Главная
Study mode:
on
1
Introduction
2
Outline
3
Background
4
Packet capture
5
Mirroring
6
Three drawbacks
7
What are the alternatives
8
NetFlow
9
How does it work
10
History lesson
11
IPFIX
12
IPFIX template
13
IPFIX is structured
14
botnet detection algorithms
15
pcap vs IPFIX
16
Applications of IPFIX
17
IPFIX exporter
18
Adapt capture
19
Network big data
20
Template extensibility
21
Collaboration
Description:
Explore IPFIX and its application in botnet traffic capture through the BotProbe project in this 42-minute Security BSides London conference talk. Delve into the advantages of IPFIX over traditional packet capture methods, including its ability to capture traffic across layers 3-7 of the OSI model and achieve a 97% reduction in traffic volumes. Learn about the history of NetFlow, the development of IPFIX, and how its template extensibility enhances threat detection capabilities. Discover the potential applications of IPFIX in pre-event forensics, legal traffic interception, and improved traffic analysis times. Gain insights into botnet detection algorithms, the comparison between pcap and IPFIX, and the process of adapting capture methods for network big data scenarios.

BotProbe - Botnet Traffic Capture Using IPFIX

Security BSides London
Add to list
0:00 / 0:00