BruCON 0x0A has ended
Back To Schedule
Friday, October 5 • 13:30 - 17:30
The hunt is on: Engineering the NextGen Cyber Threat Detection System. Attackers, it’s not so easy to hide anymore! FILLING

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
Limited Capacity filling up

The cyber attack landscape has changed.  Malicious adversaries continue to enhance techniques used to exploit enterprise networks.  A key ingredient missing from our cyber experts is a better way to hunt for adversarial presence.  The purpose of this talk is to show how to engineer a brand new Cyber Threat Intelligence Detection System (CTDS) and release a new frameworks called Excalibur TIE Mark I, and Themis Network Analyzer that allows investigators to better way to hunt for new threats in real-time. This technical talk dives straight in to show how to engineer the intelligence engine and create autonomous network sensors that extract and analyze thousands of artifacts both from each host machine and directly from the enterprise network.  This system develops real indicators of compromise (IOC) from large data sets and then applies these IOCs to better protect your enterprise network from new attacks.

Novel approaches are presented with algorithms used to analyze, correlate, and produce IOCs allowing the investigator to better hunt for new threats, populate uniform data sets best for information dissemination and analysis, and create new visualization graphs used for the human to derive meaning from vast amounts of data aggregation.  Finally, this talk applies everything we’ve learned and shows how to create new distributed network sensors and deploy IOCs discovered from the Threat Intelligence Engine to better protect the enterprise network.  Rest assured, lots of live demos are included in this talk.  And of course, this talk comes with a new open-source tool release for the community to use!

Attacks of tomorrow will no longer be as effective if we have the right tools to better hunt for the adversary.  This involves a new set of thinking.  Threat Intelligence will be the next paradigm in computer security.  Allow me to show you how to engineer the entire framework and deploy it on your network.

avatar for Solomon Sonya

Solomon Sonya

Solomon Sonya (@Carpenter1010) is an Assistant Professor of Computer Science at the United States Air Force Academy. He has a background in software development, malware analysis, covert channels, steganography, distributed computing, computer hacking, information protection paradigms... Read More →

Friday October 5, 2018 13:30 - 17:30 CEST
04. Orval Novotel