The 10th Annual Black Hat USA Network Operations Center (NOC) Report

Unknown

Black Hat USA 2024 · Day 1 · Briefing

Overview

This talk provides an introductory look into the Black Hat USA Network Operations Center (NOC) report, a crucial annual presentation that details the operational and security landscape observed during one of the world's most prominent cybersecurity conferences. While the provided transcript focuses heavily on the team, its operational philosophy, and the rigorous selection process for its technology partners, it sets the stage for what is typically a deep dive into the unique challenges and threat intelligence gathered from securing a highly dynamic and often adversarial network environment.

Watch on YouTube

Visual summary for The 10th Annual Black Hat USA Network Operations Center (NOC) Report by Unknown
Visual summary for The 10th Annual Black Hat USA Network Operations Center (NOC) Report by Unknown

Key moments

  1. 0:00 Introduction of speakers and Black Hat NOC history
  2. 1:48 Introducing the massive Black Hat NOC team
  3. 2:00 Inside the NOC: environment, culture, and 'grift'
  4. 2:31 Clarifying Black Hat NOC partners vs. sponsors
  5. 3:15 Appreciating the dedication of partner leads
  6. 3:41 Rigorous product selection: NOC acts like customers

The 10th Annual Black Hat USA Network Operations Center (NOC) Report

Speakers: Neil Wiler (Griffter), VP of Defensive Services, Colefire; Bart Stump, Managing Principal, Colefire

Conference: Black Hat USA

YouTube: https://www.youtube.com/watch?v=63bUI-2APY4

Overview

This talk provides an introductory look into the Black Hat USA Network Operations Center (NOC) report, a crucial annual presentation that details the operational and security landscape observed during one of the world's most prominent cybersecurity conferences. While the provided transcript focuses heavily on the team, its operational philosophy, and the rigorous selection process for its technology partners, it sets the stage for what is typically a deep dive into the unique challenges and threat intelligence gathered from securing a highly dynamic and often adversarial network environment.

The presentation is delivered by seasoned cybersecurity professionals Neil Wiler, known as Griffter, and Bart Stump, both holding leadership positions at Colefire. Their extensive experience, particularly Griffter's 22-year tenure with the Black Hat NOC and Bart's 16 years, underscores the institutional knowledge and dedication behind this critical operation. The annual NOC report is highly anticipated by the security community as it offers unparalleled insights into real-world attack vectors, emerging threats, and the efficacy of defensive strategies in a high-stakes, real-time scenario.

The significance of the Black Hat NOC report extends beyond merely recounting incidents; it serves as a vital educational resource for network defenders, security architects, and incident response teams worldwide. The data collected from such a unique "live fire" environment helps shape best practices, inform product development, and refine threat intelligence. By sharing their experiences and findings, the NOC team contributes significantly to the collective cybersecurity posture of the broader industry, making the annual report a cornerstone event at Black Hat USA.

Background

▶ Watch: Introduction of speakers and Black Hat NOC history (0:00)

The Black Hat USA conference is a premier gathering for information security professionals, researchers, and hackers, attracting thousands of attendees annually. This concentration of highly skilled individuals, many of whom are actively exploring and testing the boundaries of network security, creates an exceptionally challenging and dynamic environment for network operations and security. The Network Operations Center (NOC) is the dedicated team responsible for designing, deploying, and maintaining the conference network, while simultaneously monitoring it for malicious activity, ensuring stability, and responding to any incidents that arise.

The existence of an "Annual NOC Report," now in its 10th iteration, highlights a long-standing commitment to transparency and knowledge sharing within the security community. The NOC's work is not just about keeping the lights on; it's about providing a secure, reliable, and performant network experience for attendees, speakers, and exhibitors, all while understanding that the network itself is a target. This unique context necessitates a robust and adaptive security posture, continually evolving to counter the sophisticated threats present.

