Conducting Defensive Information Warfare
- n
Conducting Defensive Information Warfare on Open Platforms 23rd - - PowerPoint PPT Presentation
Conducting Defensive Information Warfare on Open Platforms 23rd October 2013 LinuxCon Europe Ben Tullis (formerly of) LinuxIT (Europe) Ltd. Ben Tullis - Background Professional Linux sysadmin (etc.) for 12+ years Worked in
–
–
–
–
–
–
–
e.g. espionage, identity theft, physical theft
e.g. sabotage, denial of service, physical theft
–
–
–
e.g. Disable ”Large Receive Offload” and ”Generic Receive Offload” on the collector:
– Implement WPA2-Enterprise
– Implement IEEE 802.11w
– A Rogue Access Point – A De-Authentication Attack
Legitimate Clients
ncsource=drone1:host=10.10.100.1,port=2502 ncsource=drone2:host=10.10.100.2,port=2502 alert=APSPOOF,10/min,1/sec apspoof=Tullix:ssid="Tullix",validmacs="00:11:22:33:44:55,AA:BB:CC:DD:EE:FF" allowplugins=true ncsource=drone1:host=10.10.100.1,port=2502 ncsource=drone2:host=10.10.100.2,port=2502 alert=APSPOOF,10/min,1/sec apspoof=Tullix:ssid="Tullix",validmacs="00:11:22:33:44:55,AA:BB:CC:DD:EE:FF" allowplugins=true
ncsource=wlan0:drone1:channellist=Tullix dronelisten=tcp://10.10.100.1:2502 droneallowedhosts=10.10.0.1 ncsource=wlan0:drone1:channellist=Tullix dronelisten=tcp://10.10.100.1:2502 droneallowedhosts=10.10.0.1
ncsource=drone1:host=10.10.100.1,port=2502 ncsource=drone2:host=10.10.100.2,port=2502 alert=DEAUTHFLOOD,5/min,2/sec alert=BCASTDISCON,5/min,2/sec allowplugins=true ncsource=drone1:host=10.10.100.1,port=2502 ncsource=drone2:host=10.10.100.2,port=2502 alert=DEAUTHFLOOD,5/min,2/sec alert=BCASTDISCON,5/min,2/sec allowplugins=true
– Nfdump tool-set
– NfSen web-interface
– Custom Correlation Engine – Custom web framework
Thanks to Creative Commons:
emote-logon-to-help-find-laptop-thief
ction-92052
liday-bundle
h-voice-control
y-ever
r-attacks-could-cause-global-catastrophe.html
e_2012.png
2-quickstart/
nstaller-Kibana-par-Puppet-partie-1
net/fail2ban-month.png
Explicit Permission Granted: