From charlesreid1

Revision as of 03:40, 14 March 2017 by Admin (talk | contribs)

Initial Notes

Intrusion detection system.

Bro training has pcaps with samples of things like malware hiding shells in HTTP traffic. For example, this folder has some pcaps containing traffic from a yayih trojan:

More info:

Hat tip:

Returning Notes

Returning to this: how do you utilize outlier detection, unsupervised learning, and classification to improve networking benchmarks and differentiation of traffic? (Or maybe that's what bro actually does in the first place.)