Title :
Botnet Statistical Analysis Tool for Limited Resource Computer Emergency Response Team
Author :
Kaemarungsi, Kamol ; Yoskamtorn, Nawattapon ; Jirawannakool, Kitisak ; Sanglerdsinlapachai, Nuttapong ; Luangingkasut, Chanin
Author_Institution :
Thai Comput. Emergency Response Team (ThaiCERT), Nat. Electron. & Comput. Technol. Center (NECTEC), Pathumthani, Thailand
Abstract :
Botnet is recognized as one of the fastest growing threat to the Internet and most users do not aware that they were victimized. ThaiCERT is one of many computer emergency response teams that have limited resources in term of budget to monitor and handle this kind of threat. An interim solution for teams with limited resource is to subscribe to the Shadowserver Foundation´s mailing list instead of deploying their own capturing and monitoring tools. The valuable information from the Shadowserver Foundation in form of plaintext e-mails may be difficult to manage and analyze. However, there is a need to analyze information provided by the Shadowserver Foundation to be able to efficiently handle botnet´s incidents for our own constituency. In this manuscript, we present our approach to handle the botnet threat using available information from the Shadowserver Foundation and describe our automate tool using by our incident handling team. Finally, we present our statistical data on botnet´s threat in our constituency over the last two years.
Keywords :
Internet; electronic mail; security of data; software agents; system monitoring; Internet threat; Shadowserver Foundation; ThaiCERT; botnet statistical analysis tool; computer emergency response team; monitoring tools; plaintext e-mails; Command and control systems; Computer security; Computerized monitoring; IP networks; Information analysis; Internet; Peer to peer computing; Software tools; Statistical analysis; Web server;
Conference_Titel :
IT Security Incident Management and IT Forensics, 2009. IMF '09. Fifth International Conference on
Conference_Location :
Stuttgart
Print_ISBN :
978-0-7695-3807-5
DOI :
10.1109/IMF.2009.13