Loading…
FloCon 2024 has ended
Wednesday, January 10 • 1:00pm - 4:30pm
Track II: Jupyter in Security: Applying Data Science Tools for Analyzing Suricata EVE

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
In this workshop, we will explore how to how to apply situational cyber security knowledge to machine learning more effectively. We will demonstrate, analyze, and explain hands-on machine learning and statistical approaches with probabilistic algorithms that can deliver results that simple deterministic approaches cannot
Managing large quantities of security data has always been challenging. There are an abundance of approaches to finding bad actors, and they all tackle different parts of the problem in different ways. In modern day dispersed, decentralized, and diverse organizational deployments and infrastructures, finding and focusing on acute incidents and breaches always benefits from two major factors: the right people with the right knowledge, and the correct tools and approaches applied to the correct subset of problems.

In this session, we will review the pros and cons of various approaches from the perspective of a security analyst and highlight their differences. The ultimate goal—catching bad guys sooner—requires an effective combination of data science coupled with a deep understanding of cyber security. We will investigate and provide practical examples of utilizing Jupyter notebooks, a data scientists tool, to analyze Suricata EVE data. We will also identify and discuss some common mistakes and misconceptions and how to more effectively apply situational cyber security knowledge to machine learning.

This workshop will use open-source tools, including Suricata, Jupyter, and Python data analysis libraries (Pandas) to apply statistical analysis of real network security event data. We will explore how actual raw Suricata EVE JSON data can be transformed for statistical analysis.

Related reading that this workshop will be based on:
https://www.stamus-networks.com/blog/jupyter-playbooks-for-suricata-part-3
https://youtu.be/hevTFubjlDQ

Requirements: Basic understanding of network protocols, TCP/IP, and IT security.

Speakers
avatar for Peter Manev

Peter Manev

QA/Training Lead, Open Information Security Foundation - OISF
Peter Manev is the co-founder and chief strategy officer (CSO) of Stamus Networks and a member of the executive team at Open Network Security Foundation (OISF). Peter has over 15 years of experience in the IT industry, including enterprise-level IT security practice. He is a passionate... Read More →


Wednesday January 10, 2024 1:00pm - 4:30pm CST

Attendees (1)