Monitoring Malware Activity on the LAN Network

Monitoring Malware Activity on the LAN Network
复制标题

监控 LAN 网络上的恶意软件活动

DOI:
10.1007/978-3-642-13861-4_26
复制
发表时间:
2010
期刊:
--
影响因子:
--
通讯作者:
M. Skrzewski
M. Skrzewski
中科院分区:
--
文献类型:
--
作者:
M. Skrzewski

文献摘要

被引文献

相似文献

许多与安全相关的组织定期发布当前的网络和系统安全信息,以及顶级恶意软件程序的列表。这些列表提出了一个问题,如果蠕虫(唯一具有自身通信能力的威胁)在这些列表中很低或缺失,这些威胁将如何传播。本文讨论了恶意软件的网络活动的研究,旨在提供的问题的答案,什么是现代恶意软件的主要感染渠道,在专用的,不受保护的网络上使用虚拟蜜罐系统完成。系统设置,网络和系统监控解决方案,超过三个月的网络流量和恶意软件监控的结果,沿着我们的研究问题的建议答案。
Many security related organizations periodically publish current network and systems security information, with the lists of top malware programs. These lists raises the question how these threats spreads out, if the worms (the only threat with own communication abilities) are low or missing on these lists. The paper discuss the research on malware network activity, aimed to deliver the answer to the question, what is the main infection channel of modern malware, done with the usage of virtual honeypot systems on dedicated, unprotected network. Systems setup, network and systems monitoring solutions, results of over three months of network traffic and malware monitoring are presented, along with the proposed answer to our research question.