ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Storm botnet 'services' could be sold

Tom Espiner ZDNet.co.uk

Published: 16 Oct 2007 15:25 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The owners of the Storm botnet, whose identities are as yet unknown, could be preparing to sell off the "services" of segments of the network, according to Joe Stewart, a researcher from managed security services company SecureWorks.

Stewart claimed in a blog post on Sunday that the latest Storm variants now use a 40-byte key to encrypt their peer-to-peer traffic, meaning each node will only be able to communicate with nodes that use the same key.

"This effectively allows the Storm author to segment the Storm botnet into smaller networks," wrote Stewart in his blog post. "This could be a precursor to selling Storm to other spammers, as an end-to-end spam botnet system, complete with fast-flux DNS and hosting capabilities. If that's the case, we might see a lot more of Storm in the future."

Fast-flux service networks are networks of compromised computer systems with public DNS records that are constantly changing, making it more difficult to track and control criminal activities, according to the Honeynet Project Research Alliance, a forum of honeypot research organisations. A honeypot is an system, often undefended, set up as a trap for attackers.

Stewart said that the good news is that security researchers can now distinguish encrypted Storm traffic from legitimate peer-to-peer traffic, making it easier for network administrators to detect Storm nodes on networks where firewall policies normally allow peer-to-peer traffic.

Antivirus vendor Sophos agreed that Stewart's analysis of the use of encryption to segment the Storm network for the purposes of resale is "probably correct".

Watch this

Video blog: Small businesses are ripping out VoIP

Chatting to analyst Clive Longbottom from Quocirca at IP'07, it seems that VoIP can be a complex beast – especially for smaller companies...

View video blog+

"Storm's use of encrypted traffic is an interesting feature which has raised eyebrows in our lab," said Graham Cluley, senior technology consultant at Sophos. "Its most likely use is for the cybercriminals to lease out portions of the network for misuse. It wouldn't be a surprise if the network was used for spamming, distributed denial of service attacks, and other malicious activities."

The Storm botnet was initially created at the beginning of 2007 when the Storm worm was spammed out, hiding in email attachments with a subject line of "230 dead as storm batters Europe". While it has continued to grow since then, it is difficult to gauge its true size as a large percentage of the infected machines are on 'stand-by', according to security expert Bruce Schneier.Schneier wrote in a blog post at the beginning of October that he was worried what Storm's creators had in store for Phase II of the botnet. "Oddly enough, Storm isn't doing much, so far, except gathering strength," Schneier wrote, adding that: "Aside from continuing to infect other Windows machines and attacking particular sites that are attacking it Storm has only been implicated in some pump-and-dump stock scams. There are rumours that Storm is leased out to other criminal groups. Other than that, nothing."

Schneier wrote that the Storm botnet authors had quietly been increasing the strength of the botnet by having small portions attacking other computers and then lying dormant, by using a yet-smaller fraction of the botnet to control compromised computers.

"Storm is designed like an ant colony, with separation of duties," wrote Schneier. "Only a small fraction of infected hosts spread the worm. A much smaller fraction are command-and-control servers. The rest stand by to receive orders. By only allowing a small number of hosts to propagate the virus and act as command-and-control servers, Storm is resilient against attack. Even if those hosts shut down, the network remains largely intact, and other hosts can take over those duties."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
9 out of 9 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Head of Medical Affairs - 100k, South East

Liaising with external agencies * Overall responsibility for corporate Regulatory compliance and interaction with Global Regulatory Affairs * ...

Enterprise Applications Finance Hyperion Consultant - Senior Manager - London

Production configuration and hand-over - Development of finance process training material - Delivery of training to new and experienced users - ...

Sytems Engineers - Portsmouth - 40-60K

Role profile: - System and software specifications - Verification and validation - Installation and deployment - Leading prototyping activities. I am ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment