SLIDE 1
DHCP Rework in Bro 2.6
Seth Hall Corelight
DHCP Rework in Bro 2.6 Seth Hall Corelight Why Tackled? Why - - PowerPoint PPT Presentation
DHCP Rework in Bro 2.6 Seth Hall Corelight Why Tackled? Why Tackled? Log wasnt great. Purely based on DHCP ACK messages. No tie together between assigned IP address and MAC address. Load balancing issues Mix of broadcast
Seth Hall Corelight
address.
load balancing.
Refine and extend case (switch) Define a case with no values up front
Worker Worker Worker Worker Worker Worker Manager DHCP::aggregate_msgs
Client Server discover
request ack
One Log Entry!
compatibility script for scripts that haven’t been updated.