ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Bot herders go low key

Dawn Kawamoto CNET News.com

Published: 18 Nov 2005 11:10 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Malicious makers of bots are finding big is not always better when it comes to avoiding detection, according to a security expert.

Over the past two years, the average network of bots, or compromised PCs commandeered by remote attackers, has dropped from more than 100,000 to an average of 20,000, Mark Sunner, MessageLabs's chief technology officer, said during Tuesday's annual Security Roundtable Webcast.

A botnet is comprised of a number of computers that have been surreptitiously compromised without their owners' knowledge. The move to pint-size botnets helps attackers have more success in delaying detection of their networks, Sunner said.

"When a larger botnet is spreading a virus, it lights up the switchboard of [antivirus] vendors, and they'll respond in a few hours with a signature to contain the outbreak," Sunner said.

"With a smaller botnet, it may take a day or so before it's discovered and a signature is written," he said.

Maksym Schipka, a senior antivirus researcher at MessageLabs, noted that two other issues have also contributed to the shrinking size of botnets.

First, an increase in the numbers of hackers hoping to put together networks has made the task of securing zombie computers more competitive, so it is harder for the "bot herder" to amass a larger number of drone computers.

Second, broadband users, the primary targets of hackers, are taking more steps to secure their computers.

Often, bots have been infected with software that will connect to an IRC server and await instructions from the malicious attacker. Botnets are often used to send out spam and can also be used to send out a flood of data to bring down a system in a distributed denial-of-service attack.

When a phishing scam is launched, antivirus companies will write signatures that identify the attack for their protective products. The more quickly antivirus vendors distribute a signature for a virus and customers deploy it, the less effective that particular botnet can be, Sunner said.

"As botnets get used up, they are blacklisted and less useful for spamming or phishing attacks," Sunner said. "But they get mopped up and are used for DoS attacks."

As DoS attacks don't directly use email or viruses, they won't be caught by blacklists or signature-based antivirus products. Last year, Sunner said his company began noticing old, worn-out spambots were being resold as potential DoS bots on various sites and forums used by attackers.

"People would advertise bots with 'fresh' machines, or ones that were mopped up," Sunner said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
95 out of 195 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Infrastructure Expert - Linux - Wintel - SQL - Hedge Fund

Infrastructure Expert required immediately for growing hedge fund based in West End. As Infrastructure Expert, you will carry out project work across ...

C++ Expert - Reading - STL, Design Patterns, OOA/OOD 50k-80k

C++ Expert Needed to join an international organisation in Reading. The ideal candidate will have expert level skills in C++, proven throughout their ...

C++ Expert

Pharmaceuticals, C++, Oracle, Server Side My client, one of the largest consutancy firms in the world is looking for a C++ expert to join their ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment