They didn't know what hit them. Network security monitoring on a massive scale.

No ratings

Presented at ConfidenceKrakow 2018 by

Have you ever thought - all those network security monitoring tools are exciting, but it is impossible to use them in real-world networks? What would you say, if I told you, that saving every network packet with session level logs is possible in a network that spans three continents, several data centers and multiple offices?It will be a highly practical talk, answering two main questions - how we do it and why we do it. What is the value of storing 10 000 network events per second for incident response and threat hunting?You will see how the NSM we have built, based on open-source projects - BroIDS and Suricata, provide the level of visibility and flexibility nothing else could. For a desert, I will serve ready to consume code in GitHub repos with Ansible playbooks, Suricata rules and Bro scripts.