Advertisement
Promo

Security threats Toolkit

RSA sees increase in fast-flux botnets

Tom Espiner ZDNet.co.uk

Published: 18 Mar 2008 12:56 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security vendor RSA has reported that it has seen an increase in the use of sophisticated techniques that hide command-and-control servers in networks of compromised computers. However, University of Cambridge researchers have disputed the claim, saying fast-flux use has remained constant over the past year.

Fast-flux is a DNS technique that distributes command-and-control by constantly reallocating the servers controlling peer-to-peer botnets. It makes those servers difficult to identify and shut down, as they "move" around the network. Fast-flux can also be associated with the allocation of proxy servers to hide static command-and-control servers in botnets.

RSA said on Monday that the technique, widely reported as being used by the controllers of the Storm botnet, is now being used by at least three other compromised networks.

"We've definitely seen an increase in the trend of using fast-flux as an attack vector," RSA director of financial services Andrew Moloney said on Monday.

RSA refused to name the botnets or the gangs involved, and said naming them would compromise its surveillance. Senior RSA researcher Uriel Maimon told ZDNet.co.uk that RSA had recently seen a gang using a combination of fast-flux DNS distributed command-and-control and routing all botnet traffic through proxy servers to further obfuscate the compromised networks.

However, researchers from the University of Cambridge have challenged RSA's claims, saying instead that the number of botnets using fast-flux has not increased in the past year but has remained constant.

"It has been fairly consistent for the past 12 months," said Tyler Moore, a researcher at the University of Cambridge Computer Laboratory. "We've mainly been tracking fast-flux websites used for phishing attacks but fast-flux networks are a for-hire service — people pay to host whatever they want."

Read this

Feature
Special report: The top five internal security threats

What should an employer watch out for?

Read more +

The researchers had not named the botnets, instead calling them "Fast-flux 1" and so on, and had detected three "pools" using fast-flux techniques.

Moore said that he had focused his research on group phishing sites, which attempt to dupe users into divulging sensitive information, and fast-flux sites claiming to sell pharmaceutical products.

Fast-flux sites are also used to recruit and interact with "money mules", who launder the proceeds of phishing crime for phishers.

The University of Cambridge researchers track which domains links in spam emails try to resolve to. Links to fast-flux networks automatically resolve to many different IP addresses.

Moore said that use of proxies to hide command-and-control servers, a technique most widely used by the Rock Phish gang, had also remained consistent for the past year.

"We don't track them beyond the proxies," said Moore. "We leave it to SOCA and the FBI to go after Rock Phish."

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
6 out of 6 people found this useful


Full Talkback thread

1 comment

  1. Botnets donp1927

Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

Campaigners criticise '£10bn NHS IT ov...

The National Health Service's flagship IT project has been criticised by a tax campaign group for running billions of pounds over budget. The NHS National Programme for IT (NPfIT)... More

2 comments

Climate research centre compromised

One of the UK's leading climate change research centres has had a security breach. The Climate Research Unit at the University of East Anglia (UEA) suffered a compromise of information,... More

1 comment

Government web-monitoring plans on hol...

Government plans to compel ISPs to process and store details of all web communications have been put on hold until after the next election. The Home Office told ZDNet UK on Wednesday... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters