The show botnet-alertstats command displays the statistics related to advanced botnet detection by a Sensor.
This command has no parameters.
Syntax:
show botnet-alertstats
Information displayed by the show botnet-alertstats command includes the following:
The count of domains, IP addresses, and URLs detected based on the callback detectors
The count of DGA bots detected
The count of suspected DGA command and control servers detected
The count of communications from your network to DGA command and control servers
The count of activities monitored for FFSN
The count of communications from your network to the flux agents of FFSN
The count of command and control domains detected based on heuristics, such as protocol anomalies and DNS response failures
Sample Output:
Callback detector matches : 306
DGA Zombie detected : 5
DGA CnC Server Suspects detected : 25
DGA Zombie to CnC Server callbacks detected : 50
Ip Flux botnet activity detected : 30
IP Flux agent callback detected : 60
Other Zero day botnets detected : 25
Applicable to:
NS-series and Virtual IPS Sensors