29.03, 9:30–10:25 (Europe/Prague), Track II
Jazyk: Čeština
Intrusion Detection and Prevention Systems don’t have to be expensive or complex. This session demonstrates how open-source tools like Suricata make network monitoring accessible for small offices, home labs, and SOHO environments using affordable hardware.
Learn practical deployment approaches, automated alerting workflows, and see a live demo showing how Suricata detects malicious activity during a phishing attack.
Intrusion Detection and Prevention Systems (IDS/IPS) are often seen as enterprise-only tools, but they don't have to be costly or complex. Open-source solutions like Suricata make network monitoring accessible for small offices, home offices (SOHO), and even personal HomeLabs—often for under €100 using everyday hardware.
In this session, we'll explore why network monitoring is essential in these environments, especially for incident response, where traditional endpoint logs (antivirus, Windows events) are frequently insufficient or already deleted. We'll cover affordable deployment options, including managed switches or MikroTik routers for traffic mirroring, and low-power devices like thin clients to run Suricata alongside lightweight SIEM tools. You'll see a live setup on Alpine Linux, with automated pipelines for log collection, analysis, and real-time alerts sent via webhooks to Discord, Telegram, Slack, or Teams.
The session wraps up with a quick demo of a phishing attack involving malware, showcasing how Suricata detects and notifies on malicious traffic. Join us to learn how to enhance your home or small network security without breaking the bank.
Obeznámení
Ladislav Bačo je bezpečnostný konzultant a analytik malvéru, s 15 ročnými skúsenosťami v oblastiach počítačovej bezpečnosti, informatiky a vzdelávania. Ladislav spolupracoval pri riešení bezpečnostných incidentov namierených voči kritickej infraštruktúre doma aj v zahraničí a analyzoval viacero pokročilých kybernetických hrozieb typu APT.
V súčasnosti pracuje vo firme ESET ako analytik sieťových infiltrácií. Ladislav taktiež spolupracuje s viacerými slovenskými univerzitami v oblasti kyberbezpečnosti, participuje na vzdelávacích programoch pre študentov a konzultuje bakalárske a diplomové práce.