[Bro] Yet Another Conference - like no other :)
lysemose at gmail.com
Mon Oct 21 05:15:03 PDT 2013
Cool to see some real world experiences... Especially the part "what's
working" and "what's not working".
On Sat, Oct 19, 2013 at 1:19 PM, Michal Purzynski <michal at rsbac.org> wrote:
> On 10/18/13 7:38 PM, Kristoffer Björk wrote:
> Great presentation!
> Do you use security onion for the bro & snort clusters or you installed it
> on vanilla linux/bsd boxes?
> It's all Security Onion, tuned to our needs. That's the power of SO -
> it's so flexible you can enable/disable/change parts of it without
> impacting the rest. I can't imagine doing all the integration that SO does,
> myself. Technically doable, but -ENOTIME :)
> On Fri, Oct 18, 2013 at 12:52 PM, Michal Purzynski <michal at rsbac.org>wrote:
>> On 10/14/13 2:09 PM, James Lay wrote:
>> > On Oct 14, 2013, at 5:03 AM, Michal Purzynski <michal at rsbac.org> wrote:
>> >> Yes. I'm from Mozilla. Now you know :)
>> >> Slides from my recent talk about NSM @ Mozilla at YaC 2013 are here, a
>> >> full video will hopefully follow.
>> >> http://tech.yandex.ru/events/yac/2013/talks/1131/
>> >> Happy to answer questions, share experience, etc. Note it's an emerging
>> >> project and I expect new servers to be shipped this week, so far using
>> >> whatever-I-could-find in terms of CPU, but the rest matches.
>> Video is there.
>> 1. I'm not a native speaker. That's why I'm talking slower ;)
>> 2. There's quite a bit of people in the audience but the camera mostly
>> gets what's in 2-3 front rows which were reserved
>> 3. Being is the last in a day, presenting at 19:30 is hard
>> Hope it's providing some useful background on our implementation of Bro.
>> Feedback welcome :)
>> Bro mailing list
>> bro at bro-ids.org
> Bro mailing list
> bro at bro-ids.org
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Bro