DeepSeek and Packet Analysis? Let's find out...

Поділитися
Вставка

КОМЕНТАРІ • 174

  • @ChrisGreer
    @ChrisGreer  8 днів тому +14

    With all the buzz around Deepseek AI, I threw a couple of packet captures at it to see if it could help with the analysis and find root cause. I was actually pretty happy with the results, but I still had to dig deeper and fact-check the AI analysis. Not quite there yet but close!
    You can download the first pcap and follow along here:
    github.com/packetpioneer/yout...
    If you like, please let me know!! It helps. Really.
    Want more packet goodness?
    == More On-Demand Training from Chris ==
    ▶Getting Started with Wireshark - bit.ly/udemywireshark
    ▶Getting Started with Nmap - bit.ly/udemynmap

    • @ilozeet
      @ilozeet 7 днів тому

      what did you have to fact check please

  • @tpavan
    @tpavan 7 днів тому +5

    As always, no BS, straight to the point content, Chris's videos are the best!!

    • @ChrisGreer
      @ChrisGreer  7 днів тому +2

      Thanks for the comment! 🙏

  • @JohnnyLeuthard
    @JohnnyLeuthard 6 днів тому +2

    That's pretty cool. I did this on a local copy of Deepseek and Ollama to run it local. I used a packet from created when I started got through your masterclass series. Very cool. I can see where this would be extremely helpful to help navigate a capture. I'd still look at the actual capture but a 2nd set of eyes to partner with. This is where AI has great potential.

  • @packetpulse
    @packetpulse 8 днів тому +28

    Never thought of using AI model for pcap analysis. Thank uou

    • @ChrisGreer
      @ChrisGreer  8 днів тому +4

      It’s a powerful combo, right? Thanks for watching!

    • @redlinejoes
      @redlinejoes 7 днів тому +4

      It's something we've been doing in cybersecurity for a few years. There are some interesting open-source projects from Nvidia using Morpheus and the Triton inference server. Converting to text might not be the best method, either. With the Nvidia projects, we convert to JSON, which the APIs speak natively. There's a lot of existing research and development on these topics if you're interested.

    • @packetpulse
      @packetpulse 7 днів тому +3

      @@redlinejoes you mind sharing more details pls.

    • @Mr0rris0
      @Mr0rris0 6 днів тому

      ya.... AI is not for making giraffe snakes or helping sponsored gladiator/astrologers and witches do "technomancy"
      while the old have not caught up with the new...
      the new have not caught up to the old....

  • @mytechnotalent
    @mytechnotalent 7 днів тому +3

    Chris this is fantastic! It is interesting how it can help speed up analysis however knowing the skill is essential and so fortunate for your work.

  • @Relics
    @Relics 7 днів тому +38

    One issue is that you're using the older v3 model instead of the newer reasoning (r1) model which is what deepseek blew up in popularity from. At the bottom of the input text bar you can enable the R1 Reasoning "Deepthink".
    You will likely see better and more in depth results.

    • @Relics
      @Relics 7 днів тому +6

      I recommend trying it again and seeing the difference between a normal model and a reasoning model (If any in this case.)

    • @ChrisGreer
      @ChrisGreer  7 днів тому +8

      Nice call thank you.

    • @redlinejoes
      @redlinejoes 7 днів тому +2

      It produces similar results, but sometimes, the MoE in the CoT process of the "reasoning" model will argue with itself and get stuck in a loop.

    • @whitescreen1031
      @whitescreen1031 7 днів тому +6

      I can't believe he is not aware of it as well. Almost everyone else reviewing DeepSeek online has pointed that option out, and that it is also right below the prompt field with a clear label. He seems to have just jumped right into it without actually exploring how to use it, just unbelievable! 🤣

    • @33gbm
      @33gbm 5 днів тому

      ​@@redlinejoes They are definitely not producing similar results; r1 is much more 'error-proof'

  • @Juanchicookie
    @Juanchicookie 7 днів тому +2

    Chris! This is really nice. Thank you for putting this video together for us.
    I will use it to practice and get some guidance to improve my traffic analysis skills 🤗

  • @randomized4368
    @randomized4368 6 днів тому +1

    At last one sensible expert, warning about security and privacy of deepseek👍

    • @raoultesla2292
      @raoultesla2292 6 днів тому +1

      YES ! Everyone is so exited to use the newest 'smartes' CSV file they forget who/where it reports to.

