Follow the Foolish Zebras: Finding Threats in Your Logs

Presented at DerbyCon 3.0 All in the Family (2013), Sept. 28, 2013, 3 p.m. (25 minutes)

We all know that our users do foolish things. Our normal response is to try to build stronger fences, to keep our zebra herd out of danger. Instead, what if we identify the riskiest zebras, radio-collar them, and track them to see where they go? This talk will use examples from real logs to show ideas for creatively using your log data, so your users can show you where the danger lies.


Presenters:

  • Chris Larsen
    Senior malware researcher and linguist at Blue Coat Systems. Prefers to spend time looking at traffic logs and writing code, but telling people about malware is almost as much fun. (Which has led to talks at RSA, ShmooCon, HackCon, etc.) Stopped playing World of Warcraft years ago, because it’s more fun to hunt for real Bad Guys…

Links:

Similar Presentations: