DeepSeek and Packet Analysis? Let's find out...

  Рет қаралды 57,222

Chris Greer

Chris Greer

Күн бұрын

Пікірлер
@ChrisGreer
@ChrisGreer 8 күн бұрын
With all the buzz around Deepseek AI, I threw a couple of packet captures at it to see if it could help with the analysis and find root cause. I was actually pretty happy with the results, but I still had to dig deeper and fact-check the AI analysis. Not quite there yet but close! You can download the first pcap and follow along here: github.com/packetpioneer/yout... If you like, please let me know!! It helps. Really. Want more packet goodness? == More On-Demand Training from Chris == ▶Getting Started with Wireshark - bit.ly/udemywireshark ▶Getting Started with Nmap - bit.ly/udemynmap
@ilozeet
@ilozeet 7 күн бұрын
what did you have to fact check please
@tpavan
@tpavan 7 күн бұрын
As always, no BS, straight to the point content, Chris's videos are the best!!
@ChrisGreer
@ChrisGreer 7 күн бұрын
Thanks for the comment! 🙏
@JohnnyLeuthard
@JohnnyLeuthard 6 күн бұрын
That's pretty cool. I did this on a local copy of Deepseek and Ollama to run it local. I used a packet from created when I started got through your masterclass series. Very cool. I can see where this would be extremely helpful to help navigate a capture. I'd still look at the actual capture but a 2nd set of eyes to partner with. This is where AI has great potential.
@packetpulse
@packetpulse 8 күн бұрын
Never thought of using AI model for pcap analysis. Thank uou
@ChrisGreer
@ChrisGreer 8 күн бұрын
It’s a powerful combo, right? Thanks for watching!
@redlinejoes
@redlinejoes 7 күн бұрын
It's something we've been doing in cybersecurity for a few years. There are some interesting open-source projects from Nvidia using Morpheus and the Triton inference server. Converting to text might not be the best method, either. With the Nvidia projects, we convert to JSON, which the APIs speak natively. There's a lot of existing research and development on these topics if you're interested.
@packetpulse
@packetpulse 7 күн бұрын
@@redlinejoes you mind sharing more details pls.
@Mr0rris0
@Mr0rris0 6 күн бұрын
ya.... AI is not for making giraffe snakes or helping sponsored gladiator/astrologers and witches do "technomancy" while the old have not caught up with the new... the new have not caught up to the old....
@mytechnotalent
@mytechnotalent 7 күн бұрын
Chris this is fantastic! It is interesting how it can help speed up analysis however knowing the skill is essential and so fortunate for your work.
@Relics
@Relics 7 күн бұрын
One issue is that you're using the older v3 model instead of the newer reasoning (r1) model which is what deepseek blew up in popularity from. At the bottom of the input text bar you can enable the R1 Reasoning "Deepthink". You will likely see better and more in depth results.
@Relics
@Relics 7 күн бұрын
I recommend trying it again and seeing the difference between a normal model and a reasoning model (If any in this case.)
@ChrisGreer
@ChrisGreer 7 күн бұрын
Nice call thank you.
@redlinejoes
@redlinejoes 7 күн бұрын
It produces similar results, but sometimes, the MoE in the CoT process of the "reasoning" model will argue with itself and get stuck in a loop.
@whitescreen1031
@whitescreen1031 7 күн бұрын
I can't believe he is not aware of it as well. Almost everyone else reviewing DeepSeek online has pointed that option out, and that it is also right below the prompt field with a clear label. He seems to have just jumped right into it without actually exploring how to use it, just unbelievable! 🤣
@33gbm
@33gbm 5 күн бұрын
​@@redlinejoes They are definitely not producing similar results; r1 is much more 'error-proof'
@Juanchicookie
@Juanchicookie 7 күн бұрын
Chris! This is really nice. Thank you for putting this video together for us. I will use it to practice and get some guidance to improve my traffic analysis skills 🤗
@ChrisGreer
@ChrisGreer 7 күн бұрын
Go get it!!
@randomized4368
@randomized4368 6 күн бұрын
At last one sensible expert, warning about security and privacy of deepseek👍
@raoultesla2292
@raoultesla2292 6 күн бұрын
YES ! Everyone is so exited to use the newest 'smartes' CSV file they forget who/where it reports to.
@raoultesla2292
@raoultesla2292 6 күн бұрын
Chris, always cutting edge, on spot, current. Nice
@mikulast3292
@mikulast3292 7 күн бұрын
Thank You Chris once again for your hints! Haven't been long on your channel, but glad You are still here and making very handy content. ;-) (literally a few years back You teached me from scratch thru your series how to read pcaps) From zero to hero BRO 👍
@ChrisGreer
@ChrisGreer 7 күн бұрын
Welcome back!
@zoren001
@zoren001 7 күн бұрын
Excited for the future auto AI packet analysis
@brodmontgomery
@brodmontgomery 7 күн бұрын
That was fascinating. I'm now going to go back and use the packet captures that you've supplied to us previously and experiment with DeepSeek and the other AI platforms, see if I can learn something new. Thanks.
@ChrisGreer
@ChrisGreer 7 күн бұрын
Have fun!
@rakumarudu81
@rakumarudu81 5 күн бұрын
Thank you for great tutorial. Didn't think about Deepseek for packet debugging
@udhayakumars1766
@udhayakumars1766 7 күн бұрын
Thanks for keeping us up to date, this is really cool.
@MartinMonday-t5g
@MartinMonday-t5g 4 күн бұрын
Thanks for this Video, it's very cool to see the posibilies of AI in the IT Security!
@admar-nelson
@admar-nelson 7 күн бұрын
Good Job DeepSeek AI! one more source to get job done! and thank you Chris happy new year for you and your family
@ChrisGreer
@ChrisGreer 7 күн бұрын
Thanks for watching!
@freddrune8315
@freddrune8315 7 күн бұрын
Great video sir. I look forward to your next video.
@jjann54321
@jjann54321 8 күн бұрын
Great video as always. So the message is, "Deepseek is good, but not Chris Greer good." I can empathize with Deepseek, we do our best.
@ChrisGreer
@ChrisGreer 8 күн бұрын
haha.. one day it will be better. But for now at least it got us most of the way there. Thanks for watching and commenting!
@redlinejoes
@redlinejoes 7 күн бұрын
Better prompts produce better results. It's a skill issue, not a limitation of the model.
@TheGTP1995
@TheGTP1995 6 күн бұрын
​@@redlinejoes but if you know networking you don't need to query the LLM in the first place, so no real skill issue😉
@redlinejoes
@redlinejoes 5 күн бұрын
​@@TheGTP1995 Are you lost?
@GibsonHambleton
@GibsonHambleton 6 күн бұрын
Great video Chris. Very interesting!
@muhdbasheer
@muhdbasheer 8 күн бұрын
Amazing job, Chris.
@0x004
@0x004 8 күн бұрын
You're gonna make a packet head out of DeepSeek! Thanks for the video, great to see it!
@ChrisGreer
@ChrisGreer 8 күн бұрын
I'll send it the tshirt. 👍 Thanks for watching!
@Daniel-tb6gn
@Daniel-tb6gn 5 күн бұрын
Good video, I just discovered your channel. It will be great to see this experiment with the R1 model.
@ChrisGreer
@ChrisGreer 5 күн бұрын
Thanks for coming and commenting! I’m gonna do a few more of these with more models. Stay tuned! 👍
@AnomalousURL
@AnomalousURL 8 күн бұрын
Thanks, Chris! Great demo and information. I appreciate the insight.
@ChrisGreer
@ChrisGreer 8 күн бұрын
Thanks for the watch!
@fabriziopelliccione6810
@fabriziopelliccione6810 8 күн бұрын
Hey! I am Working for SonicWall! don't blame us! ..just kidding... never used AI to analyze packets, will give a try! awesome video! as usual! thanks
@ChrisGreer
@ChrisGreer 8 күн бұрын
Hey it was just the config not the box, it's all good. I've got other pcaps that blame other vendors too... 😆
@Makinou
@Makinou 7 күн бұрын
It can be interesting if you compare the result with another AI like chatgpt to see which can be more precise in this exercise 😁
@ChrisGreer
@ChrisGreer 7 күн бұрын
Great thinking - I actually have that on my list of videos to shoot. Thanks for the comment! 👍
@redlinejoes
@redlinejoes 7 күн бұрын
I do this often and it's dependant on the size of model used. I run models locally and compare those to o1 for example. What's impressive is that the response from a
@junchaochang6962
@junchaochang6962 8 күн бұрын
good video,i always watch every video you uploaded,and i have learned lots of network knowledge especially wireshark ,thanks for your efforts
@ChrisGreer
@ChrisGreer 8 күн бұрын
Thank you for the comment!
@hamradiowithkevin
@hamradiowithkevin 7 күн бұрын
Thank you Chris, Excellent test and confirmation that AI chat bots may in fact become part of our workflow.
@ChrisGreer
@ChrisGreer 7 күн бұрын
I agree - I think they are going to be a very helpful tool, at least with an initial analysis!
@guarism0
@guarism0 7 күн бұрын
Great stuff 👍🏻 This could be fantastic with a local DeepSeek r1 instance.
@ohasis8331
@ohasis8331 8 күн бұрын
Nice analysis demo.
@thameemyousuf8194
@thameemyousuf8194 6 күн бұрын
New insights..thanks Chris
@ChrisGreer
@ChrisGreer 6 күн бұрын
More to come!
@EduardKhiaev
@EduardKhiaev 7 күн бұрын
as usual, amazing stuff
@DANNOS1993
@DANNOS1993 8 күн бұрын
Thanks!.. Didn't know you can do this with wireshark
@ChrisGreer
@ChrisGreer 8 күн бұрын
Glad it helps, enjoy!
@PoteRomo
@PoteRomo 7 күн бұрын
Interesting lab! Thanks for sharing!!!
@ChrisGreer
@ChrisGreer 7 күн бұрын
Thanks for watching!
@justus-0b3
@justus-0b3 7 күн бұрын
Thanks for the video. I wonder how it would have performed on the second capture if you had turned on deepthink for reasoning
@ChrisGreer
@ChrisGreer 7 күн бұрын
I'll try it out and see what happens!
@EmilioOP9
@EmilioOP9 15 сағат бұрын
Amazing video and great content as always. Thank you for doing these videos. My two cents: could you name the files differently like 'capture1.txt' before uploading to Deepseek? This way we will know that Deepseek didn't use the file name as a clue of the issue. Again, thank you.
@ChrisGreer
@ChrisGreer Сағат бұрын
Great suggestion - I'm on it with the next video...
@WireSharkFest
@WireSharkFest 8 күн бұрын
Awesome video! Curious to see how Qwen 2.5 would perform as well...
@ChrisGreer
@ChrisGreer 7 күн бұрын
Hmmm…. Comparison? Next vid?
@joeypeleg152
@joeypeleg152 5 күн бұрын
It would be very interesting in finding out with wireshark if there are leaks in a local install of Deepseek??? Important for businesses
@majiddehbi9186
@majiddehbi9186 8 күн бұрын
wow chris I just finish your video with D.Bombal u guys are doing a great great job, now so quick u are teeling us about deepseek THx for all the information you give
@ChrisGreer
@ChrisGreer 8 күн бұрын
Thanks for the feedback! Deepseek is pretty cool.
@Uncle_Buzz
@Uncle_Buzz 8 күн бұрын
Really fun stuff. NG AI-based IDS systems do this all day, but they don't really analyze why something didn't work, rather suspicious things.
@dsulvadarius
@dsulvadarius 6 күн бұрын
Is there any particular reason you did not click on the DeepThink (R1) button in DeepSeek's UI?
@defy933
@defy933 5 күн бұрын
then he wouldn't have any content for his channel lol
@Sparks3D
@Sparks3D 8 күн бұрын
Very cool. Would love to see some cyber security examples to see if it comes up with the correct conclusion.
@ChrisGreer
@ChrisGreer 8 күн бұрын
Great idea. On to some malware analysis!
@syedtaimoorhussain4626
@syedtaimoorhussain4626 8 күн бұрын
Would love to see the comparison with chatgpt and other AI models
@ChrisGreer
@ChrisGreer 8 күн бұрын
On it! Next up I am going to do a Deepseek vs ChatGPT vs Packet Copilot sort of thing. Thanks for the suggestion.
@SelvaKumar-rl5wn
@SelvaKumar-rl5wn 8 күн бұрын
Waiting...😊
@Wahinies
@Wahinies 6 күн бұрын
​@@ChrisGreeryou are a gentleman and a scholar
@harrysearia1784
@harrysearia1784 7 күн бұрын
Get info as usual Chris. One question I have is how do you sanitize the data before submitting it?
@ChrisGreer
@ChrisGreer 7 күн бұрын
I use a tool called Tracewrangler. I would share a video of how to use it but I haven't made one yet! My mistake, I will get to that soon... www.tracewrangler.com/
@harrysearia1784
@harrysearia1784 7 күн бұрын
@ChrisGreer You sir, are a certified Rock Star!!!!!
@justinatwell8187
@justinatwell8187 2 күн бұрын
I know you can ask these LLMs loaded questions to get them on the right track or to sway them. I wonder if the filename affects its output, or the speed of response. Are we leading it?
@leoniaklebanov2502
@leoniaklebanov2502 6 күн бұрын
Awesome, idea!!!!
@ChrisGreer
@ChrisGreer 6 күн бұрын
Thanks for the feedback! Gonna do a few more of these.
@borisvokladski5844
@borisvokladski5844 7 күн бұрын
It could be interesting to see, if the distilled versions of Deep Seek could come to the same conclusion.
@aaronbanks3673
@aaronbanks3673 7 күн бұрын
Cool video!
@ricardotovar9035
@ricardotovar9035 2 күн бұрын
🔥🔥🔥
@senditall152
@senditall152 7 күн бұрын
I wonder if the file name helps it though.
@ChrisGreer
@ChrisGreer 7 күн бұрын
I was actually wondering that myself as well. I'm going to shoot another video with a different AI and see if that makes a diff. I'll post it.
@redlinejoes
@redlinejoes 7 күн бұрын
The file name is not as crucial for RAG as the contents. The file can be called anything. What's used in the embedding is the contents of that file. The name is far less significant than the process.
@augustedrifande6017
@augustedrifande6017 8 күн бұрын
Thanks 🙂.
@samvid1980
@samvid1980 8 күн бұрын
absorbed knowledge thanks bro
@ChrisGreer
@ChrisGreer 8 күн бұрын
Always welcome
@Network_Engineer-w7q
@Network_Engineer-w7q 7 күн бұрын
Great video. Can I provide AP logs and syslogs to Deepseek and will it debug the logs and give client disconnect reasons?
@abdelkrimdakouan7211
@abdelkrimdakouan7211 7 күн бұрын
I think you just used deepseek v3 and not r1 (you need to activate it by toggling the deepthink button in the right bottom of the chat text box)
@namrataasati7915
@namrataasati7915 3 күн бұрын
I am following the sames you did, but deepseek not accepting the fille saying "extract only text from images and files"
@QEDAGI
@QEDAGI 8 күн бұрын
Very nice. Going to try it locally using ollama AND LM Studio to rate their inferences. I mean, why feed someone else when you can run your own.
@ChrisGreer
@ChrisGreer 7 күн бұрын
I'm gonna start working on my own as well... more to come and thank you for the comment!
@scientificodessey8889
@scientificodessey8889 8 күн бұрын
Love from Bangladesh bro.
@ChrisGreer
@ChrisGreer 8 күн бұрын
Love back!
@fununclenerfs
@fununclenerfs 7 күн бұрын
Chasing that algorithmic trend ;)
@ArztvomDienst
@ArztvomDienst 8 күн бұрын
Ok kewl. Now, lets feed it some from Malware Traffic Analysis repo pls
@BoniShadat
@BoniShadat 8 күн бұрын
Nice ❤
@dhruvbhardwaj6765
@dhruvbhardwaj6765 5 күн бұрын
am not able to upload text file
@NighthunterNyx
@NighthunterNyx 5 күн бұрын
Dude enable R1 …..this is weird to use the older v3 model without reasoning
@buddyairguy2249
@buddyairguy2249 7 күн бұрын
How about running DeepSeek locally, then monitor the network to see if it is secretly reaching out and sending data back to China. In concerns me anytime I run anything that was developed in China. I know Ollama and LMStudio can run DeepSeek models. I find it hard to believe they wouldn't embed something bad in DeepSeek.
@ChrisGreer
@ChrisGreer 7 күн бұрын
That is a GREAT idea!! 👏👏 💡
@NetworkPuck
@NetworkPuck 8 күн бұрын
Thanks
@diogenesmoore8064
@diogenesmoore8064 7 күн бұрын
Amazing!! ....by the way: I'm a dummy on this, but, I'd listened that you can hear calls/audio/packets. Is it possible? How?....and....can we automate this with A.i.?......Thanks!
@Schnarchos
@Schnarchos 5 күн бұрын
lol you didn't even use the reasoning R1 model, which is probably way better for this task
@ChrisGreer
@ChrisGreer 5 күн бұрын
Not really TBH, I’ll be posting soon on R1 vs Chat vs OpenAI soon.
@FreedomForKashmir
@FreedomForKashmir 7 күн бұрын
But didn't you already give it a hint by namking the file name as tlsbroken.txt ??
@ChrisGreer
@ChrisGreer 7 күн бұрын
Possibly. - we will see on another video 👍
@MrNameless0shelter
@MrNameless0shelter 6 күн бұрын
I got palo firewall to analyze 😅😅
@bibbidi_bobbidi_bacons
@bibbidi_bobbidi_bacons 7 күн бұрын
👏🏻👏🏻👏🏻
@yourtube12345
@yourtube12345 5 күн бұрын
Song name??
@powerhour4602
@powerhour4602 6 күн бұрын
Maybe run a pcap?
@BeyondPC
@BeyondPC 5 күн бұрын
Oh I thought you were going to run wireshark while you use a local DeepSeek model and examine its network activity so we can 'know' where or if the data is going.
@ChrisGreer
@ChrisGreer 5 күн бұрын
That video is definitely in the works! Thanks for watching and please stay tuned. 👍
@aliwalil4160
@aliwalil4160 8 күн бұрын
How do you use the deepseek? I can get submit a couple of prompts daily, otherwise the servers are busy...
@ChrisGreer
@ChrisGreer 8 күн бұрын
I saw that too - give it another try in a few mins.
@redlinejoes
@redlinejoes 7 күн бұрын
Run it locally using your GPU
@torryboy2503
@torryboy2503 6 күн бұрын
If it is American ai server whatever data you can put, but if it other countries, warning signs. Isn't that hypocrisy
@ChrisGreer
@ChrisGreer 5 күн бұрын
Thanks for the comment and with all due respect, when did I say that you can put anything into an American AI server? You need to sanitize your pcaps if you put them anywhere not your network, esp that is accessible. Period. End.
@raelhogweed1790
@raelhogweed1790 6 күн бұрын
neato!
@codecaine
@codecaine 8 күн бұрын
👏👏👏
@cbrunnkvist
@cbrunnkvist 7 күн бұрын
You might have kind of given it away by naming the files... like, undoubtably it adds bias to the output when you name the datasource e.g. "rst errors" instead of just "pcap", no?
@alwarithalkhusaibi7902
@alwarithalkhusaibi7902 7 күн бұрын
I recommend asking it the problem he found it the packet without saying further information such, why does break Meanwhile if this working well by training it can do some complex tasks that cybersecurity analyst take around 15 minutes to find out.
@ChrisGreer
@ChrisGreer 7 күн бұрын
That is definitely the goal. I will be posting much more on this topic.
@Pygon2
@Pygon2 7 күн бұрын
"Tell me what the problem is in this file that I named with what the problem is" doesn't seem like much of a test.
@techfarmllc
@techfarmllc 6 күн бұрын
Imagine you create AI agen to automatically do all that for you and report back to you! I have already left this Cyber Security career..after 30 years doing this shit!
@bibbidi_bobbidi_bacons
@bibbidi_bobbidi_bacons 7 күн бұрын
A/b with other well known and used ai enhancements led search engines
@temhirtleague-chess
@temhirtleague-chess Күн бұрын
The one thing AI will not thrive on is cyber security. If this thing hallucinates and misses a serious threat while analyzing packets, the company is done.
@techfarmllc
@techfarmllc 6 күн бұрын
Splunk should AI jazzed their software
@cannaroe1213
@cannaroe1213 4 күн бұрын
I _am_ a packet-person... :o
@Wahinies
@Wahinies 6 күн бұрын
I wonder if it could be jerry rigged into any APIable network ecosystem and eat Mist's lunch
@gd2860
@gd2860 5 күн бұрын
Great stuff
@raphaelamorim
@raphaelamorim 6 күн бұрын
Why did you name the file 'tcpresets'? You gave extra-context, man!
@ChrisGreer
@ChrisGreer 6 күн бұрын
Haha you are totally right, I am gonna do some further content about that. Thanks for the comment!
@vanitymeetstechnology8792
@vanitymeetstechnology8792 7 күн бұрын
Men you look soo good with Beard ... pls dont do full shave ever ... Thank you for the video
@ChrisGreer
@ChrisGreer 7 күн бұрын
Thanks! I’ll keep it. 🧔🏻‍♂️
@abdallahboucedraya
@abdallahboucedraya 6 күн бұрын
Why no one before do this tests to any other llm !!!!!!! Is not a question
@atom6_
@atom6_ 6 күн бұрын
Enable the “deep think R1” flag, then it will try to reason its conclusions
@RPhaF
@RPhaF 7 күн бұрын
You're not using R1, you're using DeepSeek V3, you need to select R1 to activate it....
@ChrisGreer
@ChrisGreer 7 күн бұрын
Next video…. On it! 👍 thanks for commenting.
@defabriek123
@defabriek123 7 күн бұрын
Helo Cris i lookin g you do this deepsek wit the sharks ande i like. looke good fo me tank you much. so look mor sharks for this deepsek. also my siestes like you hannesom i pushe thies botton an look fo buy shaks you my fient. i like thies anmay be i now won the gifft you tank you. I hav ni poblem fo many monnies buy the sharhs. how much for tis sharks to buy tank you? im like thies vere good tank you cris tank you
@Bambotb
@Bambotb 7 күн бұрын
It looks like cybersecurity will be cut by 90% like software engineers in a couple of years right ? I see people are so much in denial 😂
@ChrisGreer
@ChrisGreer 7 күн бұрын
Yeah I will prob be out of a job soon too 😆
@Bambotb
@Bambotb 7 күн бұрын
@ well you can still be part of the 10% that stays mate or you think all will be wiped iut
@thameemyousuf8194
@thameemyousuf8194 6 күн бұрын
There should be always a human in this loop
@Bambotb
@Bambotb 6 күн бұрын
@ sure thats why i said 90%
@brians4919
@brians4919 7 күн бұрын
All good great until it's found it really Chinese spyware.
@TryEvaflow
@TryEvaflow 7 күн бұрын
All LLMs are Spyware.
the ONLY way to run Deepseek...
11:59
NetworkChuck
Рет қаралды 733 М.
Tiny Core Linux is Basically Magic
14:23
Action Retro
Рет қаралды 318 М.
My scorpion was taken away from me 😢
00:55
TyphoonFast 5
Рет қаралды 2,7 МЛН
Your Remote Desktop SUCKS!! Try this instead (FREE + Open Source)
22:30
How TCP really works // Three-way handshake // TCP/IP Deep Dive
1:01:10
China's slaughterbots show WW3 would kill us all.
14:46
Digital Engine
Рет қаралды 1,7 МЛН
Can DeepSeek R1 Actually Write Good Code?
37:28
Garage Tinkering
Рет қаралды 162 М.
DeepSeek is a Game Changer for AI - Computerphile
19:58
Computerphile
Рет қаралды 1,3 МЛН
NVIDIA CEO Jensen Huang's Vision for the Future
1:03:03
Cleo Abram
Рет қаралды 1,1 МЛН
Transformers (how LLMs work) explained visually | DL5
27:14
3Blue1Brown
Рет қаралды 4,7 МЛН