R 2010

Chuck Norris botnet detection plugin

PLESNÍK, Tomáš, Michal TRUNEČKA, Pavel PISKAČ, Jan VYKOPAL, Pavel ČELEDA et. al.

Basic information

Original name

Chuck Norris botnet detection plugin

Name in Czech

Zásuvný modul pro detekci botnetu Chuck Norris

Authors

PLESNÍK, Tomáš (203 Czech Republic, belonging to the institution), Michal TRUNEČKA (203 Czech Republic, belonging to the institution), Pavel PISKAČ (203 Czech Republic, belonging to the institution), Jan VYKOPAL (203 Czech Republic, guarantor, belonging to the institution) and Pavel ČELEDA (203 Czech Republic, belonging to the institution)

Edition

2010

Other information

Language

English

Type of outcome

Software

Field of Study

10201 Computer sciences, information science, bioinformatics

Country of publisher

Czech Republic

Confidentiality degree

není předmětem státního či obchodního tajemství

RIV identification code

RIV/00216224:14610/10:00040931

Organization unit

Institute of Computer Science

Keywords in English

Chuck Norris; NetFlow; detection; plugin; NfSen

Technical parameters

Odpovědná osoba: Eva Janouškovcová, Masarykova univerzita, Centrum pro transfer technologií, Žerotínovo nám. 9, 601 77 Brno, tel.: +420 549 49 8016, e-mail: ctt@ctt.muni.cz

Tags

International impact
Změněno: 30/9/2013 17:55, doc. Ing. Pavel Čeleda, Ph.D.

Abstract

V originále

Chuck Norris botnet detection plugin for NfSen collector periodically analyses NetFlow data. The plugin provides output of detection methods aimed at botnet behaviour during its lifecycle: port scanning from infected hosts outside the local network, scanning from infected hosts in the local network, communication with the botnet distribution and control servers, and DNS spoofing.

Links

OVMASUN200801, research and development project
Name: CYBER ? Bezpečnost informačních a komunikačních systémů AČR - on line monitorování, vizualizace a filtrace paketů. Rozvoj schopností Computer Incident Response Capability v prostředí Cyber Defence. (Acronym: CYBER)
Investor: Ministry of Defence of the CR, CYBER - Security of Czech Army Information and Communication Systems - On-line Monitoring, Visualization and Packet Filtration. Computer Incident Response Capability Development in the Cyber Defence Environment