Monitoring Malware Activity on the LAN Network
Monitoring Malware Activity on the LAN Network
复制标题
监控 LAN 网络上的恶意软件活动
DOI:
10.1007/978-3-642-13861-4_26
复制
发表时间:
2010
期刊:
影响因子:
--
通讯作者:
M. Skrzewski
中科院分区:
文献类型:
--
作者:
M. Skrzewski
Many security related organizations periodically publish current network and systems security information, with the lists of top malware programs. These lists raises the question how these threats spreads out, if the worms (the only threat with own communication abilities) are low or missing on these lists. The paper discuss the research on malware network activity, aimed to deliver the answer to the question, what is the main infection channel of modern malware, done with the usage of virtual honeypot systems on dedicated, unprotected network. Systems setup, network and systems monitoring solutions, results of over three months of network traffic and malware monitoring are presented, along with the proposed answer to our research question.