Stories
Slash Boxes
Comments
typodupeerror delete not in

Book Reviews

Recent reviews from Slashdot readers:

Submitting a review for consideration is easy; please first read Slashdot's book review guidelines. Updated: 2008114 by samzenpus

Comments: 1 +-   Prototype software sniffs out , disrupts botnets-> on Friday February 15 2008, @02:57PM coondoggie

Submitted by coondoggie on Friday February 15 2008, @02:57PM
internet
coondoggie writes "Researchers this week detailed a prototype system to identify and eradicate botnets in the wild. Georgia Tech's BotSniffer uses network-based anomaly detection to identify botnet command and control channels in a local area network without any prior knowledge of signatures or server addresses, the researchers said. The idea is to ultimately detect and disrupt botnet infected hosts in the network. The researchers said their prototype, which was presented at the Internet Society's Network and Distributed System Security Symposium this week, is based on the fact that botnets engage in coordinated communication, propagation, and attack and fraudulent activities. BotSniffer, can capture network command and control protocols and utilize statistical algorithms to detect botnets. http://www.networkworld.com/community/node/25105"
Link to Original Source
submission

This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More
Loading... please wait.
  • Sounds a bit like a properly configured IDS/IPS system, in that it is simply a detection/prevention system that uses abnormality detection rather than signatures.

    Nothing new - another spin on something we are all too lazy to use.
I've run DOOM more in the last few days than I have the last few months. I just love debugging ;-) (Linus Torvalds)