Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



IDS: Re: backdoor detection

Re: backdoor detection

From: Jose Nazario <jose_at_monkey.org>
Date: Sun, 29 Dec 2002 20:11:10 -0500 (EST)

On Fri, 27 Dec 2002, Ramesh Gupta wrote:

> For detecting encrypted backdoors, one has to resort to statistical or
> timing analysis of traffic and anomaly detection methods.

in this vein, marius eriksen's tool "netics" could be useful:

        http://monkey.org/~marius/netics/http://monkey.org/~marius/netics/

imagine getting an average entropy and flow length for hosts and services
and then profiling against that. this way you could detect rogue sshd
services (ie on port 31337/tcp) or plaintext services in normally
encrypted traffic (ie an "https" server that's really a telnet proxy).

just a couple of examples.

___________________________
jose nazario, ph.d. jose_at_monkey.org
                                        http://www.monkey.org/~jose/
Received on Dec 30 2002

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos