RUS  ENG
Full version
JOURNALS // Uchenyye zapiski UlGU. Seriya "Matematika i informatsionnyye tekhnologii" // Archive

Uchenyye zapiski UlGU. Seriya "Matematika i informatsionnyye tekhnologii", 2021 Issue 2, Pages 63–74 (Mi ulsu53)

Botnet detection via server logs analysis

K. A. Sutyrkina, A. N. Burmistrov

Ulyanovsk State University, Ulyanovsk, Russia

Abstract: We've worked on botnets detection by analyzing real web-server logs. The special software product has been created to generate a sample of IP addresses, ports, and login/password pairs from the log le, which contains unsuccessful authorizations reports. As the result, a map of potential botnets was compiled, besides the most dangerous passwords, and a blacklist of IP addresses was obtained.

Keywords: botnet detection, analysis of log les, web server.

UDC: 004.056.5

Received: 30.11.2021



© Steklov Math. Inst. of RAS, 2024