427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet227/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   223   224   225   226   227   228   229   230   ...   387
Bog'liq
Botnets - The killer web applications

www.syngress.com
282
Chapter 7 • Ourmon: Anomaly Detection Tools
427_Bot_07.qxd 1/8/07 3:40 PM Page 282


Q: 
Why does the TCP port report sometimes spot Web servers?
A: 
The short answer is: we don’t know why. We would love to understand
this better. It could have something to do with HTTP mostly sending a
lot of small files, so there are many control packets and just a few data
packets. In theory, later designs of HTTP allow one server to put many
files in one TCP connection, but this doesn’t work if the Web page itself
has separate parts at different IP addresses.
Q: 
What kinds of real-world situations have you seen diagnosed with the
UDP port report?
A: 
Probably everybody on the planet is getting SPIM 24/7. We have seen
SQL-slammer outbreaks that are not exactly hard to spot. We have also
seen numerous instances of badly maintained UNIX servers where some
component of the Web server (say, using PHP) has been exploited and the
web server itself is now being used to DOS a remote host. Bot systems
tend to use TCP for scanning, but UDP does pop up sometimes. A UNIX
system can have a bot as well, even if the majority of bots are found on
Microsoft systems.
Q: 
Are the parts of ourmon focused on network management (not talked
about in the book) ever useful for anomaly detection?
A: 
Everything in ourmon seems to be useful for anomaly detection. DOS
attacks can cause top N talker graphs to show a single system doing the
DOS to be the top N system. One system infected on campus with SQL-
slammer caused the ICMP top N message graph to entirely point at that
system as many systems in the world were busy sending ICMP messages
back to the infected host.

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   223   224   225   226   227   228   229   230   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish