Главная
Study mode:
on
1
Intro
2
Meet Bro
3
Why am I here
4
The problem
5
The idea
6
Writing it down
7
Heuristics
8
Application Whitelisting
9
Network Whitelisting
10
How can I do this
11
Bro
12
Connection ID
13
Python Scripts
14
EventDriven Scripts
15
String Format
16
New Connection
17
Check Destination Port
18
If Statement
19
Bro Script
20
Logging
21
Parse
22
Scenario Network
23
Brophy
24
Install Brophy
25
Restart Brophy
26
Generate Baseline File
27
SMB Traffic
28
Recap
29
Use Cases
30
Port List
31
Machine Learning
32
End Date
Description:
Learn how to arm small security programs with network baseline generation and alerts in this 36-minute conference talk from BSidesCharm 2017. Explore the Bro network security monitor and discover techniques for application and network whitelisting. Dive into practical implementation using Python scripts and Bro scripts for event-driven monitoring. Understand how to generate baseline files, analyze SMB traffic, and leverage machine learning for enhanced security. Gain insights into use cases and port listing to strengthen your organization's network defenses.

Arming Small Security Programs - Network Baseline Generation and Alerts

Add to list
0:00 / 0:00