Purple Packets: Effective Network Defense Against Real-World Attacks

No ratings

Presented at BSidesDFW 2019 by

There are two sides to every story. Yin and yang. Day and night. Host and network. Unfortunately, when it comes to enterprise security, many organizations tend to focus heavily on host-based defenses, and apply “just-enough” monitoring to their network. However, the network can be one of the best places to not only defend against the attacker, but also observe and understand their capabilities.In this talk, we’ll examine techniques with which advanced adversaries utilize your networks. Whether it’s via intricate protocol abuse, malleable traffic, or combinations of protocols to avoid standard detection, there is much to glean from an observation of network traffic. We’ll explore vulnerabilities and attack techniques that can perhaps be best detected at the network level, such as BlueKeep, an exploitation of Microsoft’s Remote Desktop Protocol and web application vulnerabilities.To help our audience discover just how impactful proper network defenses can be, we’re going to emulate common techniques, followed by a detailed explanation of each attack. Furthermore, we’ll outline specific steps that would have detected and stopped the malicious traffic. Our goal, by the end of the session, is for our attendees to have a solid understanding of how the attacks work and what they need to do to protect themselves.