Home > Ask the Security Experts > Expert Archive: Information Security Threats Questions & Answers > Will the botnet threat continue?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Will the botnet threat continue?

Ed Skoudis, past SearchSecurity.com expert EXPERT RESPONSE FROM: Ed Skoudis, past SearchSecurity.com expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 06 February 2007
Do you see botnets becoming a greater threat in 2007? Are there any new or emerging methods that seem to be especially effective in luring in victims?

>
Yes, I do. Botnets are collections of infected machines, often thousands or millions, that are under the control of a single attacker. On today's Internet, these are the bad guys' money-making machines. Attackers use botnets to drive advertising revenue with click-through ads. They can also steal credit card numbers for identity theft and spew spam for phishing attacks. Thus, based on the economics alone, I expect to see botnets become an even bigger issue in 2007.

Today, the most common method of luring victims into a botnet involves client-side exploitation, and I expect to see even more of it as we move through 2007. In these attacks, the bad guys send content via email or by hosting it on Web pages. This content, often Microsoft Word documents, PowerPoint presentations, PDF documents and the like, should not be executable. In these cases, the attacker's file is carefully formatted to exploit a vulnerability in the associated document-reading application. A huge number of vulnerabilities have been discovered in these applications recently.

Most users have been educated to avoid running attachments that contain executables, and many organizations' mail servers even filter out executable attachments. But with an exploit for a normal document-viewing application, any type of attachment can contain executable code. Thus, users who would never run a .exe might get infected by viewing a .doc, .ppt, PDF or other file type. It's a sad state of affairs, and I expect that we'll see much more of that infection vector in 2007.

More information:

  • DDoS attacks are still being launched from botnets. Ed Skoudis explains what ISPs are doing to combat them.
  • Are intrusion prevention systems enough to stop botnets?


  • BROWSE BY TAG
    Emerging Information Security Threats,   Expert Archive: Information Security Threats,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Emerging Information Security Threats
    Modern malware, stealthy botnets, adapt quickly, expert says
    New ransomware Trojan pushes victims to buy software
    Bruce Schneier on outsourcing, awareness training
    US-CERT warns of BlackBerry snooping software
    Marcus Ranum on cyberwarfare, infosec careers
    Researchers find thousands of flawed embedded devices
    Enterprise botnets contain thousands of malware variants
    Nuke and pave to eradicate botnets
    Rand study urges caution on cyberwarfare attacks
    Hathaway joins Harvard to contribute to DOD project

    Expert Archive: Information Security Threats
    The telltale signs of a network attack
    Will Google Chrome enhance overall browser security?
    Are there antivirus suites that pick up more than just run-of-the-mill viruses?
    What tools can a hacker use to crack a laptop password?
    Are social networking sites an easy target for malicious hackers?
    What are the dangers of cross-site request forgery attacks (CSRF)?
    Should social engineering tests be included in penetration testing?
    What kind of data is compromised during a Google hack?
    Best practices for using restriction policy whitelists
    Defining mobile device security concerns

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    DNS rebinding attack  (SearchSecurity.com)
    drive-by pharming  (SearchSecurity.com)
    JavaScript hijacking  (SearchSecurity.com)
    man in the browser  (SearchSecurity.com)
    phlashing  (SearchSecurity.com)
    polymorphic malware  (SearchSecurity.com)
    pulsing zombie  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts