A QUICk decode
QUIC is a new transport layer protocol that is being adopted across the internet. Application protocols like HTTP/3, SMB, and DNS are using QUIC today. Security product support for QUIC is currently weak and may leave gaps in our defense. Thankfully, Wireshark now has great support for QUIC. In this talk, we'll use Wireshark to decode QUIC traffic, look at some of the usual fields, and even see how to carve files and data from QUIC traffic.
Learn more about SEC503 Network Monitoring and Threat Detection In-Depth: https://www.sans.org/u/1vtz
About the Speaker:
Andy Laman is the founder and principal consultant at A4 InfoSec, an independent consulting firm with services focusing on monitoring, detection, and incident response. Andy has more than 25 years of information technology and security experience in multiple industries. He has held lead security positions in Fortune 500 and several global companies. Andy is a course contributor and teaches SEC503: Network Monitoring and Threat Detection In-Depth, for the SANS Institute. In addition to the CISSP, Andy holds multiple GIAC certifications including the prestigious GIAC Security Expert (GSE #142) certification as well as multiple other industry certifications.