Explore machine learning techniques for analyzing Bro logs in this conference talk from Security Onion 2016. Dive into practical applications of cyborgism, focusing on HTTP proxy logs analysis. Learn about supervised and unsupervised machine learning approaches, including binary classification with random forests and outlier detection using isolation forests. Discover how to generate synthetic abnormal data, understand decision trees, and leverage scikit-learn and Python for efficient model training, testing, and evaluation. Gain insights into identifying influential features and interpreting classifier explanations. Acquire valuable ideas for improving log file analysis and enhancing cybersecurity practices through the integration of machine learning methodologies.
Practical Cyborgism - Machine Learning for Bro Logs