Implementing custom security frameworks with Bro

Oct. 8, 2017 0 comments ADMIN Magazine Detection & Response firewall kali security

Bro [1] is high-quality security monitoring tool designed to discover and analyze traffic trends on your network. Bro provides in-depth analysis of network traffic without limiting itself to traditional signature-based approaches. I first heard about the Bro network security monitoring framework when a consultant friend of mine talked about melding the world of big data and security together. My friend believed that traditional signature-based intrusion detection and monitoring simply wasn't enough to ensure a secure network. The problem with networks is that, because of the increased number of devices, services, and tools used today, it's easy for attackers to enter networks in many different ways. Ransomware, botnets, malware, and remote control tools are readily available. Social engineering is especially prevalent now. Traditional intrusion detection and perimeter security tools just aren't up to the task. Traditional monitoring tools are also having a hard time catching all of ...

http://www.admin-magazine.com/Archive/2016/35/Implementing-custom-security-frameworks-with-Bro/(t...