Knowledgebase

Portal Home > Knowledgebase > Abuse > Botware / Malware defense


Botware / Malware defense




Prevention:

  1. Ensure OS and software patches on the desktop are up to date.
  2. Disallow installation of new software on desktop (users have no administrative rights)
  3. Block domains that are known to be distributing malware.
        - Malware domains http://www.malwaredomains.com
        - C&C list http://www.emergingthreats.net/rules/bleeding-botcc.rules
        - RBN list http://www.emergingthreats.net/rules/bleeding-rbn.rules
  4. Utilize a different AV scanning on web proxy (defense in depth).
  5. Blocking IRC ports which offers some protection against older generation of botnets.
  6. Blocking all bad ports and make all traffic go through proxies, where traffic and anonymous behavior can be monitored.
  7. Browser hardening using Firefox Noscript and IE zones.
  8. Watch office documents in email, particularly from spoofed sources.  If the in coming source IP doesn't match the header information, drop the email.
  9. When performing JRE updates, ensure the old version get removed.
  10. Using HIPS (Host Intrusion Prevention System) to prevent potential harmful or abnormal behavior on the desktops.

 

Detection:

  1. Deploy listening nepenthes sensors on local IP space for early detection of infected machines.
  2. Deploy commercial and opensource detection systems - BotHunter, MainNerve .   
  3. Setting up internal darknets to detect bots that are wildly spreading thru blind network scans.
  4. Egress monitoring during off-hours to pick out phone homes.
  5. Monitor user-agent strings on the web proxy and detect anomalies.
  6. Content monitoring using Data Loss Monitoring systems.
  7. Scan for BHO (Browser Helper Object) and match it against known bad list such as the one at Castlecops.


Was this answer helpful?

Add to Favourites Add to Favourites    Print this Article Print this Article

Also Read
Chrootkit help (Views: 1387)
Brute Force Detection (Views: 1304)
Rootkit help (Views: 1370)

99.9% Network
Uptime Guaranteed
30 Days Moneyback
Guaranteed
24x7x24 Online
Customer Support