Contact BayLISA for event and ticket information.

Looks like this event has already ended.

Check out upcoming events by this organizer, or organize your very own event.

View upcoming events Create an event

BayLISA March Special Event

Thursday, March 30, 2006 from 7:00 PM to 9:30 PM (PT)

Sunnyvale, CA

Ticket Information

Type End     Quantity
All Ended Free  
SHARE THIS EVENT

Event Details

NSM and Argus Rik Farrow

Network Security Monitoring is a technique developed by Richard Bejtlich (The Tao of Network Security Monitoring, AW 2004). In brief, NSM means to capture network traffic four different ways, to provide a security analyst with the greatest, and most useful, amount of informantion for analyzing security incidents that involve the monitored networks.

In this presentation, I will outline how NSM works, its benefits, then focus on the one tool that Richard recommends using even if the rest of the system gets ignored. Argus is a session data collector, a tool that collects packet headers and converts them into succinct transaction records. Argus allows you to see which IP addresses communicate, how much data was sent, the ports used, and TCP states for the transaction. While argus itself is easy to use, it produces binary output which must be translate using ra (report argus). You can even start using argus after an incident has occurred, because the network traces will help you to identify involved hosts.

I will demonstrate argus and show how you can use ra to uncover compromised hosts in your networks.

The talk will end with some slides and discussion about the future of computer security.

When & Where



Yahoo Inc!
Bldg C. Classroom 5
701 First Avenue
Sunnyvale, CA 94089

Thursday, March 30, 2006 from 7:00 PM to 9:30 PM (PT)


  Add to my calendar

Hosted By

BayLISA



BayLISA includes system and network administrators across a range of skill levels. BayLISA meets monthly to discuss topics of interest to administrators and managers of sites supporting more than 100 users and/or computers. blw@baylisa.org to contact event coordinators.