Overview
Syllabus
Intro
Welcome
About me
Agenda
Why BSides
Assumed breach mentality
Application Awareness
Processing Power
Why are these things broken
Firewall lets traffic out
DLP
URL Filtering
Anomaly Detection
Static Patterns
Data chunking
A funny story
Encryption arouses suspicion
FireWay
Test Data Mode
Server Mode
Client Mode
sanitized logs
Layer 7 rule
Firewall is already past data
So thats pretty cool right
But lets do something
Reassembly
Servers Ready
Example
Output
Spacing
Reverse BitTorrent
Generate Sequence Key
Random Characters
Sequence Key
Reassemble
Small Pieces
Layer 7 Devices
HTTP
Why HTTP
Why Encoding
HTTP Headers
DNS Requests
Wireshark
Reassembly Keys
Inbound
Discussion Questions