  • @raoultesla2292
    @raoultesla2292 6 днів тому

    Chris, always cutting edge, on spot, current. Nice

  • @mikulast3292
    @mikulast3292 7 днів тому

    Thank You Chris once again for your hints! Haven't been long on your channel, but glad You are still here and making very handy content. ;-)
    (literally a few years back You teached me from scratch thru your series how to read pcaps) From zero to hero BRO 👍

  • @zoren001
    @zoren001 7 днів тому +2

    Excited for the future auto AI packet analysis

  • @brodmontgomery
    @brodmontgomery 7 днів тому +1

    That was fascinating. I'm now going to go back and use the packet captures that you've supplied to us previously and experiment with DeepSeek and the other AI platforms, see if I can learn something new. Thanks.

  • @rakumarudu81
    @rakumarudu81 4 дні тому

    Thank you for great tutorial. Didn't think about Deepseek for packet debugging

  • @udhayakumars1766
    @udhayakumars1766 7 днів тому

    Thanks for keeping us up to date, this is really cool.

  • @MartinMonday-t5g
    @MartinMonday-t5g 4 дні тому

    Thanks for this Video, it's very cool to see the posibilies of AI in the IT Security!

  • @admar-nelson
    @admar-nelson 7 днів тому +1

    Good Job DeepSeek AI! one more source to get job done! and thank you Chris happy new year for you and your family

  • @freddrune8315
    @freddrune8315 7 днів тому +1

    Great video sir. I look forward to your next video.

  • @jjann54321
    @jjann54321 8 днів тому +23

    Great video as always. So the message is, "Deepseek is good, but not Chris Greer good." I can empathize with Deepseek, we do our best.

    • @ChrisGreer
      @ChrisGreer  8 днів тому +2

      haha.. one day it will be better. But for now at least it got us most of the way there. Thanks for watching and commenting!

    • @redlinejoes
      @redlinejoes 7 днів тому +1

      Better prompts produce better results. It's a skill issue, not a limitation of the model.

    • @TheGTP1995
      @TheGTP1995 6 днів тому

      ​@@redlinejoes but if you know networking you don't need to query the LLM in the first place, so no real skill issue😉

    • @redlinejoes
      @redlinejoes 5 днів тому

      ​@@TheGTP1995 Are you lost?

  • @GibsonHambleton
    @GibsonHambleton 6 днів тому

    Great video Chris. Very interesting!

  • @muhdbasheer
    @muhdbasheer 8 днів тому +1

    Amazing job, Chris.

  • @0x004
    @0x004 7 днів тому +1

    You're gonna make a packet head out of DeepSeek! Thanks for the video, great to see it!

    • @ChrisGreer
      @ChrisGreer  7 днів тому

      I'll send it the tshirt. 👍 Thanks for watching!

  • @Daniel-tb6gn
    @Daniel-tb6gn 5 днів тому

    Good video, I just discovered your channel. It will be great to see this experiment with the R1 model.

    • @ChrisGreer
      @ChrisGreer  5 днів тому

      Thanks for coming and commenting! I’m gonna do a few more of these with more models. Stay tuned! 👍

  • @AnomalousURL
    @AnomalousURL 8 днів тому

    Thanks, Chris! Great demo and information. I appreciate the insight.

  • @fabriziopelliccione6810
    @fabriziopelliccione6810 7 днів тому +2

    Hey! I am Working for SonicWall! don't blame us! ..just kidding...
    never used AI to analyze packets, will give a try!
    awesome video! as usual!
    thanks

    • @ChrisGreer
      @ChrisGreer  7 днів тому

      Hey it was just the config not the box, it's all good. I've got other pcaps that blame other vendors too... 😆

  • @Makinou
    @Makinou 7 днів тому +12

    It can be interesting if you compare the result with another AI like chatgpt to see which can be more precise in this exercise 😁

    • @ChrisGreer
      @ChrisGreer  7 днів тому +11

      Great thinking - I actually have that on my list of videos to shoot. Thanks for the comment! 👍

    • @redlinejoes
      @redlinejoes 7 днів тому

      I do this often and it's dependant on the size of model used. I run models locally and compare those to o1 for example. What's impressive is that the response from a

  • @junchaochang6962
    @junchaochang6962 8 днів тому

    good video,i always watch every video you uploaded,and i have learned lots of network knowledge especially wireshark ,thanks for your efforts

    • @ChrisGreer
      @ChrisGreer  8 днів тому

      Thank you for the comment!

  • @hamradiowithkevin
    @hamradiowithkevin 7 днів тому

    Thank you Chris, Excellent test and confirmation that AI chat bots may in fact become part of our workflow.

    • @ChrisGreer
      @ChrisGreer  7 днів тому

      I agree - I think they are going to be a very helpful tool, at least with an initial analysis!

  • @EmilioOP9
    @EmilioOP9 13 годин тому

    Amazing video and great content as always. Thank you for doing these videos.
    My two cents: could you name the files differently like 'capture1.txt' before uploading to Deepseek? This way we will know that Deepseek didn't use the file name as a clue of the issue.
    Again, thank you.

  • @ohasis8331
    @ohasis8331 7 днів тому

    Nice analysis demo.

  • @guarism0
    @guarism0 7 днів тому

    Great stuff 👍🏻
    This could be fantastic with a local DeepSeek r1 instance.

  • @thameemyousuf8194
    @thameemyousuf8194 6 днів тому

    New insights..thanks Chris

  • @EduardKhiaev
    @EduardKhiaev 7 днів тому

    as usual, amazing stuff

  • @DANNOS1993
    @DANNOS1993 8 днів тому

    Thanks!.. Didn't know you can do this with wireshark

  • @PoteRomo
    @PoteRomo 7 днів тому

    Interesting lab! Thanks for sharing!!!

  • @justus-0b3
    @justus-0b3 7 днів тому

    Thanks for the video. I wonder how it would have performed on the second capture if you had turned on deepthink for reasoning

    • @ChrisGreer
      @ChrisGreer  7 днів тому +2

      I'll try it out and see what happens!

  • @WireSharkFest
    @WireSharkFest 7 днів тому

    Awesome video! Curious to see how Qwen 2.5 would perform as well...

    • @ChrisGreer
      @ChrisGreer  7 днів тому +1

      Hmmm…. Comparison? Next vid?

  • @joeypeleg152
    @joeypeleg152 5 днів тому

    It would be very interesting in finding out with wireshark if there are leaks in a local install of Deepseek??? Important for businesses

  • @majiddehbi9186
    @majiddehbi9186 8 днів тому

    wow chris I just finish your video with D.Bombal u guys are doing a great great job, now so quick u are teeling us about deepseek THx for all the information you give

    • @ChrisGreer
      @ChrisGreer  8 днів тому

      Thanks for the feedback! Deepseek is pretty cool.

  • @Uncle_Buzz
    @Uncle_Buzz 8 днів тому

    Really fun stuff. NG AI-based IDS systems do this all day, but they don't really analyze why something didn't work, rather suspicious things.

  • @dsulvadarius
    @dsulvadarius 6 днів тому +3

    Is there any particular reason you did not click on the DeepThink (R1) button in DeepSeek's UI?

    • @defy933
      @defy933 5 днів тому

      then he wouldn't have any content for his channel lol

  • @Sparks3D
    @Sparks3D 8 днів тому

    Very cool. Would love to see some cyber security examples to see if it comes up with the correct conclusion.

    • @ChrisGreer
      @ChrisGreer  8 днів тому +1

      Great idea. On to some malware analysis!

  • @syedtaimoorhussain4626
    @syedtaimoorhussain4626 8 днів тому +6

    Would love to see the comparison with chatgpt and other AI models

    • @ChrisGreer
      @ChrisGreer  8 днів тому +5

      On it! Next up I am going to do a Deepseek vs ChatGPT vs Packet Copilot sort of thing. Thanks for the suggestion.

    • @SelvaKumar-rl5wn
      @SelvaKumar-rl5wn 7 днів тому

      Waiting...😊

    • @Wahinies
      @Wahinies 6 днів тому

      ​@@ChrisGreeryou are a gentleman and a scholar

  • @harrysearia1784
    @harrysearia1784 7 днів тому

    Get info as usual Chris. One question I have is how do you sanitize the data before submitting it?

    • @ChrisGreer
      @ChrisGreer  7 днів тому

      I use a tool called Tracewrangler. I would share a video of how to use it but I haven't made one yet! My mistake, I will get to that soon...
      www.tracewrangler.com/

    • @harrysearia1784
      @harrysearia1784 7 днів тому

      @ChrisGreer You sir, are a certified Rock Star!!!!!

  • @leoniaklebanov2502
    @leoniaklebanov2502 6 днів тому

    Awesome, idea!!!!

    • @ChrisGreer
      @ChrisGreer  6 днів тому

      Thanks for the feedback! Gonna do a few more of these.

  • @justinatwell8187
    @justinatwell8187 2 дні тому

    I know you can ask these LLMs loaded questions to get them on the right track or to sway them. I wonder if the filename affects its output, or the speed of response. Are we leading it?

  • @borisvokladski5844
    @borisvokladski5844 7 днів тому

    It could be interesting to see, if the distilled versions of Deep Seek could come to the same conclusion.

  • @aaronbanks3673
    @aaronbanks3673 7 днів тому

    Cool video!

  • @ricardotovar9035
    @ricardotovar9035 2 дні тому

    🔥🔥🔥

  • @senditall152
    @senditall152 7 днів тому +2

    I wonder if the file name helps it though.

    • @ChrisGreer
      @ChrisGreer  7 днів тому

      I was actually wondering that myself as well. I'm going to shoot another video with a different AI and see if that makes a diff. I'll post it.

    • @redlinejoes
      @redlinejoes 7 днів тому

      The file name is not as crucial for RAG as the contents. The file can be called anything. What's used in the embedding is the contents of that file. The name is far less significant than the process.

  • @augustedrifande6017
    @augustedrifande6017 8 днів тому

    Thanks 🙂.

  • @samvid1980
    @samvid1980 8 днів тому

    absorbed knowledge thanks bro

  • @Network_Engineer-w7q
    @Network_Engineer-w7q 7 днів тому

    Great video.
    Can I provide AP logs and syslogs to Deepseek and will it debug the logs and give client disconnect reasons?

  • @abdelkrimdakouan7211
    @abdelkrimdakouan7211 7 днів тому +1

    I think you just used deepseek v3 and not r1 (you need to activate it by toggling the deepthink button in the right bottom of the chat text box)

  • @namrataasati7915
    @namrataasati7915 2 дні тому

    I am following the sames you did, but deepseek not accepting the fille saying "extract only text from images and files"

  • @QEDAGI
    @QEDAGI 8 днів тому

    Very nice. Going to try it locally using ollama AND LM Studio to rate their inferences. I mean, why feed someone else when you can run your own.

    • @ChrisGreer
      @ChrisGreer  7 днів тому +1

      I'm gonna start working on my own as well... more to come and thank you for the comment!

  • @scientificodessey8889
    @scientificodessey8889 8 днів тому

    Love from Bangladesh bro.

