Packets or it didn't happen!
  • More About DNS over HTTPS Traffic Analysis - Dr. J
    Two days ago, I wrote about how to profile traffic to recognize DNS over HTTPS. This is kind of a problem for DNS over HTTPS. If you can see it, you may be able to block it. On Twitter, a few chimed in to provide feedback about recognizing DNS over HTTPS. I checked a couple […]
  • Profiling TLS Traffic to Identify DNS over HTTPS - Dr. J
    Whenever I talk about DNS over HTTPS (DoH), the question comes up if it is possible to fingerprint DoH traffic without decrypting it. The idea is that something about DoH packets is different enough to identify them. This evening after recording my podcast, I experimented a bit with this idea to see what could be […]
  • When MacOS Catalina Comes to Life: The First Few Minutes of Network Traffic From MacOS 10.15. - Dr. J
    This is continuing a post from April about network traffic from Windows 10. When dealing with network traffic, it is always good to know what is normal. As part of this series, I will investigate the first few minutes of network traffic from current operating systems. With macOS 10.15 Catalina just being released, I figured […]
  • The Weekly Zeek: DNS Cache Poisoning detection - Andy
    Recently in class, we were discussing detection strategies for DNS cache poisoning attacks. One of the ideas was to look for duplicate DNS replies to the same request. This would be pretty difficult with signature detection tools and flow data wouldn’t have enough details. Zeek would be perfect for this type of detection. Let’s write […]
  • The Weekly Zeek: Events, not packets - Andy
    One of the Zeek concepts we discuss in SEC503: Intrusion Detection In-Depth is how scripts are reacting to events, not necessarily packets. Yes, Zeek processes packets and scripts can be written to react to individual packet characteristics but this is through exposed events. A single packet may trigger one event but, more than likely, it […]

Upcoming Events

Oct 19, 2019 - Oct 24, 2019
Cairo, Egypt
Oct 21, 2019 - Oct 26, 2019
Santa Monica, CA
Dec 2, 2019 - Dec 7, 2019
London, United Kingdom
Dec 9, 2019 - Dec 14, 2019
Frankfurt, Germany
Dec 12, 2019 - Dec 17, 2019
Washington, DC
Feb 3, 2020 - Feb 8, 2020
New Orleans, LA
Feb 24, 2020 - Feb 29, 2020
Zurich, Switzerland
Feb 24, 2020 - Feb 29, 2020
Jacksonville, FL
Mar 4, 2020 - Mar 9, 2020
Louisville, KY
Mar 9, 2020 - Mar 14, 2020
Dallas, TX
Mar 16, 2020 - Mar 21, 2020
Norfolk, VA
Mar 16, 2020 - Mar 21, 2020
San Francisco, CA
Apr 5, 2020 - Apr 10, 2020
Orlando, FL
Apr 20, 2020 - Apr 25, 2020
London, United Kingdom
Apr 27, 2020 - May 2, 2020
Baltimore, MD
May 8, 2020 - May 13, 2020
San Diego, CA
May 11, 2020 - May 16, 2020
Amsterdam, Netherlands
May 17, 2020 - May 22, 2020
San Antonio, TX
Jun 8, 2020 - Jun 13, 2020
Paris, France
Jun 8, 2020 - Jun 13, 2020
Las Vegas, NV
Jan 13, 2020 - Mar 4, 2020
Online