427 Botnet fm qxd


Table 6.1 IRC Report: Evil Channel Sort channel



Download 6,98 Mb.
Pdf ko'rish
bet181/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   177   178   179   180   181   182   183   184   ...   387
Bog'liq
Botnets - The killer web applications

Table 6.1
IRC Report: Evil Channel Sort
channel
msgs
joins
privmsgs ipcount
wormyhosts
evil?
lsass445
4572
187
4385
11
8
E
.i-exp
1
0
1
2
1
e
alien
122
92
30
2
1
e
hobo
12
8
4
3
1
e
Table 6.2
IRC Report: Channel List for Channel Hobo
hobo
msg stats
max ww
client/server ports
192.168.2.3
199
95
H
4929/504
192.168.2.4
159
40
H
1028/21958
10.0.0.1
756
50
S
25394/2777
Our first table gives the 
evil channel sort
. In this sort we rank channels high
if they have more hosts in them with per-host higher-scanning weights. We
will talk more about the scanning weight in the next chapter. For now, accept
that we are just counting hosts (under the wormyhosts label). A scanner is a
host that performed what appears to be an act of scanning. It is simply
looking for other hosts—probably to attack them with an exploit. So for
some reason channel lsass445 had eight scanners apparently out of 11 hosts.
www.syngress.com
224
Chapter 6 • Ourmon: Overview and Installation
427_Botnet_06.qxd 1/8/07 3:14 PM Page 224


Given eight scanners out of 11 hosts in the channel including any IRC
servers, it is pretty likely that this channel is a botnet. However, false positives
do occur and a channel with just a host or two with a high scanner weight
may easily turn out to be a false positive (not guilty). We call the scanning
weight the 
TCP work weight
and will talk more about it in the next chapter.
We are also interested in the other three channels because they are borderline
cases and far less easy to declare a botnet client network. Here it turned out
that channels hobo and .i-exp were botnet channels with the same IP server
address (we are not giving real IP addresses and will confine ourselves to
giving addresses as either net 192.168/16 or 10/8. In our examples, addresses
with 192.168 as a prefix may be assumed to be local. Addresses using net 10
may be assumed to be remote). It turns out that alien is innocent, and the
other two channels are guilty. We will explain these details in Chapter 8 on
botnets, and in that chapter and Chapter 9 give more details about how we
investigated our data to determine if these channels were botnets.
Notes from the Underground…
From the enterprise perspective, you may encounter two types of botnet
environments in your log files. The set of hosts participating in the bot
traffic is called a 
mesh
. You determine the type of mesh based on
whether the botnet server is located inside or outside your enterprise:

Client bot mesh
This is the term for a set of botnet clients
that exists within a campus or enterprise and communicates
with an external botnet server. Botnet clients are sometimes
called zombies.

Server bot mesh
This bot mesh includes an on-site botnet
server. Botnet servers are sometimes called Command and
Control (C&C) hosts. 

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   177   178   179   180   181   182   183   184   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish