Nemea: Searching for Botnet Footprints
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F68407700%3A21240%2F15%3A00230490" target="_blank" >RIV/68407700:21240/15:00230490 - isvavai.cz</a>
Result on the web
<a href="http://pesw2015.fit.cvut.cz/index.php?page=Program" target="_blank" >http://pesw2015.fit.cvut.cz/index.php?page=Program</a>
DOI - Digital Object Identifier
—
Alternative languages
Result language
angličtina
Original language name
Nemea: Searching for Botnet Footprints
Original language description
Malicious network traffic originated by malware means a serious threat. Current malware is designed to hide itself from the eyes of victim users as well as network administrators. It is very difficult or impossible to discover such traffic using traditional ways of flow-based monitoring. This paper describes a network traffic analysis of a backbone network as an attempt to discover infected devices. Cooperation with forensic laboratory and analysis of samples of malware allow to gain information that can lead to find unwanted traffic. Special tailored Nemea framework with high speed monitoring pipeline was used to discover infected devices on the network.
Czech name
—
Czech description
—
Classification
Type
D - Article in proceedings
CEP classification
IN - Informatics
OECD FORD branch
—
Result continuities
Project
—
Continuities
S - Specificky vyzkum na vysokych skolach<br>I - Institucionalni podpora na dlouhodoby koncepcni rozvoj vyzkumne organizace
Others
Publication year
2015
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Data specific for result type
Article name in the collection
Proceedings of the 3rd Prague Embedded Systems Workshop
ISBN
978-80-01-05776-6
ISSN
—
e-ISSN
—
Number of pages
6
Pages from-to
11-16
Publisher name
ČVUT FIT, Katedra číslicového návrhu
Place of publication
Praha
Event location
Roztoky u Prahy
Event date
Jul 2, 2015
Type of event by nationality
EUR - Evropská akce
UT code for WoS article
—