Showing posts with label packet analysis. Show all posts
Showing posts with label packet analysis. Show all posts

Saturday, September 19, 2015

SilkWeb - Netflow via Webservices

 "Your  security operations or network operations tools cannot run in isolation anymore. True SOC operations is about cohesion of data." 

The common need I get from many Network & Security Operations Centers (NOC & SOC) analysts is their wish to integrate data from their various feeds into UI frameworks and dashboards.  How about NetFlow data itself, NetFlow basically is (at a minimum) a 5-tuple summary of network traffic that crosses your perimeter (firewall or router).  If your NetFlow data goes into a database there are a few tools to translate your database queries to JSON/XML and make these available over webservices.   In this blog I am introducing a project that will help expose SiLK NetFlow data over webservices JSON/XML/CSV to able to integrate SiLK data into your NOC/SOC dashboard with some basic examples. The project is in GitHub called silkweb.

Saturday, October 25, 2014

So you want to disable SSLv3?

Recent vulnerability released by Google called Poodle - puts security administrators to scramble keeping up with "heartbleed", "retiring of SHA-1" and "removal of SSLv3"  As I come from the solutions and enterprise architecture background, I get pinged by these questions about the real risk and impact of implementing these security enforcement's.

Wednesday, March 26, 2014

Rolling PCAP (Packet Capture) for a production network

It is common to see many SOCs (Security Operations Centers) wanting a packet capture of a recent event to trace down some network activity either part of an attack or an investigation.  A file format called PCAP is a good way to store network data on the disk.  However no one can afford to store PCAP forever, so a rolling packet capture depending on your network bandwidth is a very viable way to collect and store PCAP.

Friday, July 19, 2013

DNS PCAP and BPF

DNS most interesting protocol can be analyzed using some packet filters that can help you look at and analyze various types of DNS packets on the network.  In this blog, I am compiling a list of these to summarize the ones I have discovered as useful for analyzing DNS packets.  The examples are relevant to UDP DNS which is about 90-95% of DNS packets seen.