On TechRepublic: Windows 7: Slower to boot than Vista?
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Mar 14, 2005 9:31:00 PM

Botnets, collections of compromised computers controlled by a single person or group, have become more pervasive and increasingly focused on identity theft and installing spyware, according to a Honeynet Project report.

The report, released on Monday, summarizes the findings of researchers who have tapped into more than 100 different botnets since last summer. Some of the networks were made up of more than 50,000 computers, said the Honeynet Project, a security group that sets up heavily monitored systems, or honeypots, and allows them to be attacked.

While many of the networks had been used to hit other botnets with denial-of-service attacks, others had been used to gather sensitive identity information and install adware and spyware, a practice that is increasing, said Thorsten Holz, a computer science research student at RWTH Aachen University of Technology in Germany and one of the primary authors of the paper.

"Our research shows that some attackers are highly skilled and organized, potentially belonging to some well-organized crime structures," Holz, a member of the Honeynet Project, wrote in the paper. "Even in unskilled hands, it should be obvious that botnets are a loaded and powerful weapon."

Over the past year, security experts have become increasingly wary of botnets. Once used mainly by online vandals to attack each other, the large networks of compromised computers are now a tool for groups of criminals bent on making money through identity fraud or adware installation. A person whose computer is infected with bot software runs the risk of having sensitive information such as account passwords and credit card numbers sent to the controller of the network.

A botnet onslaught is believed to have caused an outage at Internet service provider Akamai Technologies last summer.

At least a million computers worldwide are unwitting hosts to bot software, Honeynet researchers calculate--but that's a conservative estimate, Holz wrote in the report. A typical bot could be connected to 10,000 other computers, use the old-school Internet chat system--known as IRC--for command and control, and have a plug-in architecture that allows new features to be quickly added, he noted.

The report also describes how the researchers monitored the bots and intercepted communications. The Honeynet Project plans to release the software programs it developed to the community at large.

Some interesting applications of the malicious networks have been noticed by researchers, Holz said in an interview. In one case, bot software detected whether the game "Diablo II" was installed on the host PC. If the game was present, the program would steal items from the player's characters and drop them at preplanned places in the online game world. The botnet's controller would then collect the items and sell them on auction site eBay, Holz said.

"It was pretty clever and hard to detect," he said.

Future botnets will likely move to peer-to-peer communications, which are harder to intercept and shut down, Holz said. Moreover, there is a trend toward smaller numbers of bots in each network--a measure that makes the collection of compromised computers that much harder to detect, he said. While a network of 3,000 to 8,000 computers is harder to detect than one of 20,000, it can be as damaging, he added.

"Even those small botnets can cause much harm, especially if the compromised machines have good Internet connectivity or are located within interesting places," Holz said.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 37 Talkback(s)
It is not
surprizing that the infected ms windows PCs are using these 'remote services' privileged ports.

What were they thinking? Didn't they do any authentication at all on the requests comming to the... (Read the rest)
Posted by: michael-t Posted on: 03/16/05 You are currently: a Guest | | Terms of Use
HAHA, those Windows Clowns are at it again!  Xunil_Sierutuf | 03/14/05
No where does it state what OS is affected.  ShadeTree | 03/14/05
It's obvious unless you've been living under a rock  voska | 03/14/05
they did mention diablo 2...  linuxoverwindows | 03/15/05
LOL.. and you are funny for not thinking it's Win32! (NT)  Xunil_Sierutuf | 03/14/05
a little proof to add to the mix  voska | 03/14/05
Again Supposition  ShadeTree | 03/14/05
Sometimes reasoning is futile, Shady!  Hugh Jass | 03/14/05
So much for reasoning.  CobraA1 | 03/14/05
a little research goes a long way shade  Monkey_MCSE | 03/15/05
Common sense Mr. Tree, Common sense  voska | 03/15/05
Well..  Patrick Jones | 03/14/05
RTF report  Richard Flude | 03/14/05
Shhh!  ShadeTree | 03/15/05
Talk about assumptions..  Patrick Jones | 03/15/05
i didnt need to read it to know they were talking about windows...  linuxoverwindows | 03/15/05
I like shinning a flashlight on ignorance (NT)  voska | 03/15/05
Trying to save face are you?  voska | 03/15/05
Post after post without a response in between?  ShadeTree | 03/15/05
Take THAT Shadester!  Jeff Spicoli | 03/15/05
The usual predictable flurry of auto-denial from the MS apologists  whisperycat | 03/15/05
ooops, typo - $60 Million, not $60 Billion!  whisperycat | 03/15/05
The Burst story  Roger Ramjet | 03/15/05
Yes, it was, you are right.  whisperycat | 03/15/05
yup...  jdahs@... | 03/15/05
A couple corrections  ShadeTree | 03/15/05
Shadetree, Is it a coincidence you parrot the Microsoft party line?  whisperycat | 03/15/05
No, If His Car Was Faulty  itanalyst | 03/15/05
analogies  linuxoverwindows | 03/15/05
Twisting the facts huh Jellyclock.  ShadeTree | 03/15/05
And kind regards to all you non windows users  FilledOut | 03/15/05
Tree Hugger  Chad_z | 03/15/05
Well, fortunately, I learned to properly admin  FilledOut | 03/15/05
hush  linuxoverwindows | 03/15/05
Well, time to get them to switch  FilledOut | 03/15/05
Guys like you fail in sales  osreinstall | 03/15/05
It is not  michael-t | 03/16/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here