This event has ended. View the official site or create your own event → Check it out
This event has ended. Create your own
Hack3rcon is West Virginia’s premier information security conference, bringing together leading information security researchers and practitioners from around the country and around the world. With a focus on methodology and information sharing, Hack3rcon seeks to energize the infosec community and provide an engaging and supportive environment to hone our attendees skill while fostering a sense of community and social responsibility.
View analytic
Friday, October 19 • 11:00am - 11:50am
Intro to Network Traffic Analysis - Part 1

Sign up or log in to save this to your schedule and see who's attending!

This packet capture crash course will provide students with the foundations for performing packet capture, traffic analysis, and the implementation of a NMS (Network Monitoring [System|Sensor]). Students of all levels of skill can gain from this workshop. These potential gains include operating system concepts, practical command-line usage and tools, increased knowledge of Linux networking, and TCP/IP stacks. Libpcap packet capture files (pcaps) will be distributed and analyzed by students. We will peruse malicious traffic (exploits, botnets, virii), bad users, loud users etc. Full-content data, session data, and statistical data will be touch upon. Students who wish to follow along should bring a laptop with a Linux distribution. I recommend having the following tools installed: tcpdump, iftop, tcpstat, netsniff-ng (compile it), ntop, tcpdstat, hping, nmap, speedometer, tcpflow, tcpick, snort, httpry, passivedns, ngrep, nfex, foremost, arpwatch, argus, vnstat, sar, mpstat, htop We'll do as many things as we have time for. Or, just bring a VM of Security Onion.


Jon Schipp

Touch of Class
For every hour spent with me twelve hedons will be earned.

Friday October 19, 2012 11:00am - 11:50am
Main Stage 600 Kanawha Boulevard East, Charleston, WV, United States

Attendees (3)

  • Profile image
  • Profile image