The show botnet-alertstats command displays the statistics related to advanced botnet detection by a Sensor.
This command has no parameters.
Syntax:
show botnet-alertstats
Information displayed by the show botnet-alertstats command includes the following:
- The count of domains, IP addresses, and URLs detected based on the callback detectors
- The count of DGA bots detected
- The count of suspected DGA command and control servers detected
- The count of communications from your network to DGA command and control servers
- The count of activities monitored for FFSN
- The count of communications from your network to the flux agents of FFSN
- The count of command and control domains detected based on heuristics, such as protocol anomalies and DNS response failures
Sample Output:
Callback detector matches : 306
DGA Zombie detected : 5
DGA CnC Server Suspects detected : 25
DGA Zombie to CnC Server callbacks detected : 50
Ip Flux botnet activity detected : 30
IP Flux agent callback detected : 60
Other Zero day botnets detected : 25
Applicable to:
NS-series and Virtual IPS Sensors