427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet211/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   207   208   209   210   211   212   213   214   ...   387
Bog'liq
Botnets - The killer web applications

T
IP
Some things to remember about the TCP port report.
1. You may be viewing an attack in parallel. Say, for example,
that you have 2000 hosts in it, all with a port signature of
www.syngress.com
264
Chapter 7 • Ourmon: Anomaly Detection Tools
427_Bot_07.qxd 1/8/07 3:40 PM Page 264


port 25. his is probably a remote botnet that has been
ordered to scan your network for possible open e-mail
proxies. This can very well be the explanation for the spike in
the TCP worm graph in Case Study #2 in the previous chapter.
In Chapter 9 we will explain how to make this correlation.
2. Sorting by IP address gives us the ability to see multiple
infected hosts in an IP subnet.
3. Sorting the destination TCP ports gives us the ability to see
patterns in scans initiated by malware. We may be able to see
that a set of hosts are under the same remote control or pos-
sibly have the same malware program.
4. Our IRC report engine (next chapter) uses the TCP work
weight to determine if there are too many attacking clients in
a sick IRC channel. If so, it places the IRC channel in its 
evil
channel
list. 
TCP Work Weight: Details 
In this section we will briefly talk about a few aspects of the TCP work
weight. It is the most important statistical measure in the port report, and we
need to discuss how it is computed and what can seemingly go wrong with
that process.
First of all, let’s look at how the work weight is computed.The rough
equation for the work weight for one IP host is:
where:

SS is the total number of SYNS sent by the IP during the sample
period.

FS is the total number of FINS sent by the IP during the sample
period.

RR is the total number of TCP RESETS returned to the IP during
the sample period.

TP is the total number of TCP packets, including control and data
sent and received by the host, during the sample period.

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   207   208   209   210   211   212   213   214   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish