427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet201/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   197   198   199   200   201   202   203   204   ...   387
Bog'liq
Botnets - The killer web applications

www.syngress.com
Ourmon: Anomaly Detection Tools • Chapter 7
253
427_Bot_07.qxd 1/8/07 3:40 PM Page 253


Notes from the Underground…
The Hacker Rule of Economy
Small attacks don’t pay.
A hacker sending spam wants to send a 
lot
of
spam. A botnet client scanning for hosts to increase the botnet mesh
size wants to scan and exploit a 
lot
of hosts. Otherwise the rate of
return is too low. The hacker won’t get enough money from the spam
or enough hosts for the botnet. Another economic measure is that
using a lot of bots results in an attractive network that might be sold
to others. It is also more resistant simply because any bot client can
become a bot server. If the human owner of the botnet has many
clients, it is less important if one is lost and removed from the mesh. 
This is why ourmon looks for anomalies in the large and tries to point
out parallelism and give the user some sense of scale in an attack. Ourmon
won’t tell you about a single SQL slammer packet.That isn’t a design goal for
ourmon. Snort, on the other hand, can tell you about a single SQL slammer
packet because detecting individual packet threats is a design goal.
We need one more definition before we go on. In intrusion detection, the
terms 
false positive
and 
false negative
are used. A 
false positive
is an event that the
system reported that appears bad and in point of fact is benign.Too many
false positives can cause an analyst to lose interest. A 
false negative
is worse. In
that case the system reports that something is okay (or doesn’t report any-
thing) and in point of fact the event is bad. Not reporting that the wolf is in
the house and is wearing grandma’s dress is bad, so false negatives are very bad
indeed. On the other hand, systems and analysts using the system have limits.
Too many false positives can wear an analyst out to the point that he or she
doesn’t pay attention any more. As a result, a family of wolves in the house
could be ignored.

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   197   198   199   200   201   202   203   204   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish