IDS Comparisons with DShield Honeypot Data, (Thu, Jul 6th)

An Intrustion Detection System (IDS) can be helpful to identify suspicious activity. The information recieved from these tools needs to be tuned to the environment so the tool can highlight what is unusual. When looking at honeypot data, it is anticipated to see internet scanners and malicious traffic. What&#;x26;#;39;s the point of looking at IDS data for a honeypot? Well, it can be useful to test and IDS or compare different IDS tools. In my lab environment, network data is captured and analyzed with Suricata[1] (via Corelight[2]) and is also behind a Palo Alto[3] firewall.

Continue reading IDS Comparisons with DShield Honeypot Data, (Thu, Jul 6th)→

Posted in Uncategorized

Controlling network access to ICS systems, (Mon, Jul 3rd)

After 6 years, I have returned to the world of operating technologies. One of my main concerns at that time regarding the use of new technologies was to seek access control via the network to the different devices that make it up, because unlike the world of information technologies where access is sought to be widespread and there are multiple ways to perform access control at the application and network level, the world of industrial control has limitations depending on the version of the supervision and control protocols that are supported.

Continue reading Controlling network access to ICS systems, (Mon, Jul 3rd)→

Posted in Uncategorized

DShield pfSense Client Update, (Fri, Jun 30th)

The SANS Internet Storm Center (ISC) developed the DShield pfSense client in 2017 [1] to support the ingestion of pfSense firewall logs into the DShield project. The pfSense project has also evolved over the years, with some changes in the offerings [2]. With the advent of pfSense Community Edition (CE) 2.7.0 [3, 4] and pfSense Plus 23.01, updates to the DShield client were required to fix unintended issues.

Continue reading DShield pfSense Client Update, (Fri, Jun 30th)→

Posted in Uncategorized

Kazakhstan – the world’s last SSLv2 superpower… and a country with potentially vulnerable last-mile internet infrastructure, (Wed, Jun 28th)

In my last Diary, we looked at internet-connected web servers, which still support SSL version 2.0. Since this cryptographic protocol was deprecated all the way back in 2011, one might not think that there would be many such devices left on the internet, nevertheless, we have shown that there still appear to be over 460,000 of them[1].

Continue reading Kazakhstan – the world’s last SSLv2 superpower… and a country with potentially vulnerable last-mile internet infrastructure, (Wed, Jun 28th)→

Posted in Uncategorized