427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet300/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   296   297   298   299   300   301   302   303   ...   387
Bog'liq
Botnets - The killer web applications

T
IP
Based on the raw XML analysis report you are able to create your own
customized HTML or plain-text transformation. For that you will have to
create an XSL template, which contains instructions on how to parse an
XML document. There exist several tools for performing the transforma-
tion. One easy way to do this is by including a line like this in the XML
file (you need to use the correct filename of your XSL with the 
href
parameter): 

Interpreting an Analysis Report
The results that can be obtained from the analysis of a malware application
can be used mainly for two purposes: protecting and disinfecting the bot
hosting client systems and destroying the functionality of the currently
existing botnet. Obviously, the botnet will be left ineffective if all bots have
been disabled, but because it is not possible to deactivate all bots at the same
time and because there always is the risk of new infections, it is also very
important to shut down the C&C server. Important analysis results that can
be used for the purposes of removing and avoiding the infection of a bot
application and of shutting down the botnet may be:

Where does the bot application store its files on the infected system?

What mechanisms are used to automatically start the bot application
at system startup?

How does the bot protect the infected host from infection by other
malware?

How does the bot protect itself from detection and removal?

How are new infectable hosts found? 

What exploits/mechanisms are used to infect new hosts?

How does the bot connect to the C&C server(s), and what servers
are used? 

Where does the bot application get updates from?

What malicious operations are performed locally and remotely? 

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   296   297   298   299   300   301   302   303   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish