funsec mailing list archives

Re: BBN botnet detection efforts?


From: Roland Dobbins <rdobbins () cisco com>
Date: Thu, 6 Oct 2005 08:56:34 -0700


Nope - sounds like another siloed research team with no knowledge of the current state of the art or of ongoing efforts and the history and context behind them.

If anyone has contacts at BBN, it would probably be a good idea to reach out to them and work on bringing them into the fold.

On Oct 6, 2005, at 3:45 PM, Fergie (Paul Ferguson) wrote:

Has anyone heard anything about this?

Excerpt:

[snip]

Despite the lack of research being done on the issue, Strayer's team is making good progress in being able to monitor Internet traffic for signs of botnet flows -- to the point where the team is actually able to classify different types of packets. But progress is being hindered by the nature of life on the Internet.

[snip]

 http://www.newsfactor.com/story.xhtml?story_id=38365

- ferg


--
"Fergie", a.k.a. Paul Ferguson
 Engineering Architecture for the Internet
 fergdawg () netzero net or fergdawg () sbcglobal net
 ferg's tech blog: http://fergdawg.blogspot.com/

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


-------------------------------------------------------------------
Roland Dobbins <rdobbins () cisco com> // 408.527.6376 voice

UNIX was not designed to stop you from doing stupid things, because
that would also stop you from doing clever things.

                      -- Doug Gwyn
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: