Overview
Syllabus
Intro
Justin Warner (@sixdub)
NSM Quadrant
Encryption's Impact on the Quadrant
What this Means for Network Defenders
Encrypted Traffic Metadata
Leverage Encryption as an Advantage to Shift Balance of Power to Defenders
Hunting Primer
What is Normal?
Commonality - Asset / Request Distributions
Send/Recy Ratios by Server Name
Let's Encrypt Things!
Different Levels of Certificates
Changing The Mindset
Who would abuse free certificates?
Basic Detection → Forensics Process
So... Encryption Isn't the End of the World
Encrypted NSM Security Model (ECNSMM)
Taught by
BSidesLV