Home > Ask the Security Experts > Expert Archive: Information Security Threats Questions & Answers > Is it possible to detect today's peer-to-peer (P2P) botnets?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Is it possible to detect today's peer-to-peer (P2P) botnets?

Ed Skoudis, past SearchSecurity.com expert EXPERT RESPONSE FROM: Ed Skoudis, past SearchSecurity.com expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 22 June 2007
How do today's peer-to-peer (P2P) botnets stack up against botnets of the past?


BROWSE BY TAG
Malware, Viruses, Trojans and Spyware,   Information Security Threats,   Emerging Information Security Threats,   Expert Archive: Information Security Threats,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Malware, Viruses, Trojans and Spyware
ISP shutdown latest cat-and-mouse game with hackers
How to get rid of malware, botnets on a hospital IT network
How can search results lead to malware?
Should a national cybersecurity strategy include offensive botnets?
How to prevent mobile phone spying
How to defend against rogue DHCP server malware
New Trojan stealing FTP credentials, attacking FTP websites
Cybercriminals exploit Michael Jackson, Farrah Fawcett deaths
When BIOS updates become malware attacks
Antispyware buying guide for Indian enterprises

Emerging Information Security Threats
Antispyware buying guide for Indian enterprises
ATM malware lets attackers take over machines
FTC shutters rogue ISP for hosting malicious content, botnets
The failing war against cybercriminals
White House cybersecurity czar faces major hurdles
Cybercrime and threat management
The Pipe Dream of No More Free Bugs
Face-off: Who should be in charge of cybersecurity?
Federal efforts to secure cyberinfrastrucure
Adobe working on patch to correct new zero-day flaw

Expert Archive: Information Security Threats
The telltale signs of a network attack
Will Google Chrome enhance overall browser security?
Are there antivirus suites that pick up more than just run-of-the-mill viruses?
What tools can a hacker use to crack a laptop password?
Are social networking sites an easy target for malicious hackers?
What are the dangers of cross-site request forgery attacks (CSRF)?
Should social engineering tests be included in penetration testing?
What kind of data is compromised during a Google hack?
Best practices for using restriction policy whitelists
Defining mobile device security concerns

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
bot worm  (SearchSecurity.com)
directory traversal  (SearchSecurity.com)
government Trojan  (SearchSecurity.com)
Kraken  (SearchSecurity.com)
man in the browser  (SearchSecurity.com)
polymorphic malware  (SearchSecurity.com)
RavMonE virus  (SearchSecurity.com)
RFID virus  (SearchSecurity.com)
Rock Phish  (SearchSecurity.com)
Zotob  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


P2P botnets are just plain evil, I tell ya. Historically, botnets used centralized architectures for command and control. In this architecture, each bot-infected machine logs into a shared communications resource, such as an IRC (Internet Relay Chat) channel, and seeks evil commands from a bot-herder. Even today, most botnets are designed this way.

But the centralized architecture causes problems for the bad guys: it creates a single point of failure. If diligent investigators shut down the IRC channel or even remove the server(s) associated with that channel, the botnet becomes headless. An attacker might have spent a lot of time and effort setting up a botnet of 500,000 machines, possibly earning thousands of dollars per day, too, from the malware being propagated. If the IRC channel disappears, however, the whole criminal enterprise is blown out of the water.

To remedy this situation, attackers are turning to peer-to-peer (P2P) communication. In such an approach, an active bot on a machine can scan for other close machines that might have the same bot, one that's controlled by the same attacker. The bot can then join a botnet cloud of encrypted P2P communications. The bots can find each other nearby, making the collective unit self-aware, multi-connected and self-healing. If a given bot notices that its communicating peers have disappeared, it looks for more. So, in this arrangement, there is no single point of failure. The attacker can inject commands into any part of the botnet cloud, using crypto-algorithms to implement authentication. The bots will then dutifully distribute the commands amongst themselves, as the message cascades through the P2P botnet.

P2P botnets are persistent and difficult to remove in their entirety. It's important to carefully analyze a bot specimen and how it authenticates itself to nearby bot peers. It's also useful to investigate how commands from the attacker are formulated and authenticated. This required level of examination demonstrates just how insidious the average bot specimen has become.

More information:

  • Learn more about the risks of P2P networks.
  • Will the botnet threat continue? Ed Skoudis weighs in on the debate.




  • Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts