Journal of Information System Security
Volume 1, Number 3 (2005)
Pages 4560
ISSN 1551-0123
Sanjay Goel — University at Albany, USA
Adnan Baykal — University at Albany, USA
Damira Pon — University at Albany, USA
Information Institute Publishing, Washington DC, USA




Botnets have become the dominant mechanism for launching distributed denial-of-service attacks on computer networks. In a recent incident, the computer network of an organization was attacked and disabled. This attack was initially identified by intrusion detection devices and verified by an onsite review of activity, audit of the log files, and subsequent detailed forensic analysis of the data, which revealed a botnet. The botnet was initiated via a worm infection consequent to which the infected machines attempted to join a bot network. The case presents a forensics analysis of the incident and provides the anatomy of the worm that was used to perform the attack. The paper also presents detection techniques for identifying botnets and disabling them in order to protect the network infrastructure.




Botnets, Bots, Zombie Computers, IRC, Distributed Denial-of-Service, Computer Forensics




