You can't detect abnormal traffic if you don't know what normal traffic looks like. This talk will walk attendees through the process of creating a network baseline(Bro) and configuring IDS alerts (Snort) to notify them when "non-standard" traffic occurs. Having a standardized, repeatable method to perform this task simplifies things.