Norwegian Honeynet Project


A chapter of the Honeynet Project

Fighting Back!

March 31st, 2009 by Tor Inge Skaar (1) News,Tools

Yesterday, The Honeynet Project released a brand new Know-Your-Enemy (KYE) paper titled; Containing Conficker. Previous papers about the Conficker variants (like SRI’s analysis) have focused on explaining the inner workings of the malware. The KYE paper, on the other hand, proposes new ideas on how to identify, mitigate and remove Conficker from compromised hosts.

The paper contains a wealth of excellent information and actionable intelligence for both security analysts and network/system engineers trying to defend against the vexing issue that is; Conficker. Together with the paper, a series of different open source tools have also been released:

The collection page includes the source code for all these tools and also Nebula-generated Snort signatures for Conficker.

Here is the link to the paper again, in case you missed it: PDF.

One Response to “Fighting Back!”

  1. Identifikasi Conficker di Jaringan Says:

    [...] Fighting Back dari Norwegian Honeynet Project. Ada open source tools seperti:   Domain Name Generation Tool, Memory Disinfectant, File and Registry Detector , Conficker Remote Scanner , Nonficker Vaccination Tool VN:F [1.1.6_502]please wait…Rating: 0.0/5 (0 votes cast)SHARETHIS.addEntry({ title: “Identifikasi Conficker di Jaringan”, url: “http://blog.unipro.co.id/archives/1069″ }); [...]

Leave a Reply