Главная
Study mode:
on
1
Intro
2
Malware Detection
3
Finding Malware using DNS logs
4
Malware Generic Description
5
Malware and DNS
6
Packet Captures
7
Back to DNS - Defensive Techniques
8
DGA (Domain Generation Algorithm)
9
Malware and DGA
10
Identifying Malicious DNS Traffic - Case Study
11
Identifying Malicious Traffic
12
Establish DNS Traffic Baseline
13
Baseline NXDOMAIN responses - cont'd
14
Query for Malicious Domains
15
Analyze DNS Traffic
16
Identifying Anomalous Domain Names
17
Tools
18
dnstop
19
Passive DNS
20
Analyze Network Traffic of Suspect Hosts
21
Notify Community
22
Can we attribute an attack?
23
Props
Description:
Explore techniques for detecting malware in networks using DNS logs in this 29-minute conference talk. Learn about malware detection methods, focusing on DNS-based approaches. Understand how malware interacts with DNS, analyze packet captures, and discover defensive techniques. Dive into Domain Generation Algorithms (DGA) and their role in malware operations. Examine case studies on identifying malicious DNS traffic, establishing DNS traffic baselines, and analyzing NXDOMAIN responses. Gain insights into querying for malicious domains, analyzing DNS traffic patterns, and identifying anomalous domain names. Discover useful tools like dnstop and Passive DNS for network analysis. Learn how to analyze network traffic of suspect hosts, notify the security community, and consider attack attribution possibilities.

Utilizing DNS to Discover Malware in Your Network

Add to list