Account: (login)

More Channels


Are you the publisher? Claim this channel

Search in 126,293,059 RSS articles:

Channel Description:

Looking beyond the obvious

Latest Articles in this Channel:

  • 07/10/09--15:21: Visualising Sguil session data with NetFlow (chan 1411972)
  • I think this is the first time I’ve explicitly mentioned Sguil, and I’m not going to talk too much about the package itself as many others have already done it for me. Basically, Sguil is a nicely integrated suite of (free) tools that will help you put NSM principles into practice. It has a wonderful [...]

    alecwatersalecwaters

    in_onlyin_only

    bidirectionalbidirectional

    hrhr

    DatalineDataline

    hrhr

  • 08/12/09--15:10: Detecting encrypted traffic with frequency analysis (chan 1411972)
  • Let’s start with a little disclaimer: I am not a cryptanalyst. I am not a mathematician. It is quite possible that I am a complete idiot. You decide. With that out of the way, let’s begin. NSM advocates the capture of, amongst other things, full-content data. It is often said that there’s no point in [...]

    alecwatersalecwaters

    hrhr

    DatalineDataline

    hrhr

  • 09/02/09--13:21: Detecting encrypted traffic with frequency analysis – Update (chan 1411972)
  • I recently wrote about a plan for detecting encrypted traffic, where I mentioned in the comments that I’d come across a package called net-entropy (very detailed writeup here). I’ve been in touch with Julien Olivain, one of the authors, and he’s kindly given me the sources to experiment with. And experiment I shall – I’ll [...]

    alecwatersalecwaters

    hrhr

    DatalineDataline

    hrhr

  • 10/06/09--05:40: net-entropy Sguil agent and wiki (chan 1411972)
  • The story so far: Detecting encrypted traffic with frequency analysis Detecting encrypted traffic with net-entropy, part one Detecting encrypted traffic with net-entropy, part two I’ve written a basic Sguil agent that will upload net-entropy’s RISING ALARM messages into Sguil. You can download the agent here, and the config file here. On a Sguil sensor that [...]

    alecwatersalecwaters

    net-entropy sguilnet-entropy sguil

    net-entropy sguil eventsnet-entropy sguil events

    net-entropy sguil detailnet-entropy sguil detail

    hrhr

    DatalineDataline

    hrhr