YoVDO

Early Detection of Malicious Patterns in Event-Streaming Data

Offered By: nullcon via YouTube

Tags

nullcon Courses Cybersecurity Courses Machine Learning Courses Deep Learning Courses Threat Detection Courses Mitre Att&ck Framework Courses

Course Description

Overview

Explore advanced techniques for detecting malicious patterns in event-streaming data in this 50-minute conference talk from nullcon Goa 2019. Delve into the challenges of identifying adversarial activity using behavioral indicators rather than static indicators of compromise. Learn about tools for hunting known complex behavioral patterns and discover a deep learning approach for automatically uncovering behavioral patterns from event logs. Gain insights from Hyrum Anderson, Chief Scientist at Endgame, as he discusses the importance of early detection, the use of machine learning on sequence data, and model design considerations including features, embedding, recurrent networks, and conviction patterns. Examine the effectiveness of these methods through analysis of false positives and negatives, and understand the broader implications for information security and situational awareness.

Syllabus

Intro
CONTEXT
EQL BY EXAMPLE
SEQUENCES: ORDER MATTERS
THE DREAM: SEMI-AUTOMATIC
MACHINE LEARNING ON SEQUENCE DATA
MODEL DESIGN: FEATURES
MODEL DESIGN: EMBEDDING
MODEL DESIGN: RECURRENT
MODEL DESIGN: CONVICTION
PATTERN EARLINESS?
UPDATED MODEL SUMMARY
LEARNED PATTERNS?
FALSE NEGATIVE
FALSE POSITIVE
STEP BACK: WHAT HAVE WE DONE?


Taught by

nullcon

Related Courses

Unearthing Malicious and Risky OpenSource Packages Using Packj
nullcon via YouTube
Pushing Security Left by Mutating Byte Code
nullcon via YouTube
The Faces of MacOS Malware - Detecting Anomalies in a Poisoned Apple
nullcon via YouTube
Contextomy - Let's Debug Together
nullcon via YouTube
Mind The Gap - The Linux Ecosystem Kernel Patch Gap
nullcon via YouTube