Skip to content

Module 15 Overview ​

April 26-30 · Reading: 11 pages · Estimated total: 7 hours

Last week of instruction, and the one that ties the semester together.

Everything so far has been about making things go right. This week is about what you do once something has already gone wrong: what your logs can and cannot tell you, how detection gets built and why it fails, and how to write the memo that somebody has to act on at two in the morning.

There is one piece of arithmetic in this week, and it is the most important number in the course. It explains the thing you have now seen twice, a correct alert about a real intrusion, sitting unread in a queue, seven days before the ransomware.

Learning Objectives ​

By the end of this week, the successful student will be able to:

  • 7.1: Identify the data sources a detection capability draws on and what each can and cannot show.
  • 7.2: Distinguish misuse detection from anomaly detection and choose one for a stated scenario.
  • 7.3: Analyze authentication and web server logs to identify brute-force and scanning activity.
  • 7.4: Explain the base-rate fallacy and its effect on alert volume.
  • 7.5: Recommend a defensible incident response structured by the NIST SP 800-61 incident response phases.

Assignments and Tasks ​

Due by Thursday at 11:59 p.m. Mountain Time ​

Due by Friday, April 30 at 11:59 p.m. Mountain Time ​

April 30 is the last day of instruction. No lab, discussion, or extra credit from the instructional weeks is accepted after it (see the Late Work Policy). The usual two-day grace period cannot extend past the end of the semester, so week 15 has no grace period at all. D6, the final reflection is the only thing due after April 30, and it is governed by the Class Interaction Policy rather than by the homework late policy.

Time Estimate ​

ActivityTime
Reading (11 pages plus §8.2 and NIST skims)2 hrs 10 min
The notes page and the worked example50 min
Lab 101 hr 35 min
D5 post and two replies1 hr
Review and slack1 hr 25 min
Total~7 hrs

Released under the MIT License.