Out Of The Box

Entries Comments


Being for the benefit of Mr. Kite!

29 September, 2009 (15:58) | Botnets, Fast-Flux, Honeynet Project, Projects, TIP | 2 comments

It’s long time since I don’t write about TIP and its evolution. A lot of things have changed during these last months in order to make TIP more efficient and scalable. So maybe it’s worth to talk about it! First of all, TIP really exploits the Twisted Plugin System as best as it can. As [...]

TIP Fast-Flux Tracking module new design

1 July, 2009 (16:54) | Botnets, Fast-Flux, Projects, TIP | No comments

Few days ago I started thinking about the scalability limits of the TIP Fast-Flux Tracking module and realized its design was really awful. The approach was based on the idea of assigning a monitoring thread to each fluxy domain. This approach is well suited if the number of threads is quite small but not for [...]

TIP – Fast Flux Tracking

7 January, 2009 (16:25) | Botnets, Fast-Flux, Projects, TIP | No comments

Today I came back from my Christmas holidays with the precise idea of rewriting the Fast Flux Tracking module from scratch. In fact, in the last days I observed strange behaviors during its working when the number of domains to monitor exceeded a few thousands. A deep investigation of the code revelead to me the [...]

Tracking Intelligence Project

19 December, 2008 (18:34) | Botnets, Fast-Flux, Malware, Projects, TIP | No comments

Eppur si muove!
TIP (Tracking Intelligence Project) is taking its first steps. In my most beautiful dreams, TIP should be an information gathering framework whose purpose is to autonomously collect Internet threat trends. Currently, TIP is closely monitoring information derived from few publicly available blacklists thus identifying malicious domains and networks. To reach its goal, TIP [...]

 

Bad Behavior has blocked 24 access attempts in the last 7 days.