5 ms·
A good starting point is to set up a network tap and analyze the logs, manually. Obviously, it's one of those things that is rarely done by the people who use
by tgragnato 5y ago
A good starting point is to set up a network tap and analyze the logs, manually.
Obviously, it's one of those things that is rarely done by the people who use fancy security products.
.. because it’s hard
E.g.: Botnet traffic is often “strange” and easy to recognize
- BrandoElFollito 5y agoI am a security professional and use all kinds of fancy security products in a 100+k IP deployment. They do not do any magical stuff but the alternative is to write your own product. In a home setting, I do not see how manually analyzing the network logs can help (not to mention that most of the traffic is encrypted). You then have integrity checks on files, IOCs you need to check your files against etc. Basically this means you have to rewrite an EDR from scratch. Fancy security products are not always a way to check a box in an audit it also means using a product that you otherwise would need to either write, or put together from many pieces. Just look at wazuh (open source EDR+) and when you go past the intro you ht some hard walls (especially with updating IOCs from external sources). Security is really hard, but doing it yourself is really, really hardest.
- tgragnato 5y agoI’m pretty sure EDRs play a role in the professional protection of 100k+ IP. At home, OS and software updates combined with network monitoring should be sufficient for the more common threat models. One needs to draw a line somewhere. EDRs are complex and often fail to protect business systems when professionally managed. I do not believe it's worth wasting time on that at home.