced threat. This is due to the lack of visibility in the cyberspace. For better understanding your adversaries, In this course, we will investigate the attack surface and techniques most commonly used against an enterprise by attacking groups. It is desirable for a company to proactively and iter-atively search through networks to monitor, detect, and isolate advanced threats that evade exist-ing security solutions. Understanding your adversaries to prioritize defenses with comprehensive security strategy can effectively reduce business operation risk. Course contents: 1 Conventional Perimeter Network Defense 2 Hacking Basics 2.1 Hacking techniques 2.2 Advanced Persistent Threat (APT) 2.3 Attack phases and countermeasures 2.4 Cyber Kill Chain 2.5 Breaking Cyber Kill Chain 2.6 Threat Intelligence 2.7 Red team and blue team 2.8 Best Hacking Tools For Windows, Linux and Mac OS X 3 Threat Model 3.1 Cybersecurity Posture and Situation Awareness 3.2 Attack Surface 3.3 Insider Threats 3.4 Pitfalls of Perimeter Defense 3.5 Lockheed Martin's Kill Chain Model 3.6 MITRE’s ATT&CK Framework 3.7 Unified Kill Chain 4 Comprehensive Strategy for Cybersecurity Maturity Assessment 4.1 ISO 27001 4.2 NIST Cybersecurity Framework 4.3 Federal Financial Institutions Examination Council's (FFIEC) Cybersecurity Assessment Tool 5 Threat Hunting 5.1 A Framework for Cyber Threat Hunting 5.2 Log Analysis 5.3 Network Traffic Analysis 5.4 DNS 5.5 Correlation Analysis 5.6 Big Data Analytics 5.7 Visualization 5.8 Identifying Threat Path 5.9 Insider Threats 6 Risk Assessment and Measure 1 weeks 6.1 Measurement 6.2 Key Security and Risk Indicators 6.3 Security Scorecard 7 Incident Management 7.1 Detection, Containment and Remediation 7.2 Effectiveness 7.3 Tracking History and Trend 8 Cyber Resilience 1 week 8.1 Cyber awareness 8.2 Network segregation 8.3 Backup 9 Threat Detection and Analysis Tools 9.1 Vulnerability Assessment for Attack Surface Reduction 9.1.1 OpenVAS 9.1.2 OWASP ZAP 9.1.3 BlackDuck 9.2 Penetration Test for Identifying Attack Paths 9.2.1 Metasploit 9.3 Network Intrusion Detection & Prevention System 9.3.1 Snort 9.4 SIEM (Security Information and Event Management) 9.4.1 ELK: Elasticsearch, Logstash, and Kibana 9.4.2 IBM QRadar 9.5 Network Flow Analysis 9.5.1 Cisco Stealthwatch 10 Labs and experiments 11 Project presentation and demo

先修科目

1. 無需先修科目 2. 對資訊安全實務具有興趣的大學部學生

教學方式

上課、研讀資料、程式動手作

評分方式

1. 期末考 2. project:程式動手作、投影片、成果報告、現場報告。

教科書

教科書:自訂資料 參考書:Reference books: “Data-Driven Security: Analysis, Visualization and Dashboards,” Jay Jacobs & Bob Rudis, published by WILEY. “Network Security Through Data Analysis: Building Situational Awareness,” Michael Collins, published by O’Reilly “Learning By Practicing - Hack & Detect: Leveraging the Cyber Kill Chain for Practical Hacking and its Detection via Network Forensics,” November 12, 2018 by Nik Alleyne “The Threat Hunting Route to Predictive Cyber Security,” white paper, 2020. “Getting Started with ATT&CK,” Adam Pennington, published by Mitre, 2020