Using "New Port Browsing" Events to find Worm/Trojan/Rootkit Activity
by Ron Gula on January 12, 2007
Version 3.0 of the Passive Vulnerability Scanner (PVS) dynamical alerts when it finds "new" pieces of information about the network. Potential information includes open ports, browsed ports, OS fingerprints, client applications and network services. This blog entry discusses how the occurrence of "new browsed port" events can be used to look for various types of malicious behavior.
Browsed vs. Open Ports