Publication details

 

Chuck Norris botnet detection plugin

Basic information
Original title:Chuck Norris botnet detection plugin
Authors:Tomáš Plesník, Michal Trunečka, Pavel Piskač, Jan Vykopal, Pavel Čeleda
Further information
Citation:
Export BibTeX
Original language:English
Field:Informatics
WWW:Webová stránka s instalačním balíčkem
Type:Software
Keywords:Chuck Norris; NetFlow; detection; plugin; NfSen

Chuck Norris botnet detection plugin for NfSen collector periodically analyses NetFlow data. The plugin provides output of detection methods aimed at botnet behaviour during its lifecycle: port scanning from infected hosts outside the local network, scanning from infected hosts in the local network, communication with the botnet distribution and control servers, and DNS spoofing.

Related projects: