From charlesreid1

Revision as of 05:04, 18 April 2017 by Admin (talk | contribs) (→‎Notes)

Initial Notes

Intrusion detection system.

Bro training has pcaps with samples of things like malware hiding shells in HTTP traffic. For example:

Hat tip:

Notes

How would you integrate outlier detection, unsupervised learning, and classification algorithms to improve networking benchmarks and differentiation of traffic?

What does Bro do "under the hood" and how can that be improved by machine learning?