IDS mailing list archives

Re: Is there any malicious software web traffic detection tool or research?


From: "john lokka" <merigoth () gmail com>
Date: Wed, 11 Jun 2008 11:50:02 -1000

Thre are several programs available. I'd take a look at ARGUS and the
cisco netflow. There are more and more conference proceedings
involving netflow analysis techniques. Many cover worm detection, P2P
detection and botnet detection. Google 'netflow analysis' or ' network
traffic analysis'.


On Mon, Jun 9, 2008 at 9:11 PM, Qianli Zhang <zhang () cernet edu cn> wrote:
Hi all,
     At present, there are more and more web traffic caused by malicious
softwares. For example, some malicious plugin may periodly visit some sites
to improve their website's  ranking, or some plugins may periodly collect
the users usage profile. Is there some tool or research available to detect
such activities through web traffic analysis?  Thank you!
Regards,
seacxm


------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw
to learn more.
------------------------------------------------------------------------



------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it 
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw 
to learn more.
------------------------------------------------------------------------


Current thread: