Return to schedule

Aggressive use/distribution of IoCs (IPv4/IPv6) Feedback

Aggressive use/distribution of IoCs (IPv4/IPv6) ... to block ingress/egress at the perimeter. We will show that we can block around 40% of ALL ingress on a "normal" ISP-hosted VPS in the cloud. Discussing the benefits of this approach.

  • L2 is a much "cheaper" layer vs. L7 (NGFW)
  • Apps on DMZ and LAN are getting offloadet. No CPU cycles wasted to run bad injections.
  • Clients are blocked on egress to IoCs. #ransomwaremuch
  • We are extremely aggressive regarding frequency - updates every 10 minutes.
  • 800.000 lines in current signature list ... If time permits ... we do the same with DNS.


Speakers for Aggressive use/distribution of IoCs (IPv4/IPv6):


Metadata for Aggressive use/distribution of IoCs (IPv4/IPv6)

To be recorded: No

URLs for Aggressive use/distribution of IoCs (IPv4/IPv6)

No URLs found.


Schedule for Aggressive use/distribution of IoCs (IPv4/IPv6)

  • Thursday, Jul 18th, 2024, 14:00 (CEST) - Thursday, Jul 18th, 2024, 15:00 (CEST) at Speakers Tent