<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Italian Honey Project &#187; Paper</title>
	<atom:link href="http://www.honeynet.it/category/paper/feed" rel="self" type="application/rss+xml" />
	<link>http://www.honeynet.it</link>
	<description>The Italian chapter of the Honeynet Research Alliance</description>
	<lastBuildDate>Wed, 11 Jan 2012 11:44:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Dorothy @APWG in Dallas</title>
		<link>http://www.honeynet.it/botnet/dorothy-apwg-in-dallas</link>
		<comments>http://www.honeynet.it/botnet/dorothy-apwg-in-dallas#comments</comments>
		<pubDate>Thu, 14 Oct 2010 09:16:18 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Paper]]></category>
		<category><![CDATA[Project News]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[APWG]]></category>
		<category><![CDATA[Banking Trojan]]></category>
		<category><![CDATA[Conferences]]></category>
		<category><![CDATA[Dorothy]]></category>
		<category><![CDATA[Financial Botnet]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=366</guid>
		<description><![CDATA[
On next Tuesday (October 19) I&#8217;m going to present a research in progress paper that I wrote with the e-Crime team of Barcelona Digital and Marco Cremonini from Department of Information Technology of the Università degli Studi di Milano. The title of our paper is &#8220;A Framework For Financial Botnet Analysis&#8220;  and will be presented [...]
]]></description>
			<content:encoded><![CDATA[<p>On next Tuesday (October 19) I&#8217;m going to present a research in progress paper that I wrote with the e-Crime team of <a href="http://www.bdigital.org/EN/rdi/Pages/Security.aspx" target="_blank">Barcelona Digital</a> and Marco Cremonini from <a href="http://dti.unimi.it/"><em>Department of Information Technology</em></a> of the Università degli Studi di  <em>Milano.</em></p>
<p>The title of our paper is &#8220;<em>A Framework For Financial Botnet Analysis</em>&#8220;  and will be presented at the Anti Phishing Working Group (<a href="http://apwg.org/events/2010_gm.html#agenda">APWG</a>) conference that this year will be held in Dallas.  Our work  represents a research study that is still in progress that is  based on developing new detection and mitigation strategies to cope with financial botnets.</p>
<p>The proposed research partially relies on a customized version of the <em>Dorothy Framework</em> by improving its overall development status. The Italian Chapter of the <a href="http://www.honeynet.org/">Honeynet Project</a> is proud to see that its work is going to be useful also for such purpose, and this publication will encourage its future research.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/dorothy-apwg-in-dallas/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Attending EC2ND</title>
		<link>http://www.honeynet.it/uncategorized/attending-ec2nd</link>
		<comments>http://www.honeynet.it/uncategorized/attending-ec2nd#comments</comments>
		<pubDate>Tue, 27 Oct 2009 16:14:22 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Media]]></category>
		<category><![CDATA[Paper]]></category>
		<category><![CDATA[The Dorothy Project]]></category>
		<category><![CDATA[The Italian Honeynet Project]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=135</guid>
		<description><![CDATA[
I&#8217;m glad to inform that we will be attending the European Conference 2 Network Defence (EC2ND), scheduled on 9-10 November. This year the event is hosted by the Politecnico di Milano technical university in Milano, Italy. Me and marco will introduce the status of our  current activities. Hope to see you there!
]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m glad to inform that we will be attending the European Conference 2 Network Defence (<a href="http://2009.ec2nd.org/" target="_blank">EC2ND</a>), scheduled on 9-10 November. This year the event is hosted by the <a href="http://www.polimi.it/">Politecnico di Milano</a> technical university in Milano, Italy.<br />
Me and marco will introduce the status of our  current activities.</p>
<p>Hope to see you there!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/uncategorized/attending-ec2nd/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Taking over the Torpig botnet</title>
		<link>http://www.honeynet.it/botnet/taking-over-the-torpig-botnet</link>
		<comments>http://www.honeynet.it/botnet/taking-over-the-torpig-botnet#comments</comments>
		<pubDate>Mon, 04 May 2009 11:11:00 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Paper]]></category>

		<guid isPermaLink="false">http://m4rc00.wordpress.com/2009/05/04/taking-over-the-torpig-botnet/</guid>
		<description><![CDATA[
Interesting paper about the Torpig botnet. It&#8217;s a very accurate report about this botnet, and I suggest this paper to any botnet-researcher. I found very interesting the new technique ( called domain flux in this paper) used by Torpig for C&#38;C discovering. [..] With domain flux, each bot uses a domain generation algorithm (DGA) to [...]
]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.cs.ucsb.edu/%7Eseclab/projects/torpig/torpig.pdf">Interesting paper </a>about the Torpig botnet. It&#8217;s a very accurate report about this botnet, and I suggest this paper to any botnet-researcher.  I found very interesting the new technique ( called<span style="font-style:italic;"> domain flux</span> in this paper) used by Torpig for C&amp;C discovering.</p>
<blockquote><p>[..] With domain flux, each bot uses a domain generation algorithm (DGA) to compute<br />a list of domain names. This list is computed independently<br />by each bot and is regenerated periodically. Then, the bot attempts<br />to contact the hosts in the domain list in order until one succeeds,<br />i.e., the domain resolves to an IP address and the corresponding<br />server provides a response that is valid in the botnet’s protocol [..]</p></blockquote>
<p><a href="http://www.cs.ucsb.edu/%7Eseclab/projects/torpig/index.html#background">Here </a>is the project web site.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/taking-over-the-torpig-botnet/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

