YoVDO

BotProbe - Botnet Traffic Capture Using IPFIX

Offered By: Security BSides London via YouTube

Tags

Security BSides Courses Cybersecurity Courses Network Analysis Courses OSI Model Courses

Course Description

Overview

Explore IPFIX and its application in botnet traffic capture through the BotProbe project in this 42-minute Security BSides London conference talk. Delve into the advantages of IPFIX over traditional packet capture methods, including its ability to capture traffic across layers 3-7 of the OSI model and achieve a 97% reduction in traffic volumes. Learn about the history of NetFlow, the development of IPFIX, and how its template extensibility enhances threat detection capabilities. Discover the potential applications of IPFIX in pre-event forensics, legal traffic interception, and improved traffic analysis times. Gain insights into botnet detection algorithms, the comparison between pcap and IPFIX, and the process of adapting capture methods for network big data scenarios.

Syllabus

Introduction
Outline
Background
Packet capture
Mirroring
Three drawbacks
What are the alternatives
NetFlow
How does it work
History lesson
IPFIX
IPFIX template
IPFIX is structured
botnet detection algorithms
pcap vs IPFIX
Applications of IPFIX
IPFIX exporter
Adapt capture
Network big data
Template extensibility
Collaboration


Taught by

Security BSides London

Related Courses

Networks and Communications Security
(ISC)² via Coursera
Los bits y bytes de las redes informáticas
Crece con Google via Coursera
IT Networking Fundamentals For Complete Beginners
Udemy
Basic Network and Database Security
IBM via edX
The Complete Networking Fundamentals Course. Your CCNA start
Udemy