| |
BotHunter® - Free Internet Release
|
|
|
12 MARCH 2008
--- NEW RELEASES AVAILABLE!
NEW: An Indepth Analysis of Storm Worm
BotHunter® is a novel, dialog-correlation-based
engine
(patent-pending), which
recognizes the communication patterns of malware-infected computers
within your network perimeter.
BotHunter® is a passive traffic monitoring system, which ties together
the dialog trail of
inbound intrusion alarms with those outbound communication patterns
that are highly indicative of successful local host infection. When a
sequence of in and outbound dialog warnings are found to match
BotHunter's infection dialog
model, a consolidated report is produced to capture all of the
relevant events and event sources that played a role during the
infection process.
Many thousands of downloads so far....
Some nice BotHunter news snippet. Thanks!
[SF Chronicle],
[MCP Magazine],
[Window IT Pro],
[ComputerWorld]
[PDF] publications - "BotHunter®:
Detecting Malware Infection Through IDS-Driven Dialog
Correlation"
in Proceedings of
the 16th USENIX Security Symposium,
August 2007.
_______________________________
Software
Requirements: This installation package is designed
for Fedora, SuSE, and Debian Linux systems. Read PREPARATION.txt regarding
installation assumptions and preparation.
_______________________________
DOWNLOAD BotHunter:
_______________________________
Visit
the LIVE BotHunter® Testing Page: http://www.cyber-ta.org/malware-analysis/public/
(BotHunter® is tested daily against live infections. Scores below 0.8 indicate missed detections).
|
|
|
|
|
|
Please send us your comments / questions / feedback:
|
|
|
|
|
|
|
Special
thanks to Cliff Wang at Army Research Office (ARO) and Carl Landwehr at
the Distruptive Technology Office (DTO) for their sponsorship of the
Cyber-Threat Analytics project.
|
|
|
|
BotHunter®
Distribution Page
Cyber-TA Project
Page last updated: 11 April 2008
| Project Details |
Project
Name: Cyber-TA
Application
Name: BotHunter
Project
Leads:
Phillip Porras (SRI
International) and
Wenke Lee (Georgia-Tech)
Development
Status: Active
Intended
Audience:
Security Researchers,
System Administrators
License: FREE to use.
Operating
System: Linux Fedora
and Debian, SuSE.
Programming
Language: Java 1.4,
1.5
Topic: Internet Security
Translations: English
User
Interface: Java 1.4,
1.5
Donors: ARO, DTO, NSF.
BotHunter
Contributors:
Phillip
Porras (SRI)
Guofei Gu
(Georgia-Tech)
Martin
Fong
(SRI)
Wenke Lee
(Georgia-Tech)
Keith Skinner
(SRI)
Vinod Yegneswaran (SRI)
Last
Website Update:
10/07/2007
Last
Software Update:
available
Last Plugin
Update:
comming soon
|
|