Use page 258 to learn the flags, the offsets, and the rules. But rely on your own analysis to catch the intruder.
For those looking for more in-depth information on SEC503, there are several PDF resources available, including:
The SANS SEC503 course, officially titled (and recently updated to Network Monitoring and Threat Detection In-Depth ), is widely regarded as one of the most technical and challenging offerings from the SANS Institute . It is specifically designed to prepare students for the prestigious GIAC Certified Intrusion Analyst (GCIA) certification. Core Philosophy: "Packets as a Second Language"
The real test asks:
The course is part of the (GIAC Certified Intrusion Analyst) certification.