Hands-on Workshop on Network Security
Tuesday, August 11
Thursday, August 13
8:30 AM - 12 PM (EDT)
Online
Organizers
University of South Carolina (USC)
Overview
This workshop introduces Zeek and P4-DPDK as complementary technologies for developing high-performance cybersecurity and network security applications. Participants will learn how to leverage Zeek for network security monitoring and P4-DPDK for programmable packet processing to implement scalable detection, filtering, and traffic analysis solutions through a combination of hands-on exercises.
Audience
This workshop is intended for cybersecurity practitioners, network engineers, researchers, students, and developers interested in network security, programmable data planes, and high-performance packet processing.
Outcomes
By the end of this tutorial, attendees will gain:
- An understanding of network security monitoring using Zeek and programmable packet processing with P4-DPDK.
- Familiarity with developing cybersecurity applications for traffic analysis, intrusion detection, packet filtering, and attack mitigation.
- Practical experience implementing and evaluating network security solutions through hands-on labs using Zeek and P4-DPDK.
Pre-requisites
Participants should have a basic understanding of computer networking and Linux. Internet connectivity and a web browser are required to access the online laboratory environment. Accounts for USC's NETLAB platform will be provided for the hands-on exercises.
Agenda
Day 1: Tuesday, August 11 - Zeek IDS & ARP Spoofing Detection
| Time (ET) | Topic | Presenter |
|---|---|---|
| 8:30 - 8:35 | Welcome and Agenda Overview | Sergio Elizalde |
| 8:35 – 9:05 | Introduction to Zeek IDS [PDF, PPT] | Jorge Crichigno, Sergio Elizalde |
| 9:05 – 9:15 | Break | |
| 9:15 – 10:15 | Lab 1: Introduction to Zeek [PDF, PPT] | Sergio Elizalde |
| 10:15 – 10:25 | Break | |
| 10:25 – 11:55 | Lab 2: ARP Protocol Spoofing Detection [PDF, PPT] | Sergio Elizalde |
| 11:55 – 12:00 | Summary Day 1 and Q&A | |
| Survey | ||
Day 2: Thursday, August 13 - P4-DPDK & DDoS Mitigation
| Time (ET) | Topic | Presenter |
|---|---|---|
| 8:30 - 8:35 | Welcome and Day 2 Overview | Sergio Elizalde |
| 8:35 – 9:05 | Introduction to P4 & DPDK [PDF, PPT] | Jorge Crichigno, Sergio Elizalde |
| 9:05 – 9:15 | Break | |
| 9:15 – 10:30 | Lab 3: Introduction to P4-DPDK [PDF, PPT] | Sergio Elizalde |
| 10:30 – 10:40 | Break | |
| 10:40 – 11:55 | Lab 4: Limiting SYN Flood via Probabilistic Packet Dropping [PDF, PPT] | Sergio Elizalde |
| 11:55 – 12:00 | Summary Day 2, Q&A and Future Directions | |
| Survey | ||