<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Italian Honey Project &#187; Paper</title>
	<atom:link href="http://www.honeynet.it/category/paper/feed" rel="self" type="application/rss+xml" />
	<link>http://www.honeynet.it</link>
	<description>The Italian chapter of the Honeynet Research Alliance</description>
	<lastBuildDate>Tue, 10 Aug 2010 12:54:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Pandalabs first Quarterly Report: botnets must rank high</title>
		<link>http://www.honeynet.it/intelligence/pandalabs-first-quarterly-report-botnets-must-rank-high</link>
		<comments>http://www.honeynet.it/intelligence/pandalabs-first-quarterly-report-botnets-must-rank-high#comments</comments>
		<pubDate>Wed, 31 Mar 2010 06:35:21 +0000</pubDate>
		<dc:creator>claudio.guarnieri</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Paper]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=211</guid>
		<description><![CDATA[
Among the major blights of the Internet today, botnets must rank pretty high. They are used to send spam (more than 90% of spam on the Internet has been sent through a botnet), launch denial of service attacks, operate pay-per-click fraud, steal data from users, etc. Yet this Quarter has brought positive news in the [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Among the major blights of the Internet today, botnets must rank pretty high. They are used to send spam (<strong>more than 90% of spam on the Internet has been sent through a botnet</strong>), launch denial of service attacks, operate pay-per-click fraud, steal data from users, etc.<br />
Yet this Quarter has brought positive news in the effort to combat botnets; only positive mind, as to talk about good news would hardly be appropriate onsidering that as I write, there are still hundreds of botnets controlling millions of computers around the world.</p>
<p>In mid-February, NetWitness announced the dismantling of a botnet called <strong>Kneber</strong>.<br />
This was widely reported in the media, given the startling nature of the statistics released: 75,000 computers infected across 2,500 organizations worldwide. Kneber was based on the infamous Zeus Trojan, which first appeared in 2007 and has been infecting users ever since.</p>
<p>By the end of the month, thanks to an action brought by Microsoft, a court order was issued to shut down the Internet connections of 277 domains used for sending commands to the Waledac botnet, one of the busiest and most notorious of the last two years, specialized in sending spam.</p></blockquote>
<p>From <a href="http://www.pandasecurity.com/img/enc/Quarterly_Report_Pandalabs_Q1_2010.pdf" target="_blank">Pandalabs Q1 2010 Quarterly Report</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/intelligence/pandalabs-first-quarterly-report-botnets-must-rank-high/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Attending EC2ND</title>
		<link>http://www.honeynet.it/uncategorized/attending-ec2nd</link>
		<comments>http://www.honeynet.it/uncategorized/attending-ec2nd#comments</comments>
		<pubDate>Tue, 27 Oct 2009 16:14:22 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Media]]></category>
		<category><![CDATA[Paper]]></category>
		<category><![CDATA[The Dorothy Project]]></category>
		<category><![CDATA[The Italian Honeynet Project]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=135</guid>
		<description><![CDATA[
I&#8217;m glad to inform that we will be attending the European Conference 2 Network Defence (EC2ND), scheduled on 9-10 November. This year the event is hosted by the Politecnico di Milano technical university in Milano, Italy. Me and marco will introduce the status of our  current activities. Hope to see you there!
]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m glad to inform that we will be attending the European Conference 2 Network Defence (<a href="http://2009.ec2nd.org/" target="_blank">EC2ND</a>), scheduled on 9-10 November. This year the event is hosted by the <a href="http://www.polimi.it/">Politecnico di Milano</a> technical university in Milano, Italy.<br />
Me and marco will introduce the status of our  current activities.</p>
<p>Hope to see you there!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/uncategorized/attending-ec2nd/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Taking over the Torpig botnet</title>
		<link>http://www.honeynet.it/botnet/taking-over-the-torpig-botnet</link>
		<comments>http://www.honeynet.it/botnet/taking-over-the-torpig-botnet#comments</comments>
		<pubDate>Mon, 04 May 2009 11:11:00 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Paper]]></category>

		<guid isPermaLink="false">http://m4rc00.wordpress.com/2009/05/04/taking-over-the-torpig-botnet/</guid>
		<description><![CDATA[
Interesting paper about the Torpig botnet. It&#8217;s a very accurate report about this botnet, and I suggest this paper to any botnet-researcher. I found very interesting the new technique ( called domain flux in this paper) used by Torpig for C&#38;C discovering. [..] With domain flux, each bot uses a domain generation algorithm (DGA) to [...]
]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.cs.ucsb.edu/%7Eseclab/projects/torpig/torpig.pdf">Interesting paper </a>about the Torpig botnet. It&#8217;s a very accurate report about this botnet, and I suggest this paper to any botnet-researcher.  I found very interesting the new technique ( called<span style="font-style:italic;"> domain flux</span> in this paper) used by Torpig for C&amp;C discovering.</p>
<blockquote><p>[..] With domain flux, each bot uses a domain generation algorithm (DGA) to compute<br />a list of domain names. This list is computed independently<br />by each bot and is regenerated periodically. Then, the bot attempts<br />to contact the hosts in the domain list in order until one succeeds,<br />i.e., the domain resolves to an IP address and the corresponding<br />server provides a response that is valid in the botnet’s protocol [..]</p></blockquote>
<p><a href="http://www.cs.ucsb.edu/%7Eseclab/projects/torpig/index.html#background">Here </a>is the project web site.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/taking-over-the-torpig-botnet/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
