Publication | Closed Access
nicter: An Incident Analysis System Toward Binding Network Monitoring with Malware Analysis
41
Citations
4
References
2008
Year
Unknown Venue
EngineeringInformation SecurityNetwork AnalysisInformation ForensicsSoftware AnalysisData ScienceSystems EngineeringNetwork ThreatsIntrusion Detection SystemThreat DetectionTactical Emergency ResponseNetworked Computer SystemsMacroscopic TrendsComputer ScienceNetwork ForensicsNetwork ScienceCyberweaponProgram AnalysisSoftware TestingAnti-virus TechniqueThreat HuntingCyber Threat IntelligenceBotnet DetectionNetwork MonitoringMalware Analysis
We have been developing the Network Incident analysis Center for Tactical Emergency Response (nicter), whose present focus is on detecting and identifying propagating malwares such as worms, viruses, and bots. The nicter presently monitors darknet, a set of unused IP addresses, to observe macroscopic trends of network threats. Meantime, it keeps capturing and analyzing malware executables in the wild for their microscopic analysis. Finally, these macroscopic and microscopic analysis results are correlated in order to identify the root cause of the detected network threats. This paper describes a brief overview of the nicter, and possible contributions to the Worldwide Observatory of Malicious Behavior and Attack Tools (WOMBAT).
| Year | Citations | |
|---|---|---|
Page 1
Page 1