ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Encrypted bots could be the next threat

Joris Evers CNET News.com

Published: 15 Nov 2005 10:55 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

In their quest to retain control over hijacked PCs, cybercriminals will add encryption to their malware to avoid detection and removal, one expert predicted on Monday.

In the near future, bots will include encryption to hide their presence from security and network sniffing tools often used to detect them, said Adam Meyers, an information assurance engineer at SRA International speaking at the Computer Security Institute conference in Washington.

"We will see encrypted sessions and as things become encrypted, we'll have a more difficult time investigating botnets," Meyers said.

Once it is installed on a PC, bot software typically connects to Internet Relay Chat to listen for commands. The IRC traffic can be a giveaway to the presence of bot software on a PC and can be spotted by security software such as intrusion detection systems (IDS) or protocol analysers, for example Ethereal.

"Bot creators will try to evade IDS' that might be looking for IRC connections and to avoid things like Ethereal," Meyers said. "They will do pretty much anything to obfuscate what they are doing. It is a constant change-off; with new techniques it will take some time for people on the investigatory side to get on the same page."

Bots are a serious computer security problem and law enforcement seems to just be catching up to it. Earlier this month, authorities announced the first bot-related arrest in the US . In October, police in the Netherlands said three men suspected of hijacking about 1.5 million PCs were arrested.

A computer that has bot software installed — for example through a malicious Web site or Trojan horse — is called a zombie. A network of zombies is referred to as a botnet. The zombies can be controlled remotely by the attacker, who can send commands while the owner is oblivious to what's happening.

Botnets are often rented out by their owners, called bot herders, to relay spam and launch phishing scams to steal sensitive personal data for fraud. Botnets have also been used in blackmail schemes, where the criminals threaten online businesses with a denial-of-service attack on their Web site to extort money.

The bot writers have a choice of a variety of encryption technologies, according to Meyers. They could use SSH, SSL, ROT-13 or a proprietary method, Meyers said. Such a bot would be harder to craft than today's bots, but worthwhile, he said.

"The longer they keep their bot in place, the better it is for them, the more money they are going to make," Meyers said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
64 out of 168 people found this useful



Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Software Engineers

Working in a large, diverse and technically expert team, in a totally unique working culture. Software Engineers Cheltenham What makes this work so ...

Web Manager

As part of the public sector NHS Professionals provides competitive salaries and access to numerous benefits including one of the best pension ...

Graduate Opportunities - M&G Group Operations Graduate Scheme

Within Group Operations, we have 3 graduate schemes and are looking to build our teams in the following areas:- - Information Systems Scheme ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment