SlideShare ist ein Scribd-Unternehmen logo
1 von 26
MALICIOUS TRAFFIC
Presented by Ishraq Fataftah
Agenda
   Introduction.
   What is Malicious traffic.
   Malicious traffic types.
   Malicious traffic detection and prevention.
   Conclusion.
Introduction
   As the internet become more
    mature, management of its resources to
    provide guaranteed services is crucial.
   The success of the Internet has increased its
    vulnerability to misuse and performance
    problems.
Introduction
   It has been frequently abused by people
    mostly with hostile intentions.
   We have been under various kinds of attacks
    such as viruses, worms and commonly a
    bunch of spam mails every day.
Introduction
Malicious Traffic
   It is hard to detect and distinguish malicious
    packet and legitimate packets in the traffic.
   The behavior of Internet traffic is very far from
    being regular.
   Presents large variations in its throughput at
    all scales.
Malicious Traffic
   Any traffic anomalies that occur from hardware
    or software failures to internet packets with
    maliciously modified options.
   Generated from what is called botnets.
Malicious Traffic: Botnets
Malicious Traffic
   Monitoring the flow of packets.
   Malicious traffic usually exhausts the legitimate
    resources by sending a lot of traffic.
   Monitoring traffic targeting unused addresses
    in the network.
Malicious Traffic Types
   Scanners.
   Worms.
   Malicious Spam.
   Backscatters.
   DOS, DDOS.
Scanners
 Single source.
 Strikes the same port on many machines.

 Different ports on the same machine.

 Generates

a lot of flows.
Worms
   Self-replicating virus that does not alter files
    but resides in active memory and duplicates
    itself.
   CodeRed worm infected 395,000 computers
    and resulted in approximately $2.6 billion in
    damage.
   Results in an increase in service
    activity, especially if service is law traffic.
Worms
MyTob Worm, 2005
                              Copies itself as %System%msnmsgs.exe
                              Adds the value: “MSN” = “msnmsgs.exe” to
              IRC Server       registry:
                               HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun
                               HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersion
                               RunServices
                               HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun
                               HKEY_CURRENT_USERSoftwareMicrosoftOLE
                               HKEY_CURRENT_USERSYSTEMCurrentControlSetControlLsa


                              W32.Mytob@mm runs every time Windows starts




  User Zone                    Server Zone
Malicious Spam
   Spamming is flooding the network with a huge
    amount of unsolicited email messages to force
    people to receive them.
   Contains malware or links to malicious sites.
Backscatter
   Email bounces for emails that a person didn’t
    send.
   Spammer is spoofing the Reply-to field in
    email.
   When sent to email server, it is bounces to the
    reply-to address rather than the sender.
   Used to overcome spam filters and in DOS
    attacks.
DOS, DDOS
   Generate a huge amount of adverse traffic to a
    target server to make it unavailable.
   Attempt to exhaust the resources of the victim.
   They are difficult to detect and prevent.
   DDOS attacks are simultaneously launched
    from several sources destined to the same
    target.
DOS, DDOS
Malicious traffic Detection and
Prevention
   Anomaly detection techniques.
   Signature-scan techniques.
   Intrusion detection and prevention systems.
   QoS metrics.
   Tools such as Snort.
   Network filters such as ACLs.
   Honeypots.
Anomaly detection techniques
   Differentiates between normal and malicious
    traffic by:
     Studying the normal behavior of users, resources.
     Create patterns for these activities.

     Any behavior that deviates from this pattern is
      considered malicious.
Signature-scan techniques
   Uses a database that store signatures.
   Passive scan for network traffic, any patterns
    match these stored signatures are considered
    malicious traffic.
   Effective for known attacks.
Intrusion detection and prevention
systems
   Software or hardware that is designed to
    detect and prevent any malicious attack or
    activity on the network.
   Monitor the network traffic.
   Analyze any suspicious event.
   Log these events and report them to the
    network administrator for actions.
QoS metrics
   Studying the behavior of the network traffic
    under normal and malicious attacks.
   Extracting parameters from network traffic.
Snort
   Open source tool that is used in intrusion
    detection systems.
   Real time analysis on the network traffic.
   Intrusion detection system to monitor the
    traffic, analyzes it and inform the network
    administrator for suspicious activities.
ACLs
   Installed in routers and used to match packet
    headers against a pre-defined list of rules and
    takes pre-defined actions on any matching
    packets.
Honeypots
“a security resource whose value lies in being
  probed, attacked or compromised”

   Any attempt to interact with honeypots incurs a
    malicious activity or attack.
Conclusion
   Malicious traffic is any traffic anomalies occurs
    from failure in traffic packets that is
    intentionally modified for malicious acts.
   By studying malicious attacks we can obtain
    better understanding of malicious traffic and
    how to detect and prevent these attacks.
   An increase in the awareness toward the
    importance of security will help in mitigation
    against internet misuse.

Weitere ähnliche Inhalte

Was ist angesagt?

Firewall and Types of firewall
Firewall and Types of firewallFirewall and Types of firewall
Firewall and Types of firewallCoder Tech
 
Intrusion prevention system(ips)
Intrusion prevention system(ips)Intrusion prevention system(ips)
Intrusion prevention system(ips)Papun Papun
 
Network Intrusion Detection System Using Snort
Network Intrusion Detection System Using SnortNetwork Intrusion Detection System Using Snort
Network Intrusion Detection System Using SnortDisha Bedi
 
DDoS - Distributed Denial of Service
DDoS - Distributed Denial of ServiceDDoS - Distributed Denial of Service
DDoS - Distributed Denial of ServiceEr. Shiva K. Shrestha
 
Intrusion detection and prevention system
Intrusion detection and prevention systemIntrusion detection and prevention system
Intrusion detection and prevention systemNikhil Raj
 
VULNERABILITY ( CYBER SECURITY )
VULNERABILITY ( CYBER SECURITY )VULNERABILITY ( CYBER SECURITY )
VULNERABILITY ( CYBER SECURITY )Kashyap Mandaliya
 
Intrusion Detection System
Intrusion Detection SystemIntrusion Detection System
Intrusion Detection SystemDevil's Cafe
 
Intrusion Detection System
Intrusion Detection SystemIntrusion Detection System
Intrusion Detection SystemMohit Belwal
 
Intrusion detection system
Intrusion detection systemIntrusion detection system
Intrusion detection systemAAKASH S
 
Intrusion Detection Systems
Intrusion Detection SystemsIntrusion Detection Systems
Intrusion Detection Systemsvamsi_xmen
 
DDoS Attack PPT by Nitin Bisht
DDoS Attack  PPT by Nitin BishtDDoS Attack  PPT by Nitin Bisht
DDoS Attack PPT by Nitin BishtNitin Bisht
 
Introduction To Intrusion Detection Systems
Introduction To Intrusion Detection SystemsIntroduction To Intrusion Detection Systems
Introduction To Intrusion Detection SystemsPaul Green
 
Intrusion detection system
Intrusion detection system Intrusion detection system
Intrusion detection system gaurav koriya
 
Intrusion Detection Systems and Intrusion Prevention Systems
Intrusion Detection Systems  and Intrusion Prevention Systems Intrusion Detection Systems  and Intrusion Prevention Systems
Intrusion Detection Systems and Intrusion Prevention Systems Cleverence Kombe
 
Metasploit
MetasploitMetasploit
Metasploithenelpj
 

Was ist angesagt? (20)

Firewall and Types of firewall
Firewall and Types of firewallFirewall and Types of firewall
Firewall and Types of firewall
 
Intrusion prevention system(ips)
Intrusion prevention system(ips)Intrusion prevention system(ips)
Intrusion prevention system(ips)
 
Network Intrusion Detection System Using Snort
Network Intrusion Detection System Using SnortNetwork Intrusion Detection System Using Snort
Network Intrusion Detection System Using Snort
 
Ddos attacks
Ddos attacksDdos attacks
Ddos attacks
 
IDS and IPS
IDS and IPSIDS and IPS
IDS and IPS
 
DDoS - Distributed Denial of Service
DDoS - Distributed Denial of ServiceDDoS - Distributed Denial of Service
DDoS - Distributed Denial of Service
 
Intrusion detection and prevention system
Intrusion detection and prevention systemIntrusion detection and prevention system
Intrusion detection and prevention system
 
Security threats and attacks in cyber security
Security threats and attacks in cyber securitySecurity threats and attacks in cyber security
Security threats and attacks in cyber security
 
VULNERABILITY ( CYBER SECURITY )
VULNERABILITY ( CYBER SECURITY )VULNERABILITY ( CYBER SECURITY )
VULNERABILITY ( CYBER SECURITY )
 
Intrusion Detection System
Intrusion Detection SystemIntrusion Detection System
Intrusion Detection System
 
Intrusion Detection System
Intrusion Detection SystemIntrusion Detection System
Intrusion Detection System
 
Intrusion detection system
Intrusion detection systemIntrusion detection system
Intrusion detection system
 
Intrusion Detection Systems
Intrusion Detection SystemsIntrusion Detection Systems
Intrusion Detection Systems
 
DDoS Attack PPT by Nitin Bisht
DDoS Attack  PPT by Nitin BishtDDoS Attack  PPT by Nitin Bisht
DDoS Attack PPT by Nitin Bisht
 
Introduction To Intrusion Detection Systems
Introduction To Intrusion Detection SystemsIntroduction To Intrusion Detection Systems
Introduction To Intrusion Detection Systems
 
Firewall
Firewall Firewall
Firewall
 
Intrusion detection system
Intrusion detection system Intrusion detection system
Intrusion detection system
 
Intrusion Detection Systems and Intrusion Prevention Systems
Intrusion Detection Systems  and Intrusion Prevention Systems Intrusion Detection Systems  and Intrusion Prevention Systems
Intrusion Detection Systems and Intrusion Prevention Systems
 
Firewalls
FirewallsFirewalls
Firewalls
 
Metasploit
MetasploitMetasploit
Metasploit
 

Andere mochten auch

Towards scalable locationaware
Towards scalable locationawareTowards scalable locationaware
Towards scalable locationawareIshraq Al Fataftah
 
Intrusion Detection System(IDS)
Intrusion Detection System(IDS)Intrusion Detection System(IDS)
Intrusion Detection System(IDS)shraddha_b
 
Introduction to Snort Rule Writing
Introduction to Snort Rule WritingIntroduction to Snort Rule Writing
Introduction to Snort Rule WritingCisco DevNet
 
Intrusion detection system ppt
Intrusion detection system pptIntrusion detection system ppt
Intrusion detection system pptSheetal Verma
 
Hacking & its types
Hacking & its typesHacking & its types
Hacking & its typesSai Sakoji
 

Andere mochten auch (8)

Towards scalable locationaware
Towards scalable locationawareTowards scalable locationaware
Towards scalable locationaware
 
Optimizing spatial database
Optimizing spatial databaseOptimizing spatial database
Optimizing spatial database
 
Password based cryptography
Password based cryptographyPassword based cryptography
Password based cryptography
 
Snort IDS/IPS Basics
Snort IDS/IPS BasicsSnort IDS/IPS Basics
Snort IDS/IPS Basics
 
Intrusion Detection System(IDS)
Intrusion Detection System(IDS)Intrusion Detection System(IDS)
Intrusion Detection System(IDS)
 
Introduction to Snort Rule Writing
Introduction to Snort Rule WritingIntroduction to Snort Rule Writing
Introduction to Snort Rule Writing
 
Intrusion detection system ppt
Intrusion detection system pptIntrusion detection system ppt
Intrusion detection system ppt
 
Hacking & its types
Hacking & its typesHacking & its types
Hacking & its types
 

Ähnlich wie Malicious traffic

Information security & EthicalHacking
Information security & EthicalHackingInformation security & EthicalHacking
Information security & EthicalHackingAve Nawsh
 
Computing safety
Computing safetyComputing safety
Computing safetyBrulius
 
Threat Hunting Playbook.pdf
Threat Hunting Playbook.pdfThreat Hunting Playbook.pdf
Threat Hunting Playbook.pdflaibaarsyila
 
CyberSecurity presentation for basic knowledge about this topic
CyberSecurity presentation for basic knowledge about this topicCyberSecurity presentation for basic knowledge about this topic
CyberSecurity presentation for basic knowledge about this topicpiyushkamble6
 
Type of Malware and its different analysis and its types !
Type of Malware and its different analysis and its types  !Type of Malware and its different analysis and its types  !
Type of Malware and its different analysis and its types !Mohammed Jaseem Tp
 
Malware Hunter: Building an Intrusion Detection System (IDS) to Neutralize Bo...
Malware Hunter: Building an Intrusion Detection System (IDS) to Neutralize Bo...Malware Hunter: Building an Intrusion Detection System (IDS) to Neutralize Bo...
Malware Hunter: Building an Intrusion Detection System (IDS) to Neutralize Bo...Editor IJCATR
 
An email worm vaccine architecture
An email worm vaccine architectureAn email worm vaccine architecture
An email worm vaccine architectureUltraUploader
 
Recipient Activated Malware Diffusion
Recipient Activated Malware DiffusionRecipient Activated Malware Diffusion
Recipient Activated Malware DiffusionBruce Fowler
 
Trojan horse and salami attack
Trojan horse and salami attackTrojan horse and salami attack
Trojan horse and salami attackguestc8c7c02bb
 
A review botnet detection and suppression in clouds
A review botnet detection and suppression in cloudsA review botnet detection and suppression in clouds
A review botnet detection and suppression in cloudsAlexander Decker
 
5 worms and other malware
5   worms and other malware5   worms and other malware
5 worms and other malwaredrewz lin
 
L N Yadav Cyber SECURITY.ppt
L N Yadav Cyber SECURITY.pptL N Yadav Cyber SECURITY.ppt
L N Yadav Cyber SECURITY.pptlowlesh1
 
L N Yadav Cyber SECURITY2.ppt
L N Yadav Cyber SECURITY2.pptL N Yadav Cyber SECURITY2.ppt
L N Yadav Cyber SECURITY2.pptlowlesh1
 
A REVIEW ON DDOS PREVENTION AND DETECTION METHODOLOGY
A REVIEW ON DDOS PREVENTION AND DETECTION METHODOLOGYA REVIEW ON DDOS PREVENTION AND DETECTION METHODOLOGY
A REVIEW ON DDOS PREVENTION AND DETECTION METHODOLOGYijasa
 
EXTERNAL - Whitepaper - How 3 Cyber ThreatsTransform Incident Response 081516
EXTERNAL - Whitepaper - How 3 Cyber ThreatsTransform Incident Response 081516EXTERNAL - Whitepaper - How 3 Cyber ThreatsTransform Incident Response 081516
EXTERNAL - Whitepaper - How 3 Cyber ThreatsTransform Incident Response 081516Yasser Mohammed
 
Chapter 2 konsep dasar keamanan
Chapter 2 konsep dasar keamananChapter 2 konsep dasar keamanan
Chapter 2 konsep dasar keamanannewbie2019
 
Types of attack -Part3 (Malware Part -2)
Types of attack -Part3 (Malware Part -2)Types of attack -Part3 (Malware Part -2)
Types of attack -Part3 (Malware Part -2)SHUBHA CHATURVEDI
 
computer virus ppt.pptx
computer virus ppt.pptxcomputer virus ppt.pptx
computer virus ppt.pptxAbiniyavk
 

Ähnlich wie Malicious traffic (20)

Security threats
Security threatsSecurity threats
Security threats
 
Information security & EthicalHacking
Information security & EthicalHackingInformation security & EthicalHacking
Information security & EthicalHacking
 
Computing safety
Computing safetyComputing safety
Computing safety
 
Threat Hunting Playbook.pdf
Threat Hunting Playbook.pdfThreat Hunting Playbook.pdf
Threat Hunting Playbook.pdf
 
CyberSecurity presentation for basic knowledge about this topic
CyberSecurity presentation for basic knowledge about this topicCyberSecurity presentation for basic knowledge about this topic
CyberSecurity presentation for basic knowledge about this topic
 
Type of Malware and its different analysis and its types !
Type of Malware and its different analysis and its types  !Type of Malware and its different analysis and its types  !
Type of Malware and its different analysis and its types !
 
Malware Hunter: Building an Intrusion Detection System (IDS) to Neutralize Bo...
Malware Hunter: Building an Intrusion Detection System (IDS) to Neutralize Bo...Malware Hunter: Building an Intrusion Detection System (IDS) to Neutralize Bo...
Malware Hunter: Building an Intrusion Detection System (IDS) to Neutralize Bo...
 
An email worm vaccine architecture
An email worm vaccine architectureAn email worm vaccine architecture
An email worm vaccine architecture
 
Recipient Activated Malware Diffusion
Recipient Activated Malware DiffusionRecipient Activated Malware Diffusion
Recipient Activated Malware Diffusion
 
Modern Malware and Threats
Modern Malware and ThreatsModern Malware and Threats
Modern Malware and Threats
 
Trojan horse and salami attack
Trojan horse and salami attackTrojan horse and salami attack
Trojan horse and salami attack
 
A review botnet detection and suppression in clouds
A review botnet detection and suppression in cloudsA review botnet detection and suppression in clouds
A review botnet detection and suppression in clouds
 
5 worms and other malware
5   worms and other malware5   worms and other malware
5 worms and other malware
 
L N Yadav Cyber SECURITY.ppt
L N Yadav Cyber SECURITY.pptL N Yadav Cyber SECURITY.ppt
L N Yadav Cyber SECURITY.ppt
 
L N Yadav Cyber SECURITY2.ppt
L N Yadav Cyber SECURITY2.pptL N Yadav Cyber SECURITY2.ppt
L N Yadav Cyber SECURITY2.ppt
 
A REVIEW ON DDOS PREVENTION AND DETECTION METHODOLOGY
A REVIEW ON DDOS PREVENTION AND DETECTION METHODOLOGYA REVIEW ON DDOS PREVENTION AND DETECTION METHODOLOGY
A REVIEW ON DDOS PREVENTION AND DETECTION METHODOLOGY
 
EXTERNAL - Whitepaper - How 3 Cyber ThreatsTransform Incident Response 081516
EXTERNAL - Whitepaper - How 3 Cyber ThreatsTransform Incident Response 081516EXTERNAL - Whitepaper - How 3 Cyber ThreatsTransform Incident Response 081516
EXTERNAL - Whitepaper - How 3 Cyber ThreatsTransform Incident Response 081516
 
Chapter 2 konsep dasar keamanan
Chapter 2 konsep dasar keamananChapter 2 konsep dasar keamanan
Chapter 2 konsep dasar keamanan
 
Types of attack -Part3 (Malware Part -2)
Types of attack -Part3 (Malware Part -2)Types of attack -Part3 (Malware Part -2)
Types of attack -Part3 (Malware Part -2)
 
computer virus ppt.pptx
computer virus ppt.pptxcomputer virus ppt.pptx
computer virus ppt.pptx
 

Mehr von Ishraq Al Fataftah

Mehr von Ishraq Al Fataftah (6)

Edge detection
Edge detectionEdge detection
Edge detection
 
Peer to-peer mobile payments
Peer to-peer mobile paymentsPeer to-peer mobile payments
Peer to-peer mobile payments
 
Publish subscribe model overview
Publish subscribe model overviewPublish subscribe model overview
Publish subscribe model overview
 
Requirement engineering evaluation
Requirement engineering evaluationRequirement engineering evaluation
Requirement engineering evaluation
 
Packet sniffing in switched LANs
Packet sniffing in switched LANsPacket sniffing in switched LANs
Packet sniffing in switched LANs
 
Presentation skills
Presentation skillsPresentation skills
Presentation skills
 

Kürzlich hochgeladen

Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brandgvaughan
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsMiki Katsuragi
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machinePadma Pradeep
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piececharlottematthew16
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Manik S Magar
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationSafe Software
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLScyllaDB
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024The Digital Insurer
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 

Kürzlich hochgeladen (20)

Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brand
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering Tips
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piece
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQL
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 

Malicious traffic

  • 2. Agenda  Introduction.  What is Malicious traffic.  Malicious traffic types.  Malicious traffic detection and prevention.  Conclusion.
  • 3. Introduction  As the internet become more mature, management of its resources to provide guaranteed services is crucial.  The success of the Internet has increased its vulnerability to misuse and performance problems.
  • 4. Introduction  It has been frequently abused by people mostly with hostile intentions.  We have been under various kinds of attacks such as viruses, worms and commonly a bunch of spam mails every day.
  • 6. Malicious Traffic  It is hard to detect and distinguish malicious packet and legitimate packets in the traffic.  The behavior of Internet traffic is very far from being regular.  Presents large variations in its throughput at all scales.
  • 7. Malicious Traffic  Any traffic anomalies that occur from hardware or software failures to internet packets with maliciously modified options.  Generated from what is called botnets.
  • 9. Malicious Traffic  Monitoring the flow of packets.  Malicious traffic usually exhausts the legitimate resources by sending a lot of traffic.  Monitoring traffic targeting unused addresses in the network.
  • 10. Malicious Traffic Types  Scanners.  Worms.  Malicious Spam.  Backscatters.  DOS, DDOS.
  • 11. Scanners  Single source.  Strikes the same port on many machines.  Different ports on the same machine.  Generates a lot of flows.
  • 12. Worms  Self-replicating virus that does not alter files but resides in active memory and duplicates itself.  CodeRed worm infected 395,000 computers and resulted in approximately $2.6 billion in damage.  Results in an increase in service activity, especially if service is law traffic.
  • 13. Worms MyTob Worm, 2005  Copies itself as %System%msnmsgs.exe  Adds the value: “MSN” = “msnmsgs.exe” to IRC Server registry: HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersion RunServices HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun HKEY_CURRENT_USERSoftwareMicrosoftOLE HKEY_CURRENT_USERSYSTEMCurrentControlSetControlLsa  W32.Mytob@mm runs every time Windows starts User Zone Server Zone
  • 14. Malicious Spam  Spamming is flooding the network with a huge amount of unsolicited email messages to force people to receive them.  Contains malware or links to malicious sites.
  • 15. Backscatter  Email bounces for emails that a person didn’t send.  Spammer is spoofing the Reply-to field in email.  When sent to email server, it is bounces to the reply-to address rather than the sender.  Used to overcome spam filters and in DOS attacks.
  • 16. DOS, DDOS  Generate a huge amount of adverse traffic to a target server to make it unavailable.  Attempt to exhaust the resources of the victim.  They are difficult to detect and prevent.  DDOS attacks are simultaneously launched from several sources destined to the same target.
  • 18. Malicious traffic Detection and Prevention  Anomaly detection techniques.  Signature-scan techniques.  Intrusion detection and prevention systems.  QoS metrics.  Tools such as Snort.  Network filters such as ACLs.  Honeypots.
  • 19. Anomaly detection techniques  Differentiates between normal and malicious traffic by:  Studying the normal behavior of users, resources.  Create patterns for these activities.  Any behavior that deviates from this pattern is considered malicious.
  • 20. Signature-scan techniques  Uses a database that store signatures.  Passive scan for network traffic, any patterns match these stored signatures are considered malicious traffic.  Effective for known attacks.
  • 21. Intrusion detection and prevention systems  Software or hardware that is designed to detect and prevent any malicious attack or activity on the network.  Monitor the network traffic.  Analyze any suspicious event.  Log these events and report them to the network administrator for actions.
  • 22. QoS metrics  Studying the behavior of the network traffic under normal and malicious attacks.  Extracting parameters from network traffic.
  • 23. Snort  Open source tool that is used in intrusion detection systems.  Real time analysis on the network traffic.  Intrusion detection system to monitor the traffic, analyzes it and inform the network administrator for suspicious activities.
  • 24. ACLs  Installed in routers and used to match packet headers against a pre-defined list of rules and takes pre-defined actions on any matching packets.
  • 25. Honeypots “a security resource whose value lies in being probed, attacked or compromised”  Any attempt to interact with honeypots incurs a malicious activity or attack.
  • 26. Conclusion  Malicious traffic is any traffic anomalies occurs from failure in traffic packets that is intentionally modified for malicious acts.  By studying malicious attacks we can obtain better understanding of malicious traffic and how to detect and prevent these attacks.  An increase in the awareness toward the importance of security will help in mitigation against internet misuse.

Hinweis der Redaktion

  1. threats may range from simple to severe functional and financial damage to the network infrastructure. Adding the legal perspective, these threats should be clearly and carefully identified, analyzed and managed.
  2. data is encapsulated in packets.
  3. Most flows are roughly symmetric at the packet levelWhenever a packet is sent, a packet is received within some reasonable interval (round trip time)This can me measured (and enforced) at the edge router inexpensively
  4. these botnets launch malicious traffic that attacks network hosts and internet service provider (ISPS).
  5. Malicious traffic can be detected by monitoring the network traffic using packet monitoring tools and studying any up normal or suspected behavior in the network. By monitoring the flow of packets, maliciously changed packets can be identified and infected computers can be determined based on its signature. In addition, malicious traffic usually exhausts the legitimate resources by sending a lot of traffic to halt its functionality. Another measurement can be by monitoring traffic targeting unused addresses in the network [3]. Unused addresses should expect a very limited load of traffic not mentioning that no device should be connected to it.
  6. Among all attacks, the denial-of-service (DoS) attack is one ofthe attacks rather difficult to detect and prevent since they exploitregular services, and overwhelm such services with tremendousmalicious traffic.
  7. Anomaly-detection first establishes a normal behavior pattern forusers, programs or resources in the system, and then looks for deviationfrom this behavior.signature-scan techniques passively monitor traffic seen on a network and detect an attack when patterns within the packet match predefined signatures in a database.They are a resource that has no authorized activity, they do not have any production value. Theoreticlly, a honeypot should see no traffic because it has no legitimate activity. This means any interaction with a honeypot is most likely unauthorized or malicious activity. Any connection attempts to a honeypot are most likely a probe, attack, or compromise. Snort’s open source network-based intrusion detection system (NIDS) has the ability to perform real-time traffic analysis and packet logging on Internet Protocol (IP) networks. Snort can be configured in three main modes: sniffer, packet logger, and network intrusion detection. Snort can be configured in three main modes: sniffer, packet logger, and network intrusion detection. the program will monitor network traffic and analyze it against a ruleset defined by the user. The program will then perform a specific action based on what has been identified