You are here: silicon.com > Software > Malware

Malware

Zombie armies are shrinking, says security guru

But don't crack out the champers just yet...

Tags: zombies, botnets, botnet, zombie

By Dawn Kawamoto

Published: 17 November 2005 08:45 GMT

Malicious makers of bots are finding big is not always better when it comes to avoiding detection, according to a security expert.

Over the past two years, the average network of bots, or compromised PCs commandeered by remote attackers, has dropped from more than 100,000 to an average of 20,000, Mark Sunner, MessageLabs's chief technology officer, said during Tuesday's annual Security Roundtable Webcast.

A botnet is comprised of thousands of computers that have been surreptitiously transformed into zombie PCs without their owners' knowledge. The move to pint-size botnets helps malicious attackers have more success in delaying detection of their illicit zombie networks, Sunner said.

He added: "When a larger botnet is spreading a virus, it lights up the switchboard of [antivirus] vendors, and they'll respond in a few hours with a signature to contain the outbreak.

"With a smaller botnet, it may take a day or so before it's discovered and a signature is written."

Maksym Schipka, a senior antivirus researcher at MessageLabs, noted that two other issues have also contributed to the shrinking size of botnets.

First, an increase in the numbers of hackers hoping to put together networks has made the task of securing zombie computers more competitive, so it is harder for the "bot herder" to amass a larger number of drone computers.

Second, home users with high-bandwidth connections, the primary targets of hackers, are taking more steps to secure their computers.

Often, hijacked bots have been infected with software that will connect to an Internet Relay Chat and await instructions from the malicious attacker. Botnets are used to send out email messages for spam and phishing attacks. They can also be used to send out a flood of data to bring down a system in a denial of service attack.

When a malicious writer launches a phishing scam, antivirus companies will write so-called signatures that identify the attack for their protective products. These signatures are like taking fingerprints of malicious software. Each time the attack touches the doorknob to enter a system, the door locks.

The more quickly antivirus vendors distribute a signature for a virus and customers deploy it, the less effective that particular botnet can be, Sunner said.

He added: "As botnets get used up, they are blacklisted and less useful for spamming or phishing attacks. But they get mopped up and are used for DOS attacks."

As DOS attacks don't directly use email or viruses, they won't be caught by blacklists or signature-based antivirus products. Last year, Sunner said his company began noticing old, worn-out spambots were being resold as potential DOS bots on various sites and forums used by malicious attackers.

He said: "People would advertise bots with 'fresh' machines, or ones that were mopped up."

Dawn Kawamoto writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Analyst within Programme Control Services (PCS) part of Systems Integration & Technology Consulting-C37314

Analyst within Programme Control Services (PCS) part of Systems Integration & Technology Consulting London, Manchester and Newcastle 31,000 + 10,000 ...

Network Consultant, Engineer, CCNA, PIX, ASA, VPN, Firewall, Stevenage

Cisco PIX / ASA, Checkpoint & Cyber Guard), Intrusion detection devices (IDS) & antivirus solutions. Technical Network Consultant / Engineer required ...

Network Support Administrator Abingdon

Key Responsibilities - Remote management of single and multi-server networks - Carrying out general housekeeping and network management tasks, ...

CIO Agenda 2008
The exclusive silicon.com CIO Agenda 2008 survey looks at the CIO's tech shopping list for the year, examines whether IT budgets are rising or falling and reveals what the pain points are for tech chiefs this year. Find out more in our latest special report.





Quick Sitemap Links: