By Karl RasmussonPosted Tuesday 16th October 2007 01:31 GMT
Switch off Asia and Eastern Europe?
An analysis done by an associate has shown that the country with the greatest proportion of bots hosting spammer sites is the U.S. Should we switch them off too mate? See here...
By Shannon JacobsPosted Tuesday 16th October 2007 01:41 GMT
Actually sounds more like a good defensive strategy by the bad guys, and one of the main implications not touched upon by the article is that it makes it harder for other people to use those technologies for legitimate purposes. Were you thinking that encryption would add something good to a legitimate P2P service you are designing? Well, you better forget it now. However from the spammer's perspective, it puts their eggs into different baskets that are more strongly separated from each other, which may make it harder to get all of them.
I thought the article was another overly light populist approach to a complicated problem. Maybe the author does know his stuff--or maybe not. I'd have liked to see some links to heavier secondary sources that the Bleeding Edge Threats page.
Storm is a very devious, complex and well-designed malevolent toolset. For a really good insight into all aspects of the design I would refer all readers who have got here and want to understand more to go to Bruce Schneier's blog, which has its home at:
http://www.schneier.com/crypto-gram.html, look for "The Storm Worm" in the October 2007 archive page (it has 'fallen off the bottom' of the current page)
Bruce's entry refers out to a number of other articles and has attracted somehwat in excess of 100 comments.
By Anonymous CowardPosted Tuesday 16th October 2007 17:54 GMT
Just a warning to those wanting to use those Snort signatures - those rules are so generic, you are going to be chasing false positives all day and night.
Comments on: The balkanization of Storm Worm botnets
good article #
By Alan Donaly Posted Monday 15th October 2007 23:28 GMT
Not A Worm #
By GottaBeKidding Posted Monday 15th October 2007 23:35 GMT
Switch them off? #
By Andy Bright Posted Monday 15th October 2007 23:52 GMT
Switch the US off too? #
By Karl Rasmusson Posted Tuesday 16th October 2007 01:31 GMT
Not a well written article #
By Shannon Jacobs Posted Tuesday 16th October 2007 01:41 GMT
Re:Switch the US off too? #
By Pascal Monett Posted Tuesday 16th October 2007 05:15 GMT
@Andy Bright #
By Anonymous Coward Posted Tuesday 16th October 2007 09:35 GMT
I am with Shannon: poor article #
By Dave Posted Tuesday 16th October 2007 09:40 GMT
storm rules not useful #
By Anonymous Coward Posted Tuesday 16th October 2007 17:54 GMT