Get Adobe Flash player

Taking over the torpig botnet

In this paper, we report on our efforts to take control of the Torpig botnet and study its operations for a period of ten days. During this time, we observed more than 180 thousand infections and recorded almost 70 GB of data that the bots col- lected. While botnets have been “hijacked” and studied previously, the Torpig botnet exhibits certain properties that make the analysis of the data particularly interesting. First, it is possible (with rea- sonable accuracy) to identify unique bot infections and relate that number to the more than 1.2 million IP addresses that contacted our command and control server.

The paper may be downloaded at http://www.cs.ucsb.edu/%7Eseclab/projects/torpig/torpig.pdf

Share and Enjoy:
  • Digg
  • Facebook
  • email
  • Live
  • StumbleUpon
  • del.icio.us
  • Google Bookmarks
  • LinkedIn
  • Twitter

Leave a Reply

You must be logged in to post a comment.

Friends of Jonathan
Twitter highlights
areusecureareusecure: Woke up 7am with baby Edwin kicking and clinging to my face. Work this morning. I've sent my entry to the #SANS Forensic/Malware competition
3 months ago from Twitter for iPhone
areusecureareusecure: Work Work Work! Maltego 3 is released today (http://paterva.com/maltego). Have to find the time to play with it later this evening. #maltego
3 months ago from Twitter for iPhone
areusecureareusecure: @mubix Thanks, I replied a couple of minutes ago. Interesting stuff.
3 months ago from Twitter for iPhone
mubixmubix: @areusecure Thanks for the blog comment, I posted a reply
3 months ago from web

Jonathan James is Digg proof thanks to caching by WP Super Cache