Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Arming Small Security Programs - Network Baseline Generation and Alerts

via YouTube

Overview

Learn how to arm small security programs with network baseline generation and alerts in this 36-minute conference talk from BSidesCharm 2017. Explore the Bro network security monitor and discover techniques for application and network whitelisting. Dive into practical implementation using Python scripts and Bro scripts for event-driven monitoring. Understand how to generate baseline files, analyze SMB traffic, and leverage machine learning for enhanced security. Gain insights into use cases and port listing to strengthen your organization's network defenses.

Syllabus

Intro
Meet Bro
Why am I here
The problem
The idea
Writing it down
Heuristics
Application Whitelisting
Network Whitelisting
How can I do this
Bro
Connection ID
Python Scripts
EventDriven Scripts
String Format
New Connection
Check Destination Port
If Statement
Bro Script
Logging
Parse
Scenario Network
Brophy
Install Brophy
Restart Brophy
Generate Baseline File
SMB Traffic
Recap
Use Cases
Port List
Machine Learning
End Date

Reviews

Start your review of Arming Small Security Programs - Network Baseline Generation and Alerts

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.