427 Botnet fm qxd


Detecting E-mail Anomalies



Download 6,98 Mb.
Pdf ko'rish
bet222/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   218   219   220   221   222   223   224   225   ...   387
Bog'liq
Botnets - The killer web applications

Detecting E-mail Anomalies
In this section we take a brief look at detecting e-mail anomalies. We do this
with a slightly modified TCP port report called the 
email syn port report
. If you
look back at Figure 7.1 you can find the 30-second version of this report in
the security jump table.There is also a daily summarization in the summariza-
tion section.The goal of the e-mail syn report is to tell you which IP hosts
are sending the most SYN packets to start TCP e-mail connections. A box
infected with a spam-sending bot client tries to send large amounts of spam
to many hosts and could incur failures.Typically such boxes are less efficient
than normal e-mail servers. As a result, we sort all e-mail-sending systems by
www.syngress.com
Ourmon: Anomaly Detection Tools • Chapter 7
275
427_Bot_07.qxd 1/8/07 3:40 PM Page 275


the total number of SYNs sent and put this in a special type of report.You
should be able to use the daily summarization to determine which hosts are
sending e-mail. Once you know what is normal for your site, you can ask
yourself two questions:
1. Are there new hosts sending e-mail that we didn’t know about
before?
2. Are there hosts sending e-mail that seem to fail a lot?
The second question here should be taken with a large grain of salt. E-
mail, more than most applications, is failure prone. E-mail servers try over and
over again for days at a time before they give up. On the other hand, it could
mean something significant if a host sending e-mail never succeeds. In that
case, you might simply have a communication or configuration problem that
needs to be addressed. For example, one concrete problem we have seen are
off-campus e-mail servers trying to talk to a campus e-mail server via a DNS
name, where the DNS name exists but the host itself is gone and is never
coming back. On the other hand, normal e-mail servers are not likely to
always fail. Furthermore, they will typically not try to make as many connec-
tions as a spam-sending system.
The port report is a little different in both the 30-second and summa-
rized versions because for each host ourmon computes an e-mail-specific
TCP work weight. Usually the work weight is for all the applications on a
given host. In this case it is e-mail port-specific for a given host.The e-mail
ports are defined as 25 (SMTP), 587 (submission), and 465 (secure SMTP).
Put another way, there is a second e-mail packet-only work weight computed
in the same fashion as the normal TCP work weight. We also count all e-mail
SYN packets. Let’s take a quick look at the data formats to see how they
differ. First we look at the 30-second report (see Table 7.7) and then we look
at the summarization. We will only look at one data example in both cases.
This system is a normal, busy e-mail server on our campus.

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   218   219   220   221   222   223   224   225   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish