Aug 06, 2026  
2026-2027 Course Catalog 
    
2026-2027 Course Catalog
Add to Portfolio (opens a new window)

CFI 2200 - Advanced IDS Techniques

Credits: 3
Hours/Week: Lecture 2 Lab 2
Course Description: This course focuses on deploying security and Intrusion Detection Systems (IDS), logs collections, handling, analytics, and analysis. Our analytical tools will comprise open-source Security Onions, Zeeks, SELKS, and  LAMP (Linux, Apache, MySQL, PHP) stacks with a focus on security and Intrusion Detection Systems (IDS). Topics include the installation, configuration, and management of Security Onions, SELKS and LAMP resources, Snort IDS, Zeek IDS, and other threat analytical software IDS-related tools as well as the practical test firing of IDS resources and packets.
MnTC Goals
None

Prerequisite(s): CFI 1085  with a grade of C or higher OR instructor consent.
Corequisite(s): None
Recommendation: None

Major Content
  1. Introduction to Intrusion Detection Systems (IDS’) and Snort
  2. Deployment of  Various Intrusion Detection Systems (IDS) tools.
  3. Installation and Configuration of Snort
  4. Snort rules
  5. Analysis of various packets with Zeek
  6. Analysis of packets with various security Onions tools like Kibana
  7. Introduction to Linux, Apache, MySQL and PHP (LAMP) Stacks.
  8. Configuration of lab LAMP stack for basic web server functionality.
  9. Further configuration of  lab LAMP stack for full LAMP web server functionality.

Learning Outcomes
At the end of this course, students will be able to:

  1. demonstrate resourcefulness in the deployment of multiple Intrusion Detection systems.
  2. explain the fundamental concepts of Intrusion Detection Systems (IDS).
  3. deploy appropriate strategies in network security monitoring and traffic analysis using Zeek.
  4. explain virtualization basics their relationship to IDS-related resources in a virtual environment.
  5. solve problems related to the deployment and administration of network resources.  
  6. use prodlabon labs resources to perform analytics and log analysis.
  7. perform network intrusion analysis from Test Firing engagements using various IDS platforms.
  8. analyze network traffic and find Indications of Compromise (IOC) using various IDS tools.
  9. employ practical knowledge of SQL IDS queries.
  10. configure Linux-based IDS servers in an ESX or Cloud Environment.
  11. apply working knowledge of Snort rules.

Minnesota Transfer Curriculum (MnTC): Goals and Competencies
Competency Goals (MnTC Goals 1-6)
None
Theme Goals (MnTC Goals 7-10)
None

Practicum hours per week: 0


Courses and Registration



Add to Portfolio (opens a new window)