Aggressive use/distribution of IoCs (IPv4/IPv6)
Feedback
Aggressive use/distribution of IoCs (IPv4/IPv6) ... to block ingress/egress at the perimeter. We will show that we can block around 40% of ALL ingress on a "normal" ISP-hosted VPS in the cloud. Discussing the benefits of this approach.
- L2 is a much "cheaper" layer vs. L7 (NGFW)
- Apps on DMZ and LAN are getting offloadet. No CPU cycles wasted to run bad injections.
- Clients are blocked on egress to IoCs. #ransomwaremuch
- We are extremely aggressive regarding frequency - updates every 10 minutes.
- 800.000 lines in current signature list ... If time permits ... we do the same with DNS.
Speakers for Aggressive use/distribution of IoCs (IPv4/IPv6):
Metadata for Aggressive use/distribution of IoCs (IPv4/IPv6)
To be recorded: NoURLs for Aggressive use/distribution of IoCs (IPv4/IPv6)
No URLs found.
Schedule for Aggressive use/distribution of IoCs (IPv4/IPv6)
- Thursday, Jul 18th, 2024, 14:00 (CEST) - Thursday, Jul 18th, 2024, 15:00 (CEST) at Speakers Tent