Главная
Study mode:
on
1
Introduction
2
Disclaimer
3
Agenda
4
Data Movement Chaos
5
Botnet Growth
6
Protocols
7
Basic CNC Architecture
8
Admin Panel
9
CNC Panels
10
Techniques
11
Static Analysis
12
Dynamic Analysis
13
Google Docs
14
Security Intelligence
15
Qualitative Analysis
16
Findings
17
TopLevel Domains
18
Entropy
19
Arms Race
Description:
Explore an empirical analysis of HTTP-based botnet Command and Control (C&C) panels in this 35-minute conference talk from BSidesSF 2018. Delve into the world of crimeware chaos as Aditya K Sood presents findings from examining thousands of real-world C&C web URLs used for deploying various types of malware. Gain insights into the characteristics, design, and technologies chosen by crimeware authors for HTTP-based C&C panels. Learn about data movement, botnet growth, protocols, and basic C&C architecture. Examine techniques for static and dynamic analysis, and understand the role of security intelligence in combating cybercrime. Discover key findings related to top-level domains, entropy, and the ongoing arms race between cybercriminals and security professionals.

Crimeware Chaos - Empirical Analysis of HTTP-Based Botnet C&C Panels

Security BSides San Francisco
Add to list
0:00 / 0:00