427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet172/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   168   169   170   171   172   173   174   175   ...   387
Bog'liq
Botnets - The killer web applications

www.syngress.com
Botnet Detection: Tools and Techniques • Chapter 5
211
427_Botnet_05.qxd 1/9/07 9:59 AM Page 211


in an application that relies for its effectiveness on being installed to
an absolutely clean environment.
Darknets, Honeypots, and Other Snares
A darknet (or network telescope, or black hole) is an IP space that
contains no active hosts and therefore no legitimate traffic. Any traffic
that does find its way in is due to either misconfiguration or attack.
Intrusion detection systems in that environment can therefore be
used to collect attack data.
A honeypot is a decoy system set up to attract attackers. A low-
interaction honeypot can collect less information than a high-
interaction honeypot, which is open (or appears to be open) to
compromise and exploitation.
A honeynet consists of a number of high-interaction honeypots in a
network, monitored transparently by a honeywall.
Forensics Techniques and Tools for Botnet Detection
The field of digital forensics is concerned with the application of
scientific methodology to gathering and presenting evidence from
digital sources to investigate criminal or unauthorized activity,
originally for judicial review.
The forensic process at the judiciary level involves strict procedures
to maintain the admissibility and integrity of evidence. Even for
internal investigations, you should work as closely to those procedures
as is practical, in case of later legal or administrative complications.
There is no single, simple approach to investigating a suspected
botnet. Make the best of all the resources that can help you out, from
spam and abuse notifications to the logs from your network and
system administration tools.
Automated reports generated from log reports by tools like Swatch
don’t just help you monitor the health of your systems; in the event

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   168   169   170   171   172   173   174   175   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish