427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet176/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   172   173   174   175   176   177   178   179   ...   387
Bog'liq
Botnets - The killer web applications

Ourmon: Overview
and Installation
Solutions in this chapter:

Case Studies: Things That Go Bump 
in the Night

How Ourmon Works

Installation of Ourmon
Chapter 6
217
Summary
Solutions Fast Track
Frequently Asked Questions
427_Botnet_06.qxd 1/8/07 3:14 PM Page 217


Introduction
Botnets can be difficult to detect in a network, but recently, Portland State
University’s Jim Binkley, a professor and network security engineer, modified
a tool called ourmon to detect the presence of botnets using network traffic
analysis.The basic idea is that ourmon detects network anomalies based on
hosts that are attacking other hosts via denial-of-service (DoS) attacks or by
network scanning. It can then correlate this information with IRC channels
and tell you if an entire IRC channel (set of communicating hosts) is suspi-
cious.Thus, it is possible to find an entire set of infected hosts at one time.
Ourmon is an open source tool. Originally, it was designed for network
monitoring but after a period of time it was discovered that it was also an
anomaly-based tool, meaning that once you knew what was normal, you
could begin to get suspicious about what was abnormal (anomalous).
Ourmon is a network-based tool and not a per-host tool like a garden-variety
virus detector. It typically is used to tell you the state of all the hosts in an
enterprise from one vantage point (the logical network center) and can be
viewed as a statistical network trend indicator.
In this chapter and subsequent chapters we are going to take a look at
various aspects of ourmon that pertain to low-level anomaly detection and
higher-level detection of botnets. We will do this by looking at ourmon and
how it works and also by looking at a few botnet-related case histories. Here
is our chapter plan for the chapters on ourmon.


Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   172   173   174   175   176   177   178   179   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish