427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet255/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   251   252   253   254   255   256   257   258   ...   387
Bog'liq
Botnets - The killer web applications

www.syngress.com
Advanced Ourmon Techniques • Chapter 9
315
427_Botnet_09.qxd 1/8/07 4:45 PM Page 315


2. You then reboot ourmon and it checks your trigger syntax. It fails if
you made a mistake. (See /var/log/messages for errors or check the
console display.)
3. Every 30 seconds, ourmon now checks the trigger threshold.
4. If the trigger threshold is exceeded, ourmon creates a unique file-
name for the trigger that does not conflict with other triggers or
trigger files produced by the same trigger.
5. Ourmon then begins to store packets until either the packet count is
exhausted or the trigger threshold is crossed in the opposite direction
(going down). For example, packets will no longer be stored if the
trigger is set at 50 hosts for the worm trigger and the threshold is
crossed from 60 hosts to 40 hosts during a sample period.
In general, packets are stored based on a per-trigger filter specification. For
example, the UDP trigger we mention in a moment is per IP address, and
only UDP packets involving that IP address will be stored. Some triggers have
a trigger filter specification, and some don’t. For the kinds of triggers we talk
about here, the trigger filter specifications are not user programmable.
(However, there is a form of trigger that we are ignoring here that is associ-
ated with the BPF user graph feature and is programmable by the user. See
info.html for more information; we won’t cover it here.) 
When ourmon decides to store packets, it opens a file in the specified
directory with the filename syntax as follows:
trigger_name.timestamp.dmp.
There are two things to note in general about the stored packets. One is
that the packets will not be any bigger than the so-called snap length, which
is passed into the ourmon probe when it is booted. Currently that value is
256, which will catch a great deal of Layer 7 payload information (IRC infor-
mation in particular). Second, it is always possible that a trigger will fail to
capture any packets.This is because triggers get turned on only after one basic
probe cycle of 30 seconds.There might simply be no packets after the trigger
is turned on, so the packet capture dump file might have no content for the
obvious reason that no packets are arriving.

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   251   252   253   254   255   256   257   258   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish