Houkutusjärjestelmien käyttö Internetin haittaohjelmien ja hyökkäysverkkojen torjunnassa

Tuohimetsä, Juuso · Aaltodoc (Aalto University) · 2010

Malware and botnets in particu1ar have become the preeminent instrument of Internet crime. This thesis demonstrates how honey pots can be applied against botnets and self-propagating malware in order to both better understand the current state of malware in the Internet as well as to mitigate the threats posed by botnets. We deploy a Nepenthes honeynet for a four-month period in a class C IPv4 network assigned to a major Finnish corporation and conduct in-depth analysis on the collected malware binaries by employing behavioural sandbox analysis and several anti-virus engines. Moreover, we inspect the honeynet traffic in detail and analyze, for example, the geographic locations of both attacking and malware hosting systems as well as the autonomous systems the attacks originate from. In addition to presenting our analysis results, we demonstrate in practice how the collected, data can he used to infiltrate active real-world IRC botnets in order to observe their operators and the attacks they initiate in real-time as well as to gain access to the malware repositories they use.

Read the paper · More papers on PaperTik