A Peek Inside the Black Hat Network Operations CenterThe default hotel network may be fine for a pet supply vendor conference, but Black Hat is a different story.

ByNeil J. Rubenking

This story originally appeared onPCMag

PC Mag

Every year, the Black Hat conference presents two days of briefings that reveal amazing discoveries in the security realm. Those briefings are preceded by several days of trainings -- hands-on classrooms teaching all aspects of hardware, software and network hacking (and protection against hacking). Running those classrooms on the host hotel's network would be a huge mistake, so the conference organizers necessarily set up their own, separate network. The Network Operations Center (NOC) is a product of cooperation by several different security vendors, and staffed in part by dedicated industry-veteran volunteers. Naturally the hoi polloi aren't allowed inside, but glass walls mean we can get a pretty good look.

Aamir Lakhani, Senior Security Strategist at Fortinet, gave me a quick tour. The network gets its Internet connection from the same feed as the host hotel, but other than that it's entirely separate. "The people in the classrooms are learning hacking techniques," explained Lakhani. "We don't want that on the hotel network, and we can't have the network killing their connections." He noted that the network is highly segmented, so any hacking that's not part of a training can be easily identified. James Cabe, Fortinet Senior Technical Strategist, revealed that the network's analytics indicate that 90 percent of users are connecting using aVPN, up from 60-something last year. We're learning!

Fortinet, the event's Official Hardware Provider, supplied the network switches, firewalls and classroom wireless access points, as well as some network analytics software. A large screen in one corner rotates between displaying various analytic tools. Hey, this is the NOC, but it's also a place for the vendors to show off a bit. RSA is the main security analytics provider, while wireless access in areas other than the classrooms comes from Ruckus.

我问凯布正是NOC内部的团队行为ually does with their time. He said after the grueling initial setup, they haven't needed to do much more than monitor network activity. That's not to say that connecting at Black Hat is perfectly safe. If theKarma attackreported by Pwnie Express hits, you're not on the Black Hat network. In the event of any network breakdown or attack, they'd spring into action. A big couch in the middle of the center offers respite for team members who've been staring at screens for too long.

One large display represents the most active network segments as glowing, pulsing masses, with lines connecting them. I couldn't make head nor tail of it, but the experienced monitoring team can spot anomalous activity at a glance. Not everything in the bank of displays is quite so technical. The monitor just below the storm trooper figurine plays a continuous feed of hacker-themed movies.

The atmosphere in the Network Operations Center is an amalgam of laser-focused alertness, camaraderie, and a bit of just plain goofiness, as exemplified by this laser-eyed ape guarding the door. Cabe explained that once this event is over, the whole NOC gets broken down, packed for travel and shipped to the site ofBlack Hat Europe, then Black Hat Singapore, and so on.

This is, of course, a seriously high-level overview of the Black Hat Network Operations Center. You can't get a ton of technical detail by peeking through the windows. If you'd like to learn more about the technical side, check out Aamir Lakhani's blog post about theprocess of setting up the NOC at this year's Black Hat.

Wavy Line
Neil J. Rubenking

Lead Analyst for Security

Editor's Pick

Related Topics

Business News

'Treat People the Way You Want to be Treated': Pilot Goes Viral For Rant Directed at 'Selfish' Passengers

The American Airlines pilot wasn't tolerating any unruly behavior.

Money & Finance

Want to Become a Millionaire? Follow Warren Buffett's 4 Rules.

企业家是不能过度指狗万官方望太多a company exit for their eventual 'win.' Do this instead.

Marketing

3 Insights About Sales Teams and Buyers That Will Help Your Content Break Through

In challenging economic situations, it's critical to understand buyers' priorities and create engaging content that resonates with their needs.

Growing a Business

Are You Guilty of Poor Onboarding? The Consequences Are Worse Than You Think.

The onboarding process has a profound effect on your employee satisfaction, retention and productivity. Harness these actionable strategies to optimize your onboarding process, ensuring a smooth transition for new hires.

Marketing

On-page SEO vs. Off-Page SEO vs. Technical SEO — Here's How to Properly Optimize Each

These SEO types form a comprehensive strategy that's crucial for increasing a website's visibility and ranking in search engine results, which can lead to higher traffic and potential conversions.

Business News

Chinese Zoo Denies That Bear in Enclosure Is Really a Human in Costume

The bear has created a frenzy on social media.