Course Detail
Course Description
| Course | Code | Semester | T+P (Hour) | Credit | ECTS |
|---|---|---|---|---|---|
| CYBER SECURITY OPERATIONS MANAGEMENT | COED1215557 | Spring Semester | 3+0 | 3 | 8 |
| Course Program |
| Prerequisites Courses | |
| Recommended Elective Courses |
| Language of Course | English |
| Course Level | Third Cycle (Doctorate Degree) |
| Course Type | Elective |
| Course Coordinator | Prof.Dr. Selim AKYOKUŞ |
| Name of Lecturer(s) | Prof.Dr. Selim AKYOKUŞ |
| Assistant(s) | |
| Aim | In this course, you will deepen your knowledge on how best to detect and respond to security incidents while gaining job-ready, practical skills in cybersecurity operations You will expore security concepts, methods of security monitoring, host-based analysis techiques, network intrusion analysis, and the development of security policies and procedures. Through the use of real equipment and Cisco Pack et Tracer, you will develop critical thinking and problem-solving skills. Additionally, this course prepares you for the Cisco Certified CyberOps Associate Certification and aligns with the National Initiative for Cybersecurity Eduation (NICE) Cybersecurity Workforce Framework, ensuring standardized communication and language for cubersecurity education training, and workforce development. |
| Course Content | This course contains; Network Security Impact and Attacks: Describe the potential impact of network security attacks and how networks are attacked.,Career Resources and OS History: Identify resources available to prepare for a career in cybersecurity operations and discuss the history of the Windows Operating System.,Operating Systems and Addresses: Compare the roles of the MAC address and the IP address, and understand the features of Windows and Linux operating systems.,Malware Detection and Types: Use tools to detect malware on a Linux host and identify various types of malware.,Data Network Communications and Protocols: Explain the basic operation of data networked communications, and describe how the Ethernet, IP, and transport layer protocols support network functionality.,Network Services, Devices, and Monitoring Tools: Explain how network services and devices enable wired and wireless communication, and utilize tools like ICMP, ping, and traceroute for network monitoring.,Network Protocol Analysis and Traffic Monitoring: Analyze network protocols and services including ARP PDUs, and explain network traffic monitoring techniques. ,Vulnerabilities in Applications and Endpoints: Discuss vulnerabilities in common network applications, services, and endpoints, and explain how they are assessed and managed.,Network Defense, Cryptography, and PKI: Cryptography, and PKI: Describe network defense approaches, evaluate the impact of cryptography on network security, and discuss the support provided by the public key infrastructure (PKI).,Security Data, Alert Evaluation, and Incident Response: Identify types of network security data, explain the process of evaluating security alerts, interpret data to determine the source of an alert, and describe how the CyberOps Associate responds to cybersecurity incidents.. |
| Course Learning Outcomes | Teaching Methods | Assessment Methods |
| Demonstrate comprehensive understanding of the role and responsibilities of a Cybersecurity Operations Analyst within an enterprise context. | 10, 12, 17, 2, 3, 9 | A, E, F |
| Compare and contrast the features and characteristics of the Windows and Linux operating systems including security considerations. | 10, 12, 17, 2, 3, 9 | A, E, F |
| Explain the fundamental principles and components of network infrastructures and their significance in modern enterprises. | 10, 12, 17, 2, 3, 9 | A, E, F |
| Analyze various network protocols and services including their functionalities, vulnerabilities, and potential security implications. | 10, 12, 17, 2, 3, 9 | A, E, F |
| Identify and classify different types of network attacks understanding their methodologies and impact on network security. | 10, 12, 17, 2, 3, 9 | A, E, F |
| Utilize network monitoring tools proficiently to detect, analyze, and respond to attacks targeting network protocols and services. | 10, 12, 17, 2, 3, 9 | A, E, F |
| Implement diverse methods and strategies to prevent unauthorized access to computer networks, hosts, and sensitive data. | 10, 12, 17, 2, 3, 9 | A, E, F |
| Evaluate the impact of cryptography on network security monitoring, recognizing its role in ensuring data confidentiality, integrity, and authentication. | 10, 12, 17, 2, 3, 9 | A, E, F |
| Investigate and assess endpoint vulnerabilities and attacks employing appropriate techniques and tools for detection and mitigation. | 10, 12, 17, 2, 3, 9 | A, E, F |
| Assess and interpret network security alerts effectively, prioritizing and responding to potential security incidents in a timely manner. | 10, 12, 17, 2, 3, 9 | A, E, F |
| Analyze network intrusion data to identify vulnerabilities, compromised hosts, and potential attack vectors facilitating proactive security measures. | 10, 12, 17, 2, 3, 9 | A, E, F |
| Teaching Methods: | 10: Discussion Method, 12: Problem Solving Method, 17: Experimental Technique, 2: Project Based Learning Model, 3: Problem Baded Learning Model, 9: Lecture Method |
| Assessment Methods: | A: Traditional Written Exam, E: Homework, F: Project Task |
Course Outline
| Order | Subjects | Preliminary Work |
|---|---|---|
| 1 | Network Security Impact and Attacks: Describe the potential impact of network security attacks and how networks are attacked. | Review recent case studies on network security breaches. Study common attack vectors and their impacts on different types of networks. |
| 2 | Career Resources and OS History: Identify resources available to prepare for a career in cybersecurity operations and discuss the history of the Windows Operating System. | Research cybersecurity career paths and certifications (e.g., CISSP, CEH). Study the evolution of the Windows Operating System and its security features over time. |
| 3 | Operating Systems and Addresses: Compare the roles of the MAC address and the IP address, and understand the features of Windows and Linux operating systems. | Review networking fundamentals focusing on MAC and IP addresses. Study the security features of both Windows and Linux operating systems. |
| 4 | Malware Detection and Types: Use tools to detect malware on a Linux host and identify various types of malware. | Familiarize yourself with common malware types and their characteristics. Install and practice using malware detection tools like ClamAV on a Linux host. |
| 5 | Data Network Communications and Protocols: Explain the basic operation of data networked communications, and describe how the Ethernet, IP, and transport layer protocols support network functionality. | Study the OSI model with a focus on the data link, network, and transport layers. Review how Ethernet, IP, and TCP/UDP protocols function and support network communication. |
| 6 | Network Services, Devices, and Monitoring Tools: Explain how network services and devices enable wired and wireless communication, and utilize tools like ICMP, ping, and traceroute for network monitoring. | Review the roles of common network devices (routers, switches, access points). Practice using network monitoring tools such as ICMP, ping, and traceroute to diagnose network issues. |
| 7 | Network Protocol Analysis and Traffic Monitoring: Analyze network protocols and services including ARP PDUs, and explain network traffic monitoring techniques. | Study ARP protocol and how it resolves IP addresses to MAC addresses. Practice using tools like Wireshark to capture and analyze network traffic. |
| 8 | Vulnerabilities in Applications and Endpoints: Discuss vulnerabilities in common network applications, services, and endpoints, and explain how they are assessed and managed. | Research common vulnerabilities in applications (e.g., SQL injection, XSS) and endpoints (e.g., unpatched software, open ports). Study vulnerability assessment tools and techniques. |
| 9 | Network Defense, Cryptography, and PKI: Cryptography, and PKI: Describe network defense approaches, evaluate the impact of cryptography on network security, and discuss the support provided by the public key infrastructure (PKI). | Review network defense mechanisms (firewalls, IDS/IPS). Study the basics of cryptography (encryption, hashing) and the role of PKI in securing communications. |
| 10 | Security Data, Alert Evaluation, and Incident Response: Identify types of network security data, explain the process of evaluating security alerts, interpret data to determine the source of an alert, and describe how the CyberOps Associate responds to cybersecurity incidents. | Study different types of security data (logs, alerts). Review methodologies for evaluating and responding to security alerts. Practice incident response scenarios to understand the steps involved in managing security incidents. |
| Resources |
| NetAcad Cyber Operations NetAcad Linux Essentials Information Security Management Principles 3rd edition by A. Taylor, D. Alexander, A. Finch, D. Sutton Lecture notes delivered during classes |
Course Contribution to Program Qualifications
| Course Contribution to Program Qualifications | |||||||
| No | Program Qualification | Contribution Level | |||||
| 1 | 2 | 3 | 4 | 5 | |||