  • @fununclenerfs
    @fununclenerfs 7 днів тому

    Chasing that algorithmic trend ;)

  • @ArztvomDienst
    @ArztvomDienst 7 днів тому

    Ok kewl. Now, lets feed it some from Malware Traffic Analysis repo pls

  • @BoniShadat
    @BoniShadat 8 днів тому

    Nice ❤

  • @dhruvbhardwaj6765
    @dhruvbhardwaj6765 5 днів тому

    am not able to upload text file

  • @NighthunterNyx
    @NighthunterNyx 5 днів тому

    Dude enable R1 …..this is weird to use the older v3 model without reasoning

  • @buddyairguy2249
    @buddyairguy2249 7 днів тому +1

    How about running DeepSeek locally, then monitor the network to see if it is secretly reaching out and sending data back to China. In concerns me anytime I run anything that was developed in China. I know Ollama and LMStudio can run DeepSeek models. I find it hard to believe they wouldn't embed something bad in DeepSeek.

    • @ChrisGreer
      @ChrisGreer  7 днів тому +1

      That is a GREAT idea!! 👏👏 💡

  • @diogenesmoore8064
    @diogenesmoore8064 7 днів тому

    Amazing!! ....by the way: I'm a dummy on this, but, I'd listened that you can hear calls/audio/packets. Is it possible? How?....and....can we automate this with A.i.?......Thanks!

  • @NetworkPuck
    @NetworkPuck 8 днів тому

    Thanks

  • @Schnarchos
    @Schnarchos 5 днів тому

    lol you didn't even use the reasoning R1 model, which is probably way better for this task

    • @ChrisGreer
      @ChrisGreer  5 днів тому +1

      Not really TBH, I’ll be posting soon on R1 vs Chat vs OpenAI soon.

  • @FreedomForKashmir
    @FreedomForKashmir 7 днів тому

    But didn't you already give it a hint by namking the file name as tlsbroken.txt ??

    • @ChrisGreer
      @ChrisGreer  7 днів тому

      Possibly. - we will see on another video 👍

  • @MrNameless0shelter
    @MrNameless0shelter 6 днів тому

    I got palo firewall to analyze 😅😅

  • @bibbidi_bobbidi_bacons
    @bibbidi_bobbidi_bacons 7 днів тому

    👏🏻👏🏻👏🏻

  • @yourtube12345
    @yourtube12345 4 дні тому

    Song name??

  • @BeyondPC
    @BeyondPC 5 днів тому

    Oh I thought you were going to run wireshark while you use a local DeepSeek model and examine its network activity so we can 'know' where or if the data is going.

    • @ChrisGreer
      @ChrisGreer  5 днів тому +1

      That video is definitely in the works! Thanks for watching and please stay tuned. 👍

  • @powerhour4602
    @powerhour4602 6 днів тому

    Maybe run a pcap?

  • @aliwalil4160
    @aliwalil4160 8 днів тому

    How do you use the deepseek? I can get submit a couple of prompts daily, otherwise the servers are busy...

    • @ChrisGreer
      @ChrisGreer  8 днів тому +1

      I saw that too - give it another try in a few mins.

    • @redlinejoes
      @redlinejoes 7 днів тому

      Run it locally using your GPU

  • @torryboy2503
    @torryboy2503 6 днів тому +2

    If it is American ai server whatever data you can put, but if it other countries, warning signs. Isn't that hypocrisy

    • @ChrisGreer
      @ChrisGreer  5 днів тому

      Thanks for the comment and with all due respect, when did I say that you can put anything into an American AI server? You need to sanitize your pcaps if you put them anywhere not your network, esp that is accessible. Period. End.

  • @raelhogweed1790
    @raelhogweed1790 6 днів тому

    neato!

  • @codecaine
    @codecaine 7 днів тому

    👏👏👏

  • @cbrunnkvist
    @cbrunnkvist 6 днів тому

    You might have kind of given it away by naming the files... like, undoubtably it adds bias to the output when you name the datasource e.g. "rst errors" instead of just "pcap", no?

  • @alwarithalkhusaibi7902
    @alwarithalkhusaibi7902 7 днів тому +1

    I recommend asking it the problem he found it the packet without saying further information such, why does break
    Meanwhile if this working well by training it can do some complex tasks that cybersecurity analyst take around 15 minutes to find out.

    • @ChrisGreer
      @ChrisGreer  7 днів тому

      That is definitely the goal. I will be posting much more on this topic.

  • @Pygon2
    @Pygon2 7 днів тому +2

    "Tell me what the problem is in this file that I named with what the problem is" doesn't seem like much of a test.

  • @techfarmllc
    @techfarmllc 6 днів тому

    Imagine you create AI agen to automatically do all that for you and report back to you!
    I have already left this Cyber Security career..after 30 years doing this shit!

  • @bibbidi_bobbidi_bacons
    @bibbidi_bobbidi_bacons 7 днів тому

    A/b with other well known and used ai enhancements led search engines

  • @temhirtleague-chess
    @temhirtleague-chess День тому

    The one thing AI will not thrive on is cyber security. If this thing hallucinates and misses a serious threat while analyzing packets, the company is done.

  • @techfarmllc
    @techfarmllc 6 днів тому

    Splunk should AI jazzed their software

  • @cannaroe1213
    @cannaroe1213 4 дні тому

    I _am_ a packet-person... :o

  • @Wahinies
    @Wahinies 6 днів тому

    I wonder if it could be jerry rigged into any APIable network ecosystem and eat Mist's lunch

  • @gd2860
    @gd2860 5 днів тому

    Great stuff

  • @raphaelamorim
    @raphaelamorim 6 днів тому

    Why did you name the file 'tcpresets'? You gave extra-context, man!

    • @ChrisGreer
      @ChrisGreer  6 днів тому

      Haha you are totally right, I am gonna do some further content about that. Thanks for the comment!

  • @vanitymeetstechnology8792
    @vanitymeetstechnology8792 7 днів тому

    Men you look soo good with Beard ... pls dont do full shave ever ... Thank you for the video

    • @ChrisGreer
      @ChrisGreer  7 днів тому +1

      Thanks! I’ll keep it. 🧔🏻‍♂️

  • @abdallahboucedraya
    @abdallahboucedraya 6 днів тому

    Why no one before do this tests to any other llm !!!!!!!
    Is not a question

  • @atom6_
    @atom6_ 6 днів тому

    Enable the “deep think R1” flag, then it will try to reason its conclusions

  • @RPhaF
    @RPhaF 7 днів тому

    You're not using R1, you're using DeepSeek V3, you need to select R1 to activate it....

    • @ChrisGreer
      @ChrisGreer  7 днів тому +1

      Next video…. On it! 👍 thanks for commenting.

  • @defabriek123
    @defabriek123 7 днів тому

    Helo Cris i lookin g you do this deepsek wit the sharks ande i like. looke good fo me tank you much. so look mor sharks for this deepsek. also my siestes like you hannesom i pushe thies botton an look fo buy shaks you my fient. i like thies anmay be i now won the gifft you tank you. I hav ni poblem fo many monnies buy the sharhs. how much for tis sharks to buy tank you? im like thies vere good tank you cris tank you

  • @Bambotb
    @Bambotb 7 днів тому

    It looks like cybersecurity will be cut by 90% like software engineers in a couple of years right ? I see people are so much in denial 😂

    • @ChrisGreer
      @ChrisGreer  7 днів тому +1

      Yeah I will prob be out of a job soon too 😆

    • @Bambotb
      @Bambotb 7 днів тому

      @ well you can still be part of the 10% that stays mate or you think all will be wiped iut

    • @thameemyousuf8194
      @thameemyousuf8194 6 днів тому

      There should be always a human in this loop

    • @Bambotb
      @Bambotb 6 днів тому +1

      @ sure thats why i said 90%

  • @brians4919
    @brians4919 7 днів тому

    All good great until it's found it really Chinese spyware.