A key aspect of the Black Hat NOC's operational philosophy, as emphasized by the speakers, is its independence and integrity in technology selection. Unlike typical conference setups, the NOC explicitly states that partners "do not pay to come into the NOC." Instead, the team, led by individuals like Griffter, Bart Stump, and Principal Architect Steve Fink, meticulously evaluates security technologies by acting as genuine customers. This involves reviewing products, attending demos on the expo floor, and conducting thorough Zoom meetings to assess capabilities. Only technologies deemed the "best fit" for the NOC's specific needs are deployed. This rigorous, vendor-agnostic selection process ensures that the tools and platforms used are chosen purely for their technical merit and operational effectiveness, rather than commercial interests, thereby enhancing the reliability and trustworthiness of the network's security infrastructure. The "problem" that the Black Hat NOC effectively addresses is the need for an enterprise-grade, highly resilient, and defensible network in an environment where sophisticated adversaries are both present and, at times, actively engaged in probing activities.

Key Findings

▶ Watch: Inside the NOC: environment, culture, and 'grift' (2:00)

The provided transcript for "The 10th Annual Black Hat USA Network Operations Center (NOC) Report" primarily focuses on the introductions of the speakers, the composition of the NOC team, and the operational philosophy behind their technology selection process. Unfortunately, it does not contain any specific key findings, results, or contributions related to the network security data, observed threats, or performance metrics that would typically be presented in an annual NOC report.

A Black Hat NOC report traditionally details crucial insights such as:

  • The volume and types of malicious traffic detected.
  • Specific attack vectors and exploit attempts observed.
  • Performance statistics of the network, including bandwidth utilization and latency.
  • Identified vulnerabilities or misconfigurations exploited by attendees (ethical or otherwise).
  • The effectiveness of deployed security controls and incident response procedures.
  • New threat intelligence derived from the unique conference environment.

Without this information in the transcript, it is impossible to enumerate the main discoveries or results of the 10th Annual Black Hat USA NOC Report. The talk, as captured in this excerpt, serves as an essential preliminary, highlighting the dedicated team and the robust, independent process by which the network's foundational security technologies are chosen, but it does not delve into the actual report content.

Technical Deep Dive

▶ Watch: Clarifying Black Hat NOC partners vs. sponsors (2:31)

The provided transcript, while outlining the significant effort and rigorous selection process behind the Black Hat NOC's operations, does not include a technical deep dive into the specific code, protocols, architectures, or security tools utilized or analyzed during the 10th Annual Black Hat USA conference. The speakers emphasize the importance of their technology partners and the stringent, customer-like evaluation process they undergo to ensure the best fit for the network's needs. This process involves evaluating various devices and software, but the transcript does not name these specific technologies or detail their implementation.

Typically, a technical deep dive in a NOC report would cover:

  • The network architecture itself, including segmentation, routing protocols, and wireless infrastructure.
  • Specific security solutions deployed, such as firewalls, Intrusion Detection/Prevention Systems (IDS/IPS), Endpoint Detection and Response (EDR), Security Information and Event Management (SIEM) systems, and network visibility tools.
  • Details on how threat intelligence feeds are integrated and utilized.
  • Any custom scripts or automation developed by the NOC team for monitoring or response.
  • Analysis of specific vulnerabilities or exploit techniques observed on the network, potentially including packet captures or log snippets.

While the transcript highlights the NOC's commitment to selecting effective technologies through acting "like customers" and conducting thorough reviews, it stops short of revealing the technical specifics of these chosen solutions or the underlying network design that secures the Black Hat environment. The focus remains on the organizational and philosophical aspects of running the NOC rather than the granular technical implementation or the observed technical security incidents.

Demo / Proof of Concept

▶ Watch: Appreciating the dedication of partner leads (3:15)

The provided transcript for "The 10th Annual Black Hat USA Network Operations Center (NOC) Report" is solely introductory in nature, focusing on speaker introductions, team composition, and the operational philosophy of the NOC. Consequently, there is no mention or description of any demonstration or proof of concept being presented during this segment of the talk.

Typically, a NOC report might include demonstrations of:

  • How specific attacks were detected in real-time using their monitoring tools.
  • The functionality of custom dashboards or visualization tools developed by the team.
  • The workflow of an incident response to a particular threat.
  • The impact of specific network anomalies or malicious traffic on the conference infrastructure.

However, based on the provided content, this introductory portion of the talk did not feature any such practical demonstrations. The speakers used their allotted time to introduce themselves, their team, and the foundational principles guiding the NOC's operation, preparing the audience for the detailed report that presumably followed.

