Indicator Expansion Techniques – Tracking Cyber Threats via DNS and Netflow Analysis
United States Computer Emergency Readiness Team (US-CERT) Detection and Analysis January 2011
Indicator Expansion Techniques Tracking Cyber Threats via DNS and - - PowerPoint PPT Presentation
Indicator Expansion Techniques Tracking Cyber Threats via DNS and Netflow Analysis United States Computer Emergency Readiness Team (US-CERT) Detection and Analysis January 2011 Background As the number or compromises escalates and our
Indicator Expansion Techniques – Tracking Cyber Threats via DNS and Netflow Analysis
United States Computer Emergency Readiness Team (US-CERT) Detection and Analysis January 2011
Background
As the number or compromises escalates and
imperative to create automated Operational solutions to feed your Computer Network Defense machine. Tracking cyber threats through the coupling of DNS data and netflow analysis allows for a much higher level of confidence in identification
Tools of the Trade
model leverages the following tools
Approach
timestamps
Approach Cont . . .
quickly identifying new IP addresses and/or new domain/IP address pair
Approach Cont . . .
repository
1 2 3 5 4
Indicators Expansion
Indicators Expansion cont …
192.168.2.34 on August 6, 2011
Indicator Expansion cont …
by ‘bob@comfort.com’ resolves to IP address 127.0.0.4
wicked.55chevy.cars.com resolve to 192.168.2.34 validating a link between the two domains
Command and Control IP’s and an unusual parking methodology
Applying Netflow ‘Current’
custom written PERL script called ‘set_manager.pl’
pmapfilter, rwsetbuild, rwsetintersect
the store
resolution flow traffic analysis could be on activity that is dated
Applying Netflow ‘Future’
List) and ‘set_manager.pl’
interface
categorization allowing for more accurate traffic stores
Applying Netflow ‘Future’ Cont …
timestamp of domain/IP address pair
in 2010
(reduces false positives)
Technical comments or questions US-CERT Security Operations Center Email: soc@us-cert.gov Phone: +1 888-282-0870 Media inquiries US-CERT Public Affairs Email: media@us-cert.gov Phone: +1 202-282-8010 General questions or suggestions US-CERT Information Request Email: info@us-cert.gov Phone: +1 703-235-5110 * Information available at http://www.us-cert.gov/contact.html