Botnets: The Killer Web Applications

Schiller, Craig; Binkley, James R.

In stock
Regular price 19.250 KD inc. VAT
License
Table of contents
  • Cover
  • Contentsix
  • Chapter 1. Botnets: A Call to Action1
  • Introduction2
  • The Killer Web App3
  • How Big Is the Problem?4
  • The Industry Responds22
  • Summary24
  • Solutions Fast Track25
  • Frequently Asked Questions26
  • Chapter 2. Botnets Overview29
  • What Is a Botnet?30
  • The Botnet Life Cycle31
  • What Does a Botnet Do?42
  • Botnet Economics62
  • Summary70
  • Solutions Fast Track70
  • Frequently Asked Questions73
  • Chapter 3. Alternative Botnet C&Cs77
  • Introduction: Why Are There Alternative C&Cs?78
  • Historical C&C Technology as a Road Map79
  • DNS and C&C Technology81
  • Alternative Control Channels82
  • Web-Based C&C Servers83
  • Summary93
  • Solutions Fast Track94
  • Frequently Asked Questions95
  • Chapter 4. Common Botnets97
  • Introduction98
  • SDBot98
  • RBot104
  • Agobot111
  • Spybot118
  • Mytob123
  • Summary128
  • Solutions Fast Track129
  • Frequently Asked Questions131
  • Chapter 5. Botnet Detection: Tools and Techniques133
  • Introduction134
  • Abuse134
  • Network Infrastructure: Tools and Techniques140
  • Intrusion Detection155
  • Darknets, Honeypots, and Other Snares176
  • Forensics Techniques and Tools for Botnet Detection179
  • Summary208
  • Solutions Fast Track208
  • Frequently Asked Questions213
  • Chapter 6. Ourmon: Overview and Installation217
  • Introduction218
  • Case Studies:Things That Go Bump in the Night220
  • How Ourmon Works227
  • Installation of Ourmon232
  • Summary239
  • Solutions Fast Track240
  • Frequently Asked Questions241
  • Chapter 7. Ourmon: Anomaly Detection Tools245
  • Introduction246
  • The Ourmon Web Interface247
  • A Little Theory252
  • TCP Anomaly Detection255
  • UDP Anomaly Detection272
  • Detecting E-mail Anomalies275
  • Summary279
  • Solutions Fast Track279
  • Frequently Asked Questions283
  • Chapter 8. IRC and Botnets285
  • Introduction286
  • Understanding the IRC Protocol286
  • Ourmon’s RRDTOOL Statistics and IRC Reports290
  • Detecting an IRC Client Botnet298
  • Detecting an IRC Botnet Server304
  • Summary309
  • Solutions Fast Track309
  • Frequently Asked Questions311
  • Chapter 9. Advanced Ourmon Techniques313
  • Introduction314
  • Automated Packet Capture314
  • Ourmon Event Log324
  • Tricks for Searching the Ourmon Logs325
  • Sniffing IRC Messages329
  • Optimizing the System334
  • Summary339
  • Solutions Fast Track339
  • Frequently Asked Questions343
  • Chapter 10. Using Sandbox Tools for Botnets345
  • Introduction346
  • Describing CWSandbox348
  • Examining a Sample Analysis Report359
  • Interpreting an Analysis Report368
  • Bot-Related Findings of Our Live Sandbox383
  • Summary385
  • Solutions Fast Track387
  • Frequently Asked Questions390
  • Chapter 11. Intelligence Resources391
  • Introduction392
  • Identifying the Information an Enterprise/University Should Try to Gather392
  • Places/Organizations Where Public Information Can Be Found398
  • Membership Organizations and How to Qualify403
  • Confidentiality Agreements404
  • What to Do with the Information When You Get It407
  • The Role of Intelligence Sources in Aggregating Enough Information to Make Law Enforcement Involveme409
  • Summary411
  • Solutions Fast Track411
  • Frequently Asked Questions414
  • Chapter 12. Responding to Botnets417
  • Introduction418
  • Giving Up Is Not an Option418
  • Why Do We Have This Problem?420
  • What Is to Be Done?429
  • A Call to Arms445
  • Summary447
  • Solutions Fast Track448
  • Frequently Asked Questions451
  • Appendix A: FSTC Phishing Solutions Categories453
  • Index459
Book details
  • Vendor Elsevier S & T
  • SKU 9781597491358
  • ISBN-13 9780080500232
  • Author Schiller, Craig; Binkley, James R.
  • Category Computers
  • Subject Computer Science

Do you have questions about this book?

Ask an expert!

The book begins with real world cases of botnet attacks to underscore the need for action. Next the book will explain botnet fundamentals using real world examples. These chapters will cover what they are, how they operate, and the environment and technology that makes them possible. The following chapters will analyze botnets for opportunities to detect, track, and remove them. Then the book will describe intelligence gathering efforts and results obtained to date. Public domain tools like OurMon, developed by Jim Binkley of Portland State University, will be described in detail along with discussions of other tools and resources that are useful in the fight against Botnets.

* This is the first book to explain the newest internet threat - Botnets, zombie armies, bot herders, what is being done, and what you can do to protect your enterprise
* Botnets are the most complicated and difficult threat the hacker world has unleashed - read how to protect yourself