Staring Into The Abyss

Staring Into The Abyss



Published by dan@doxpara.com

Published by: dan@doxpara.com on Mar 22, 2009
Copyright:Attribution Non-commercial


copyright IOActive, Inc. 2006, all rightsreserved.
Staring Into The AbyssRevisiting Browser vs. MiddleboxAttacks In The Era Of Deep PacketInspectionDan KaminskyDirector of Penetration TestingIOActive, Inc.
Hi! I’m Dan.Once upon a time, my talks were referred to as“Black Ops of TCP/IP” –These were fun talks! –Lets do more of that!
Context: The Rise of DPI
Deep Packet Inspection: The attempt to extract endpoint contextfrom network traffic –This is always an attempt – only a very small percentage of what’s going on, hits the wire –Admittedly, an important percentage
DPI is on the verge of a revolution –Hardware is getting much faster Can be deployed at carrier network head ends –Software is getting much deeper Can extract full GMail messages from a series of differentialAJAX updates (Narus) –Need (well, demand) is increasingLegitimate – DDoS mitigation, larger scale firewalling, etc.

