427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet250/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   246   247   248   249   250   251   252   253   ...   387
Bog'liq
Botnets - The killer web applications

Solutions Fast Track
Understanding the IRC Protocol
The ngrep tool can be used to directly sniff strings on the network.
In IRC, channels are strings. Channels are the fundamental target of
data messages.
An IRC network consists of a set of servers and hosts.
Users join a channel and can then send messages to other users.The
messages are distributed by the servers to clients interested in the
channel.
Ourmon looks for four fundamental IRC messages, including
PINGS and PONGS used by servers to tell if clients still exist, JOIN
used to join channels, and PRIVMSG used to send data to channels.
427_Botnet_08.qxd 1/8/07 4:10 PM Page 309


Ourmon’s RRDTOOL Statistics and IRC Reports
All IRC statistics are found on the irc.html page.
The IRC data has three parts: RRDTOOL graphics that show a
global network IRC message counts, an hourly summarization (rolled
over at midnight to the previous day), and a 30-second report.
The IRC RRDTOOL graph shows message counts for PING,
PONG, JOIN, and PRIVMSG IRC messages.
The IRC ASCII report shows global, per channel, and per-host
statistics.
The most important parts of the ASCII report are the two channel
sorts at the top, including the evil channel sort and the max message
sort, as well as the breakdown of each channel with per-host statistics.
The evil channel sort shows IRC channels sorted by the number of
scanning hosts (wormy hosts) in the channel.
The max message sort shows IRC channels sorted by the total
number of all four kinds of IRC messages.
The per-channel host statistics show the IP addresses of hosts in an
IRC channel as well as other data, including the maximum TCP
work weight seen for any host in the channel.
The maxworm field in the per-host statistics is really the TCP work
weight, as discussed in the previous chapter.
Detecting an IRC Client Botnet
An IRC channel with more than a few (say, two) clients with high
maxworm (work weight) values could be a botnet channel.
If there is only a few hosts with high work weights, one should
search the TCP port report logs to see if the host has been scanning.
Note that nonscanning hosts in an “evil channel” are likely remote
botnet servers. It is a good idea to watch those hosts’ behavior with a
sniffer.

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   246   247   248   249   250   251   252   253   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish