Home > Security News > Research shows massive botnet growth
Security News:
EMAIL THIS

Research shows massive botnet growth

By Bill Brenner, Senior News Writer
26 Oct 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Online outlaws are growing botnets so fast that they're now able to take down the electronic infrastructure of entire nations, and Windows machines are their favorite accomplices. That's the gist of two new reports from McAfee Inc. and Microsoft Corp.

All this bot activity created so much noise on the network that it knocked down Internet access across the whole country.
Ken Baylor,
director of risk management, McAfee Inc.

Meanwhile, a handful of security vendors have formed a resource-sharing alliance to fight back.

The first report (.pdf), from Santa Clara, Calif.-based McAfee, focused on a series of attacks earlier this year in which botnets crippled the electronic infrastructure of a Central American country.

Ken Baylor, McAfee's director of risk management, said a global telecommunications company with a business unit in Central America experienced multiple network outages -- some lasting up to six hours -- that blocked Internet connectivity throughout the country and rendered automated teller machines useless. McAfee determined that botnets had taken down the infrastructure by launching distributed denial-of-service attacks. The telecom company deployed McAfee's IntruShield Network Intrusion Prevention System (IPS) to investigate what was causing the outages and prevent them in the future.

McAfee studied bot activity against the telecom company from April to September and found more than 6 million bot attacks per week in the country, which Baylor declined to name.

"All this bot activity created so much noise on the network that it knocked down Internet access across the whole country," Baylor said. "It also cut off the ability to use VoIP and withdraw money from ATM machines. This would last six hours at a time, two or three times a week."

Beating the bots:
Five steps for beating back the bots

Invasion force

How to protect your company against cybercrime

He said the findings are sobering for all nations, including the United States. "The U.S. has an advantage in that it has more bandwidth, so it would take more botnets to take the electronic infrastructure of the entire U.S. offline," he said. "But at the rate these botnets are growing, the bad guys could be within a year of that capability."

The second report (.pdf), from Microsoft, shows that Windows machines remain the target of choice for botnet herders.

Using intelligence it gathered using its Windows Malicious Software removal tool, Microsoft found that:

  • Backdoor Trojan horse programs and bots continue to be the top threat to Windows systems, with more than 43,000 new variants found in the first half of 2006.
  • Attackers are putting a significant amount of effort into these kinds of malware because of the potential for financial gain.
  • Of the 4 million computers Microsoft cleaned, approximately 2 million machines contained at least one backdoor Trojan.

The scope of the threat has convinced a handful of vendors that the only way to gain the upper hand is to share resources.

To that end, Simplicita Software Inc., Cloudmark, Inc., Habeas Inc., Sophos and an organization called Shadowserver have teamed up to create a global monitoring system Internet service providers can use to identify, quarantine and disinfect bot-infested computers on their networks. The new alliance is led by Simplicita via its Reputation Data Partner (RDP) Program.

"Early botmasters were unprofessional, but now they are intensely organized," said Simplicita CTO Rob Fleischman. "The bots are run by real and powerful criminals and it's a problem providers must address. The fight will swing in our favor if we fight them at the firewall, in the network and if we have partnerships like the one we've announced."

Danny Winokur, Simplicita's vice presidentVP of business development, said the companies involved were chosen because Simplicita saw their products as best-of-breed.

"Cloudmark has been a leader in antispam war, Habeas has an in-depth sender index and block list and has a lot of data on zombie machines and the Shadow Server Foundation has done a lot of research on command-and-control servers, which in turn helps them identify whole botnets," he said. "And Sophos is sharing a zombie alert service and phishing data."

Tags: Denial of Service (DoS) Attack PreventionHacker Tools and Techniques: Underground Sites and Hacking GroupsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Denial of Service (DoS) Attack Prevention
VeriSign extends DDoS attack protection service
Conficker authors prepping for next stage, researcher says
Latest DDoS attacks extremely unsophisticated, experts say
DDoS attacks hit U.S., South Korean government websites
How to prevent a denial-of-service (DoS) attack
I'll be watching you: Wireless IPS
How to prevent DDoS attacks on websites
How to prevent network denial-of-service attacks
What are 'phlashing' attacks?
Could someone place a rootkit on an internal network through a router?
Denial of Service (DoS) Attack Prevention Research

Hacker Tools and Techniques: Underground Sites and Hacking Groups
Metasploit Project acquisition ups ante for penetration testing market
Successful rogue antivirus hinges on social engineering
DEFCON survey suggests hacker community on vacation
DoD urges less network anonymity, more PKI use
New hacker skills optimize revenue
Maturing cybercriminal economy buoyed by business savvy hackers
Juniper pulls ATM hacking presentation from Black Hat
Botnet platform helps cybercriminals bid for zombie PCs
Man pleads guilty in online banking hacking scam
ATM malware lets attackers take over machines

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Electrohippies Collective  (SearchSecurity.com)
packet monkey  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts