Ignacio Arnaldo
Navn
Detecting network beaconing with machine learning and Zeek logs
Beskrivelse

We will introduce a robust approach to detect network beaconing across DNS, SSL, and HTTP using Zeek logs. We will start by analyzing patterns exhibited by C2 frameworks such as Meterpreter, Empire, Sliver, or Caldera. The wide range of observed behaviors will motivate a machine learning approach that consists in a) generating synthetic data that accounts for different beaconing frequencies, jittering, and latencies, and b) training a Convolutional Neural Network that analyzes the intervals between activities. Finally, we will showcase real-world detections and equip the audience with all the tools needed to apply the approach to their data.
 

Dato & Tid
onsdag den 1. maj 2024, 15.30 - 16.00
Sal
Sal 4
Udstiller
Corelight

Slides fra seminaret vil være synlige på denne side, hvis den pågældende taler ønsker at dele dem. Bemærk venligst, at du skal være logget ind for at se dem.