stratosphereips / StratosphereLinuxIPS

Slips, a free software behavioral Python intrusion prevention system (IDS/IPS) that uses machine learning to detect malicious behaviors in the network traffic. Stratosphere Laboratory, AIC, FEL, CVUT in Prague.
Other
687 stars 165 forks source link

Implement detection of blackmatter exfiltration #203

Open AlyaGomaa opened 1 year ago

AlyaGomaa commented 1 year ago

Created by Alya Gomaa via monday.com integration. 🎉

AlyaGomaa commented 2 months ago

https://blog.cyberproof.com/blog/blackmatter-cyber-attack-in-depth-analysis-2022

The idea is to work on some behavioral technique. like the stratosphere letters We need to detect this with behavior instead of protocol only. So SSH and HTTPS is good, maybe we should check that both are happeing? (or only one can happen at the same time?).

We need real traffic to analyze. Or we download or we execute

Then we should execute it and see how it works. But executing can be hard maybe download pcap from here: https://www.joesandbox.com/analysis/936186