next up previous contents
Next: Analysis Up: Raffael_Marty_GCIA Previous: Contents   Contents

Executive Summary

This report shows an in-depth analysis of intrusion detection logs gathered between the months of August and November 2002.

The data analyzed shows signs of intrusions and machines compromised by backdoors and worms. The following findings need immediate attention; the analysis in this report gives the necessary details and support for calling the attention to these incidents:

Whereas the above finding should be immediately addressed, there are some more recommendations that should be addressed:

We found that the data sets were already analyzed by many other GCIA students. Instead of repeating their analysis, we decided to approach the problem slightly different, by emphasizing the ways of analyzing such a data set. The paper is therefore a little weaker on the analysis of specific incidents and focuses more on the approach of getting a handle of a big data set. We will first give a very generic overview of the data found in the log files. After determining the topology, we will outline some anomalies (Chapter 2) and then establish some hypotheses on how to find suspicious behavior in a generic way (see Chapter 3).

We had to take two Sections out of this paper as it grew too big. We did not want to loose our main Sections where we came up with interesting ways of analyzing the data but put some of the ``ordinary'' analysis Sections on a Web page: http://raffy.ch/projects/Raffael_Marty_GCIA_Additional_Chapters.pdf.

Before I forget: Thanks to Christian for helping me with AfterGlow[14] and Colby for having a quick glance at the paper before submission.


next up previous contents
Next: Analysis Up: Raffael_Marty_GCIA Previous: Contents   Contents
Raffy 2004-12-20