427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet221/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   217   218   219   220   221   222   223   224   ...   387
Bog'liq
Botnets - The killer web applications

sent:
recv:
Unreachs: L3D/L4D Appflags:Port_sig
10.16.208.23 38386361
88261 0
2293
4322/2
Ps
[1025,50]
[1026,50]
Given that our normal top entry in the UDP port report has an average
work weight of less than 10000, this one does seem to be interesting.The
UDP work weight is around 380 million. So the aggressor sent 88k UDP
www.syngress.com
274
Chapter 7 • Ourmon: Anomaly Detection Tools
427_Bot_07.qxd 1/8/07 3:40 PM Page 274


packets and none were returned during the sample period. However, it got
back about 2k UDP errors. Earlier we oversimplified our UDP work weight
compute equation. We actually weight the ICMP errors in such a way that if
a host receives ICMP errors, it will get a higher work weight. We show pings
too if any, but we left that field out of the example due to space limitations.
We show unique IP destination and UDP port destination counts as with the
TCP port report.This shows that the host sent packets to 4k local hosts (a
lot) at only two ports. It’s clearly a scanner of some sort. We also have a few
application flags (not many).
P
means that packets were sent into the darknet,
and 
s
is a built-in ourmon signature for identification of some forms of
SPIM. Our port signature mechanism is completely the same as with the TCP
port report. Here we see that half the UDP packets were sent to port 1025
and the other half were sent to port 1026. In the past, one type of IM appli-
cation listened to these ports, and that is why they were the target.
T
IP
By the way, it’s not that convenient to take an approximate time in the
graph and somehow find the logged UDP port entry in a short time. In
Chapter 9, when we learn about the event log and automated packet
capture, we will learn some easier techniques for finding useful infor-
mation from the UDP port reports.

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   217   218   219   220   221   222   223   224   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish