Many different network and host-based security solutions have been developed in the past to counter the threat of autonomously spreading malware. Among the most common detection techniques for such attacks are network traffic analysis and the so-called honeypots. In this thesis, we introduce two new malware detection sensors that make use of the above mentioned techniques. The first sensor called Rishi, passively monitors network traffic to automatically detect bot infected machines. The second sensor called Amun follows the concept of honeypots and detects malware through the emulation of vulnerabilities in network services that are commonly exploited. Both sensors were operated for two years and collected valuable data on autonomously spreading malware in the Internet. From this data we were able to, for example, study the change in exploit behavior and derive predictions about preferred targets of todays' malware.
Tags: Informatik, EDV
Taschenbuch - 9783838127200 Verlag: Südwestdeutscher Verlag für Hochschulschriften AG Co. KG Ersterscheinung: Juli 2015 ISBN-13: 9783838127200 Größe: 220 mm x 150 mm x 14 mm Gewicht: 368 Gramm 236 Seiten Versandfertig in 3-5 Tagen.