4.9 • 696 Ratings
🗓️ 4 April 2025
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Friday, April 4th, |
0:03.2 | 2025 edition of the Sands and at Storm Center's Stormcast. |
0:08.8 | My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida. |
0:13.5 | Today we got another diary from one of our undergraduate interns. |
0:18.8 | Gregory Weber did talk about while analyzing |
0:22.8 | URLs collected by Honeypots and how to identify malicious traffic and distinguish it from |
0:31.1 | normal traffic to a web application. Of course, Honeypots, by definition, really only get |
0:37.1 | malicious requests. |
0:39.0 | So Gregory did compare it to data from a normal website. |
0:44.2 | There's some frequency analysis on it and actually came up with a model that looks |
0:50.4 | reasonably good in distinguishing attacks from non-attacks. |
0:55.0 | I think still needs a little bit of refinement and maybe more data really to validate it well, |
1:01.3 | but it's an interesting approach and there, of course, is a lot of work happening currently |
1:07.6 | doing sort of some more automated log analysis, automated intrusion detection |
1:12.8 | using some of these machine learning techniques. |
1:17.7 | And the next story falls in the category never underestimate the creativity of a sophisticated attacker. |
1:25.5 | In this example, it's a critical vulnerability in Evandi Connect |
1:31.4 | Secure. It was patched in February. It's a buffer overflow, but exploitation is quite |
1:39.6 | constrained for that buffer overflow. So Ivanti initially assessed that this particular |
1:46.6 | vulnerability is not exploitable. Well, they were proven wrong now, apparently, by some |
1:54.0 | actor that may be associated with some Chinese state actors. According to Mandyant, who wrote about it, |
2:03.5 | it looks like they reversed the patch, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.