Login, change your address, subscribe to new or manage current magazines or e-newsletter subscriptions
ComputerWorldNetwork WorldCIO CanadaCIO Canada Governments' ReviewJobUniverse Canada
Advanced Search
Knowledge Centres
Content Types
Featured White Papers
Unlock the potential of data with the right data warehouse solutionUnlock the potential of data with the right data warehouse solution read more
IBM Multiform Master Data Management: The evolution of MDM applicationsIBM Multiform Master Data Management: The evolution of MDM applications read more
Closing the data privacy gap: Protecting sensitive data in non-production environmentsClosing the data privacy gap: Protecting sensitive data in non-production environments read more
Yuk it Up
Green IT Playbook
Featured IT Quiz
IT Quiz: IT World Canada and IDC Canada want to know how your Green IT strategy is shaping up. Take this quiz to see how your company stacks up against other IT World Canada readers.
Featured White Papers
This white paper details Intel's current and future energy-saving initiatives to reduce costs and support business goals. Learn how Intel IT is extending its efforts to be a role model enterprise IT organization by supporting the Climate Savers Computing Initiative, which aims to drive a 50 percent reduction in computer-related CO2 emissions worldwide. No registration required.

Page 1 of 4

The botnet menace – and what you can do about it

Botnets – they're dangerous, deceptive, and very difficult to detect and deal with.

What's more, according to recent surveys, the botnet threat is growing…rapidly.

Experts say it's imperative that enterprises and consumers become aware of the acute and growing dangers posed by botnets, and take decisive and effective steps to counter them before it's too late. But that's easier said than done as botnets are insidious, and use stealth as a key weapon.

So what's a bot?

Botnets are networks of "bots" – short for robots. But these aren't the mechanical humanoids of science fiction; they're computers – large networks of captured and compromised computers.

After being commandeered, these machines may be used for a range of nefarious purposes, including scanning networks for other vulnerable systems, launching denial of service (DoS) attacks against a specified target, sending spam e-mails, and keystroke logging as a prelude to ID or password theft.

Botnets are generally created through spam e-mails or adware that leaves behind a software agent, also sometimes called a 'bot'.

When unsuspecting users click on a link, or open the delinquent e-mail, it downloads a software agent that turns their computers into botnet clients.

Read more

Don't miss part II of our coverage on the botnet menace: Seven smart strategies to battle botnets

Captured – or "botted" – machines can be controlled remotely by the malware creator – referred to as the bot master or bot herder.

If additional software has to be downloaded to complete the capture process, the bot would first do that, explains Jim Lippard director of information security operations at Florham Park, N.J.–based network services provider Global Crossing, in a podcast. "It may use any mechanism – FTP, TFTP, HTTP – to install the software."

Global Crossing's customers include more than 35 percent of the Fortune 500, as well as 700 carriers, mobile operators and ISPs.

The next thing the bot does is call home.

It would "usually do a domain name server (DNS) lookup on a particular name used by the miscreant for that botnet. Then it will find the host for that name, and connect to it using standard Internet Relay Chat (IRC) protocol," Lippard says.

The larger a botnet, the more formidable the attack it can launch.

Page 1 of 4
Send to a Friend  Rate This Page  Print This PageAdd a new comment
Bookmark this article on:
del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article? Add a new comment

If you find a comment inappropriate, You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields



Special Advertising Partners
IDC Case Study: Identity And Access Management Buying Criteria.
IDC analyses IAM buying criteria and deployment at Coppin State University. Coppin State replaces "first generation" IAM solution to obtain benefits needed for today's agile enterprise: ease of integration, rapid deployment, simplified compliance, flexibility.
White Papers
Closing the data privacy gap: Protecting sensitive data in non-production environments
How can IT organizations protect sensitive data, including employee and customer information, as well as corporate confidential data and intellectual property? Industry analysts recommend "de-identifying" or masking data as a best practice for protecting privacy. This white paper explains the importance of closing the data privacy gap in non-production environments, and provides guidance on effective data masking. Complimentary with registration. Sponsored by IBM.
Unlock the potential of data with the right data warehouse solution
Once you've made the decision to implement a new data warehouse, you want to make sure you choose the one that's right for your organization. This buyer's guide provides checklists for starting points that you can use when evaluating vendors and their products. Complimentary with registration. Sponsored by IBM.
Prepare for a more efficient SAP implementation: Take data issues off the critical path
This white paper outlines how the Preliminary Data Assessment Appliance (PDAA) from IBM can help address the challenges of integrating data from different operational applications across the enterprise to an SAP platform. Complimentary with registration. Sponsored by IBM.