260 likes | 273 Views
Learn about botnets, detection strategies, and countermeasures from an IT security expert. Case studies, prevention tips, and cybercrime insights covered. Contact via Twitter: @kiranratnakar
E N D
About Me – KiranRatnaker IT Security Researcher Certified Ethical Hacker Certified Forensic Investigator Certified Security Analyst WatchGuard Certified Professional Contact Twitter - @kiranratnakar
Agenda • What is BotNet • Botnet Detection • Countermeasures
Close Encounter with Botnet • Network of 150 Machines Dead • No Internet, No Local Server Access
Worst Things • No bot detection by AV • Websensefailed • Firewall proxy bottleneck • IP in exploit blacklist
How We Restored Network Operations? • Enabled Security features on LAN • ARP Spoofing Prevention, DoS Attack Prevention Settings, Broadcast...Multicast...Unicast Traps • Reduced network speed >Check for port utilizing high bandwidth > Shut it down > Format the machines
Challenges in Dev & QA Environment • Developer needs Admin Access • Innovation needs openness • QA Needs old versions • Port based applications is history • p2p apps on top & so as attacks
What is BotNet BotMaster • Botnet: Bot + Network • Compromised machine install programs which performs autonomus tasks, these Networked bots controlled by single botmaster with multiple command & control centers……. builds Botnet C&C C&C Bots Bots
How Botnet Spreads itself ? Peer to Peer
Cyber Crimes Ransomware Feck Id
2016 Cyberattack • Denial-of-service attack on DYN (Distributed Network Services, Inc.)
Detection • Symptoms • Benchmark • Machine Log • L3 Switch Log • Firewall Log
Benchmark • TCP/IP Connections on Machine & Firewall • 100 x 50 = 5000 Connections • What are the total Number of Machines as per Inventory & Logs • ARP on Switch = Number of Machines
Machine IP + Mac Address + VLAN Route + VLAN Broadcast on L3 Switch
Countermeasures • Daily Checks • IP Black List, Concurrent Connections, Botnet Ports, Deny Packets, Geolocation, DNS • Enable AV Firewall + IPS • Update Security Patches • Firmware Updates • Machines, Network Switches, Printers, WAP, Firewall • Install only required applications
Process Explorer Questions ? Microsoft Netmon Questions
AshishShanker ashish.shanker@synerzip.com @ShankerAshish +1.214.507.2843 • 22
Synerzip Accelerate the delivery of your product roadmap Address technology skill gaps Save at least 50% with offshore software development Augment your team with optional on-site professionals Your trusted outsourcing partner for Agile software product development.
Connect with Synerzip facebook.com/Synerzip @Synerzip linkedin.com/company/synerzip
Manging Software People & Teams on Thursday, March 16, 2017 at Noon CST Next Webinar Webinar Presenter: Ron Lichty, Author & Agile Consultant