| 1 | Develop and deepen the current and advanced knowledge in the field with original thought and/or research and come up with innovative definitions based on Master's degree qualifications. | ||||||
| 2 | Conceive the interdisciplinary interaction which the field is related with ; come up with original solutions by using knowledge requiring proficiency on analysis, synthesis and assessment of new and complex ideas. | ||||||
| 3 | Evaluate and use new information within the field in a systematic approach and gain advanced level skills in the use of research methods in the field. | ||||||
| 4 | Develop an innovative knowledge, method, design and/or practice or adapt an already known knowledge, method, design and/or practice to another field. | ||||||
| 5 | Broaden the borders of the knowledge in the field by producing or interpreting an original work or publishing at least one scientific paper in the field in national and/or international refereed journals. | ||||||
| 6 | Contribute to the transition of the community to an information society and its sustainability process by introducing scientific, technological, social or cultural improvements. | ||||||
| 7 | Independently perceive, design, apply, finalize and conduct a novel research process. | ||||||
| 8 | Ability to communicate and discuss orally, in written and visually with peers by using a foreign language at least at a level of European Language Portfolio C1 General Level. | ||||||
| 9 | Critical analysis, synthesis and evaluation of new and complex ideas in the field. | ||||||
| 10 | Recognizes the scientific, technological, social or cultural improvements of the field and contribute to the solution finding process regarding social, scientific, cultural and ethical problems in the field and support the development of these values. | ||||||
Assessment Methods
| Contribution Level | Absolute Evaluation | |
| Rate of Midterm Exam to Success | 50 | |
| Rate of Final Exam to Success | 50 | |
| Total | 100 | |
| ECTS / Workload Table | ||||||
| Activities | Number of | Duration(Hour) | Total Workload(Hour) | |||
| Course Hours | 0 | 0 | 0 | |||
| Guided Problem Solving | 0 | 0 | 0 | |||
| Resolution of Homework Problems and Submission as a Report | 0 | 0 | 0 | |||
| Term Project | 0 | 0 | 0 | |||
| Presentation of Project / Seminar | 0 | 0 | 0 | |||
| Quiz | 0 | 0 | 0 | |||
| Midterm Exam | 0 | 0 | 0 | |||
| General Exam | 0 | 0 | 0 | |||
| Performance Task, Maintenance Plan | 0 | 0 | 0 | |||
| Total Workload(Hour) | 0 | |||||
| Dersin AKTS Kredisi = Toplam İş Yükü (Saat)/30*=(0/30) | 0 | |||||
| ECTS of the course: 30 hours of work is counted as 1 ECTS credit. | ||||||
Detail Informations of the Course
Course Description
| Course | Code | Semester | T+P (Hour) | Credit | ECTS |
|---|---|---|---|---|---|
| CYBER SECURITY OPERATIONS MANAGEMENT | COED1215557 | Spring Semester | 3+0 | 3 | 8 |
| Course Program |
| Prerequisites Courses | |
| Recommended Elective Courses |
| Language of Course | English |
| Course Level | Third Cycle (Doctorate Degree) |
| Course Type | Elective |
| Course Coordinator | Prof.Dr. Selim AKYOKUŞ |
| Name of Lecturer(s) | Prof.Dr. Selim AKYOKUŞ |
| Assistant(s) | |
| Aim | In this course, you will deepen your knowledge on how best to detect and respond to security incidents while gaining job-ready, practical skills in cybersecurity operations You will expore security concepts, methods of security monitoring, host-based analysis techiques, network intrusion analysis, and the development of security policies and procedures. Through the use of real equipment and Cisco Pack et Tracer, you will develop critical thinking and problem-solving skills. Additionally, this course prepares you for the Cisco Certified CyberOps Associate Certification and aligns with the National Initiative for Cybersecurity Eduation (NICE) Cybersecurity Workforce Framework, ensuring standardized communication and language for cubersecurity education training, and workforce development. |
| Course Content | This course contains; Network Security Impact and Attacks: Describe the potential impact of network security attacks and how networks are attacked.,Career Resources and OS History: Identify resources available to prepare for a career in cybersecurity operations and discuss the history of the Windows Operating System.,Operating Systems and Addresses: Compare the roles of the MAC address and the IP address, and understand the features of Windows and Linux operating systems.,Malware Detection and Types: Use tools to detect malware on a Linux host and identify various types of malware.,Data Network Communications and Protocols: Explain the basic operation of data networked communications, and describe how the Ethernet, IP, and transport layer protocols support network functionality.,Network Services, Devices, and Monitoring Tools: Explain how network services and devices enable wired and wireless communication, and utilize tools like ICMP, ping, and traceroute for network monitoring.,Network Protocol Analysis and Traffic Monitoring: Analyze network protocols and services including ARP PDUs, and explain network traffic monitoring techniques. ,Vulnerabilities in Applications and Endpoints: Discuss vulnerabilities in common network applications, services, and endpoints, and explain how they are assessed and managed.,Network Defense, Cryptography, and PKI: Cryptography, and PKI: Describe network defense approaches, evaluate the impact of cryptography on network security, and discuss the support provided by the public key infrastructure (PKI).,Security Data, Alert Evaluation, and Incident Response: Identify types of network security data, explain the process of evaluating security alerts, interpret data to determine the source of an alert, and describe how the CyberOps Associate responds to cybersecurity incidents.. |
| Course Learning Outcomes | Teaching Methods | Assessment Methods |
| Demonstrate comprehensive understanding of the role and responsibilities of a Cybersecurity Operations Analyst within an enterprise context. | 10, 12, 17, 2, 3, 9 | A, E, F |
| Compare and contrast the features and characteristics of the Windows and Linux operating systems including security considerations. | 10, 12, 17, 2, 3, 9 | A, E, F |
| Explain the fundamental principles and components of network infrastructures and their significance in modern enterprises. | 10, 12, 17, 2, 3, 9 | A, E, F |
| Analyze various network protocols and services including their functionalities, vulnerabilities, and potential security implications. | 10, 12, 17, 2, 3, 9 | A, E, F |
| Identify and classify different types of network attacks understanding their methodologies and impact on network security. | 10, 12, 17, 2, 3, 9 | A, E, F |
| Utilize network monitoring tools proficiently to detect, analyze, and respond to attacks targeting network protocols and services. | 10, 12, 17, 2, 3, 9 | A, E, F |
| Implement diverse methods and strategies to prevent unauthorized access to computer networks, hosts, and sensitive data. | 10, 12, 17, 2, 3, 9 | A, E, F |
| Evaluate the impact of cryptography on network security monitoring, recognizing its role in ensuring data confidentiality, integrity, and authentication. | 10, 12, 17, 2, 3, 9 | A, E, F |
| Investigate and assess endpoint vulnerabilities and attacks employing appropriate techniques and tools for detection and mitigation. | 10, 12, 17, 2, 3, 9 | A, E, F |
| Assess and interpret network security alerts effectively, prioritizing and responding to potential security incidents in a timely manner. | 10, 12, 17, 2, 3, 9 | A, E, F |
| Analyze network intrusion data to identify vulnerabilities, compromised hosts, and potential attack vectors facilitating proactive security measures. | 10, 12, 17, 2, 3, 9 | A, E, F |
| Teaching Methods: | 10: Discussion Method, 12: Problem Solving Method, 17: Experimental Technique, 2: Project Based Learning Model, 3: Problem Baded Learning Model, 9: Lecture Method |
| Assessment Methods: | A: Traditional Written Exam, E: Homework, F: Project Task |
Course Outline
| Order | Subjects | Preliminary Work |
|---|---|---|
| 1 | Network Security Impact and Attacks: Describe the potential impact of network security attacks and how networks are attacked. | Review recent case studies on network security breaches. Study common attack vectors and their impacts on different types of networks. |
| 2 | Career Resources and OS History: Identify resources available to prepare for a career in cybersecurity operations and discuss the history of the Windows Operating System. | Research cybersecurity career paths and certifications (e.g., CISSP, CEH). Study the evolution of the Windows Operating System and its security features over time. |
| 3 | Operating Systems and Addresses: Compare the roles of the MAC address and the IP address, and understand the features of Windows and Linux operating systems. | Review networking fundamentals focusing on MAC and IP addresses. Study the security features of both Windows and Linux operating systems. |
| 4 | Malware Detection and Types: Use tools to detect malware on a Linux host and identify various types of malware. | Familiarize yourself with common malware types and their characteristics. Install and practice using malware detection tools like ClamAV on a Linux host. |
| 5 | Data Network Communications and Protocols: Explain the basic operation of data networked communications, and describe how the Ethernet, IP, and transport layer protocols support network functionality. | Study the OSI model with a focus on the data link, network, and transport layers. Review how Ethernet, IP, and TCP/UDP protocols function and support network communication. |
| 6 | Network Services, Devices, and Monitoring Tools: Explain how network services and devices enable wired and wireless communication, and utilize tools like ICMP, ping, and traceroute for network monitoring. | Review the roles of common network devices (routers, switches, access points). Practice using network monitoring tools such as ICMP, ping, and traceroute to diagnose network issues. |
| 7 | Network Protocol Analysis and Traffic Monitoring: Analyze network protocols and services including ARP PDUs, and explain network traffic monitoring techniques. | Study ARP protocol and how it resolves IP addresses to MAC addresses. Practice using tools like Wireshark to capture and analyze network traffic. |
| 8 | Vulnerabilities in Applications and Endpoints: Discuss vulnerabilities in common network applications, services, and endpoints, and explain how they are assessed and managed. | Research common vulnerabilities in applications (e.g., SQL injection, XSS) and endpoints (e.g., unpatched software, open ports). Study vulnerability assessment tools and techniques. |
| 9 | Network Defense, Cryptography, and PKI: Cryptography, and PKI: Describe network defense approaches, evaluate the impact of cryptography on network security, and discuss the support provided by the public key infrastructure (PKI). | Review network defense mechanisms (firewalls, IDS/IPS). Study the basics of cryptography (encryption, hashing) and the role of PKI in securing communications. |
| 10 | Security Data, Alert Evaluation, and Incident Response: Identify types of network security data, explain the process of evaluating security alerts, interpret data to determine the source of an alert, and describe how the CyberOps Associate responds to cybersecurity incidents. | Study different types of security data (logs, alerts). Review methodologies for evaluating and responding to security alerts. Practice incident response scenarios to understand the steps involved in managing security incidents. |
| Resources |
| NetAcad Cyber Operations NetAcad Linux Essentials Information Security Management Principles 3rd edition by A. Taylor, D. Alexander, A. Finch, D. Sutton Lecture notes delivered during classes |
Course Contribution to Program Qualifications
| Course Contribution to Program Qualifications | |||||||
| No | Program Qualification | Contribution Level | |||||
| 1 | 2 | 3 | 4 | 5 | |||
| 1 | Develop and deepen the current and advanced knowledge in the field with original thought and/or research and come up with innovative definitions based on Master's degree qualifications. | ||||||
| 2 | Conceive the interdisciplinary interaction which the field is related with ; come up with original solutions by using knowledge requiring proficiency on analysis, synthesis and assessment of new and complex ideas. | ||||||
| 3 | Evaluate and use new information within the field in a systematic approach and gain advanced level skills in the use of research methods in the field. | ||||||
| 4 | Develop an innovative knowledge, method, design and/or practice or adapt an already known knowledge, method, design and/or practice to another field. | ||||||
| 5 | Broaden the borders of the knowledge in the field by producing or interpreting an original work or publishing at least one scientific paper in the field in national and/or international refereed journals. | ||||||
| 6 | Contribute to the transition of the community to an information society and its sustainability process by introducing scientific, technological, social or cultural improvements. | ||||||
| 7 | Independently perceive, design, apply, finalize and conduct a novel research process. | ||||||
| 8 | Ability to communicate and discuss orally, in written and visually with peers by using a foreign language at least at a level of European Language Portfolio C1 General Level. | ||||||
| 9 | Critical analysis, synthesis and evaluation of new and complex ideas in the field. | ||||||
| 10 | Recognizes the scientific, technological, social or cultural improvements of the field and contribute to the solution finding process regarding social, scientific, cultural and ethical problems in the field and support the development of these values. | ||||||
Assessment Methods
| Contribution Level | Absolute Evaluation | |
| Rate of Midterm Exam to Success | 50 | |
| Rate of Final Exam to Success | 50 | |
| Total | 100 | |