Bro
From charlesreid1
Initial Notes
Intrusion detection system.
Bro training has pcaps with samples of things like malware hiding shells in HTTP traffic. For example, this folder has some pcaps containing traffic from a yayih trojan:
More info:
Hat tip:
Returning Notes
Returning to this: how do you utilize outlier detection, unsupervised learning, and classification to improve networking benchmarks and differentiation of traffic? (Or maybe that's what bro actually does in the first place.)