427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet277/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   273   274   275   276   277   278   279   280   ...   387
Bog'liq
Botnets - The killer web applications

Solutions Fast Track
Automated Packet Capture
Ourmon has an automated packet-capture feature that allows packet
capture during certain types of anomalous events.
Automated packet capture is turned on in the probe config file. In
general, you must create a dump directory and specify a threshold
number and packet count for each trigger you use.
Trigger-on and -off events are logged in the ourmon event file,
which you can find from the main Web page (both at top and
bottom).
Triggers of interest for anomaly detection include the trigger_worm
trigger, the UDP work weight trigger, and the drops trigger.
www.syngress.com
Advanced Ourmon Techniques • Chapter 9
339
427_Botnet_09.qxd 1/8/07 4:45 PM Page 339


The 
trigger_worm
trigger is used to capture packets when the supplied
threshold of scanning IP hosts is exceeded.
The 
UDP work weight
trigger is used for capturing packets when the
supplied threshold (a UDP work weight) is exceeded. Packets are
captured per host.
The 
drops
trigger is used to capture packets when a supplied dropped
packet threshold is exceeded.This trigger has a poor signal-to-noise
ratio and is more likely to succeed if most packets are DoS attack
packets. However, the probe system itself might fail under these
circumstances.
Captured packets can be viewed with a sniffer such as tcpdump or
WireShark.
Ourmon Event Log
The event log records both probe and back-end events of interest.
The goal of the event log is to store significant security-related events
as well as important ourmon system events.
Note that the event log stores both bot client mesh detection and bot
server detection events.
The event log is rolled over at midnight to become the previous day’s
event log. Event logs for roughly a week are kept by the system and
made available at the bottom of the main Web page.
Tricks for Searching the Ourmon Logs
Log information in ourmon exists in two directories: the Web
directory on the back-end graphics system or the log directory.
Depending on installation path, the Web directory might be
/home/mrourmon/web.pages, and the logging directory might be
/home/mrourmon/logs.

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   273   274   275   276   277   278   279   280   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish