CnCHunter - An MITM-Approach to Identify Live CnC Servers

CnCHunter - An MITM-Approach to Identify Live CnC Servers

Black Hat via YouTube Direct link

Introduction

1 of 19

1 of 19

Introduction

Class Central Classrooms beta

YouTube videos curated by Class Central.

Classroom Contents

CnCHunter - An MITM-Approach to Identify Live CnC Servers

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Introduction
  2. 2 CnCHunter
  3. 3 Goal
  4. 4 Previous Approaches
  5. 5 Our Solution
  6. 6 Overview
  7. 7 Communication protocols
  8. 8 Live CnC servers
  9. 9 Active probing
  10. 10 MITM component
  11. 11 Traffic analysis algorithm
  12. 12 Connection frequency and port frequency
  13. 13 CnCScore
  14. 14 Candidate Addresses
  15. 15 Criteria
  16. 16 Results
  17. 17 Results Summary
  18. 18 Demos
  19. 19 Conclusion

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.