Defensive Implications

▶ Watch: Rigorous product selection: NOC acts like customers (3:41)

Given the introductory nature of the provided transcript and the absence of specific key findings, technical details, or observed threats from the 10th Annual Black Hat USA NOC Report itself, it is challenging to derive concrete, talk-specific defensive implications. The transcript focuses on the process of building and running the NOC rather than the results of its operations.

However, we can infer some general defensive implications based on the operational philosophy and the inherent nature of securing a high-profile, high-risk network like Black Hat's:

  1. Prioritize Independent Technology Selection: The NOC's rigorous, non-sponsored approach to selecting security tools is a critical lesson. Defenders should evaluate products based on their technical merit and suitability for specific organizational needs, acting as "customers" rather than being swayed by vendor marketing or sponsorship deals. This ensures that the most effective solutions are deployed, free from commercial bias.
  2. Invest in a Dedicated, Skilled Team: The emphasis on a "massive team" of dedicated professionals, including technical associates and partner leads, highlights the human element of cybersecurity. Organizations must invest in building and nurturing skilled security teams (like a Security Operations Center - SOC), providing them with the resources and autonomy to effectively monitor and defend their networks.
  3. Embrace a Proactive and Adaptive Security Posture: The Black Hat network is described as "very active," with attendees "poking at things." This mirrors real-world enterprise environments where threats are constant and evolving. Defenders must adopt a proactive stance, continuously monitoring for anomalies, anticipating threats, and adapting their defenses rather than relying on static security measures.
  4. Value Real-World Operational Experience: The long tenure of speakers like Griffter (22 years) and Bart (16 years) in the Black Hat NOC underscores the invaluable nature of hands-on operational experience. Organizations should foster environments where security professionals can gain practical experience, learn from real incidents, and contribute to the collective knowledge base.
  5. Understand the Value of Network Visibility and Monitoring: Although not explicitly detailed, the existence of a NOC implies extensive network visibility and monitoring capabilities. Defenders must ensure they have comprehensive logging, traffic analysis, and anomaly detection systems in place to identify and respond to threats effectively.
  6. Foster Collaboration and Knowledge Sharing: The mention of partners and a large team working together emphasizes the importance of collaboration. Within an organization, security teams should collaborate closely with IT, development, and business units. Externally, participating in and learning from community reports like the Black Hat NOC report can provide critical external threat intelligence.

While the transcript doesn't offer specific attack patterns or vulnerabilities to defend against, it strongly advocates for the foundational principles of a robust security program: a skilled team, independent technology selection, continuous monitoring, and a proactive, adaptive mindset. These are universal truths for effective cybersecurity defense in any environment.

Key Takeaways

  • The Black Hat USA Network Operations Center (NOC) is managed by a large, dedicated team of experienced professionals and technical associates, many of whom volunteer their time.
  • Technology partners and their equipment are selected based purely on technical merit and suitability for the NOC's needs, not through sponsorship or payment.
  • The NOC team rigorously evaluates security products by acting as a genuine customer, reviewing demos and capabilities to ensure the "best fit" for the conference network.
  • Securing the Black Hat network is a highly active and dynamic challenge, requiring constant monitoring and engagement from the NOC team.
  • The overall sentiment among the NOC team is one of passion for security, with speakers expressing genuine enjoyment for their work in this high-stakes environment.

About the Speaker(s)

The talk was presented by two highly experienced cybersecurity professionals:

Neil Wiler, widely known in the information security and hacker community by his handle Griffter, is the VP of Defensive Services for Colefire. He is a veteran of the Black Hat NOC, marking this his 22nd year contributing to the operation, and has worked alongside Bart Stump for 16 of those years. Beyond Black Hat, Griffter is also the department head for Conscience and events at Defcon, another major hacker conference. His extensive background includes speaking at conferences globally and authoring several books, underscoring his deep passion and commitment to the field of security.

Bart Stump is a Managing Principal at Colefire, working alongside Griffter. He has been involved with the Black Hat NOC for approximately 16 years. Bart also has significant experience with Defcon, having contributed for about 11 years, achieving a "gold badge" before transitioning to enjoying the conference from a different perspective. His professional and volunteer work demonstrates a long-standing dedication to securing complex networks and contributing to the cybersecurity community.

All talks from Black Hat USA 2024