ISC StormCast for Tuesday, February 14th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 14 February 2017
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, February 14th, 2017 edition of the Sansanet Storm Center's |
| 0:06.3 | Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:12.0 | If you ever looked for a way to make packet analysis simpler, there is a great new website out there, |
| 0:18.6 | packettotal.com. This site does allow you to upload a packet capture, and it will then summarize it for you |
| 0:25.9 | by running it through Pro and Suricata. |
| 0:29.5 | Now, that part you could probably do yourself, but it also creates a real nice sort |
| 0:33.6 | of graphic layout, timeline, and splits out protocols and the like to explain kind |
| 0:39.9 | of the traffic for you that it found in the packet capture. A real nice site. I highly recommend |
| 0:46.0 | that you give it a spin. Of course, do not upload any confidential information to it. All data |
| 0:51.9 | that you upload to the site is being shared. |
| 0:55.7 | With more and more websites implementing TLS, I think the latest numbers are more than 50% of |
| 1:01.4 | traffic is taking advantage of some form of TLS or SSL. It has become more and more important, |
| 1:09.4 | of course, to inspect that traffic and one route many |
| 1:13.9 | organizations take is to use proxies to intercept TLS. |
| 1:19.3 | Rob wrote a diary summarizing some of the lessons that he learned when he implemented a system |
| 1:24.5 | like that. |
| 1:25.7 | For example, what sites to whitelist and what type of |
| 1:30.5 | TLS you will not be able to intercept without breaking applications. |
| 1:35.7 | For example, if certificate pinning is in place and the like, then of course the application |
| 1:42.2 | will be able to figure out that it's being intercepted and it may no longer work. |
| 1:48.5 | So if you're planning to do that, take a look at Rob's diary and of course. |
| 1:53.3 | I think a month ago I had a webcast with some of the techniques and such you can use to inspect TLS traffic |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

