Series
Master of Science in Computer Science
Master of Science in Computer Science
Permanent Link
Series Type
Degree Series
Description
Associated Organization(s)
Associated Organization(s)
Organizational Unit
Publication Search Results
Now showing
1 - 1 of 1
-
ItemHoneynet design and implementation(Georgia Institute of Technology, 2007-12-20) Artore, DianeOver the past decade, webcriminality has become a real issue. Because they allow the botmasters to control hundreds to millions of machines, botnets became the first-choice attack platform for the network attackers, to launch distributed denial of service attacks, steal sensitive information and spend spam emails. This work aims at designing and implementing a honeynet, specific to IRC bots. Our system works in 3 phasis: (1) binaries collection, (2) simulation, and (3) activity capturing and monitoring. Our phase 2 simulation uses an IRC redirection to extract the connection information thanks to a IRC redirection (using a DNS redirection and a "fakeserver"). In phase 3, we use the information previously extracted to launch our honeyclient, which will capture and monitor the traffic on the C&C channel. Thanks to our honeynet, we create a database of the activity of IRC botnets (their connection characteristics, commands on the C&C ), and hope to learn more about their behavior and the underground market they create.