SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Departmental and End User Computing >> Small-Area Networking (SAN)

The botnet world is a booming world

The botnet world is a booming world

By:  Ellen Messmer  On: 13 Jul 2009 For: Network World (US online) (GM) Creator
 

The number of identified botnets has more than doubled in a year to 3,500, the ShadowServer Foundation says. Conficker isn’t doing much right now but Torpig has obtained sensitive banking information for more than 8,000 accounts.

The thriving world of botnet attacks continues to demand IT's attention.

With U.S. and South Korean government Web sites hit by distributed denial-of-service (DDoS) attacks by a botnet controlled by an unidentified attacker -- North Korea is suspected, however -- the shadowy world of botnets continues to grow unabated.

According to the ShadowServer Foundation, a group sharing information about botnet activity, the number of identified botnets, which started to take off about half a dozen years ago, has grown from about 1,500 two years ago to 3,500 today.

So far the botnet-directed attacks against the United States and South Korea, believed carried out through hidden manipulation of about 50,000 compromised computers using an updated version of an old virus, MyDoom, have done no lasting harm to the many Web sites struck, although several American government departments, including the  Federal Trade Commission and Department of Transportation suffered outages, while FTC.gov still is struggling, according to Keynote Systems, which measures and monitors Web site use. And the DDoS botnet episode is ongoing, with more hits expected on South Korean banks and a newspaper, says South Korean antivirus firm AhnLab, which analyzed malware samples associated with the attacks.

It's not just DDoS attacks that are associated with botnets. Botnets are usually specialized, designed for criminal tasks that range from spam distribution; stealing identity credentials such as passwords, bank account data or credit cards and keylogging; click fraud; and warez (stealing intellectual property or obtaining pirated software).

"There's usually a primary purpose to a botnet," says Jose Nazario, manager of security research at Arbor Networks. "There are turf wars out there as criminals are vying for the desktop. They try to kick each other off."

Although botnets come and go, the more successful ones have endured for years as large command-and-control systems operated by shadowy groups that have taken over hundreds of thousands of desktops and sometimes servers.

These botnets are bequeathed names -- usually quirky ones -- by researchers probing them, with the first to identify a new botnet typically getting to name it.

Gammima (gaming password stealer), Conficker (fake antivirus) and Zeus (information stealer), are among what are believed to be the largest, according to security firm Damballa.


But sizing botnets up in terms of actual numbers of compromised computers, under their control as bots (sometimes called "drones") is tough, many experts say.

That's because these numerical counts, typically based on detected numbers of infected machines, are often based on IP addresses where numbers are influenced up or down by network technologies such as network-address translation. And there's constant change.

The irony of Conficker, which has infected an estimated 1 million to 10 million machines and has made attempts to sell fake antivirus to its victims, is that it remains so quiet.


Sign up for our Newsletters

 












Print |  Views: 1896   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




ellen messmer Ellen Messmer is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Recent Canadian IT Jobs




Related Content

U.S. took China's place for most malware in 2008
U.S. took China's place for most malware in 2008Whether knowingly or not, American computers are making a 'disturbingly large' contribution to the distribution of viruses and span, says Sophos
Srizbi botnet active again
Srizbi botnet active again Back from the dead. The zombie computers of one of the world's largest botnets have sprung back to life barely two weeks after the network was reported to have been shut down
Estonia recovers from massive denial-of-service attack
Estonia recovers from massive denial-of-service attackA spree of denial-of-service (DOS) attacks against Web sites in Estonia appears to be subsiding, as the government calls for greater response mechanisms to cyber attacks within the European Union.
Websense buys Montreal UGC spam filter company
websense inc. has added technology that filters spam from user generated content, announcing it has bought montreal-based defensio, a two-year-old blog spam fighting company that claims 99.7 per cent accuracy.in a
blog comments powered by Disqus