The Register® — Biting the hand that feeds IT

Feeds

Botnet takedowns 'don't hurt crooks enough'

Punching fog

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

The takedowns of the Mariposa and Waladec botnets last week were victories for the good guys, but security experts warn that although cybercrooks suffered a bloody nose they collectively retain the upper hand in their ongoing conflict with law enforcement and its security industry allies.

"We have had significant victories against several botnets in the past but that hasn't stopped the growth in malware or the growth in spam or in information theft," said Rik Ferguson, a security consultant at Trend Micro. "So, while we continue to win significant battles, winning the war will need closer cooperation between governments [and] law enforcement agencies on an ongoing basis rather than on an operational basis."

Ferguson thinks that white hats remain outgunned by cybercrooks. He called for harmonisation of e-crime laws, to get rid of safe havens, and closer international cooperation in fighting internet crime. He added that ISPs have a vital role to play in curbing the botnet scourge. He continued:

I'm not convinced we're winning this - it still needs organisations like ISPs to be willing to identify affected machines and quarantine them while informing customers of this. There is also a need for the harmonisation of laws. there are some countries where it isn't illegal to engage in online criminal activities - or countries where laws are outdated or different to other countries, so there is no harmonisation. Once harmonised, it'll be easier to prosecute and apply common laws across geographical boundaries.

Intelligence sharing between national governments on matters of cybercrime will also be key. There is already intelligence sharing for other types of crimes, why not for cybercrime?

Gunter Ollmann, vice president of Research at security firm Damballa, said that going after the crooks in controls of running botnets rather than the domains they used was the only truly effective strategy. Even then difficulties abound.

I've found the takedown of the domain names used by the botnet operators to be ineffective. The bad guys simply register new ones and carry on with their business. For example, one botnet that we track has used over 80,000 different command and control domain names since we've been monitoring them over four years. At any point in time they have around 5,000 live and in use. No sooner is one domain name closed, sinkholed, or hijacked, than they simply register some more and continue business.

Ollman, a computer scientist and security expert of many years standing, has published a number of research papers over recent months about botnets in corporate environments. His research suggests that even if one cybercrime ring is brought down other crooks will step in to exploit gaps in the market. Nonetheless pursuing the bad guys is a worthwhile endeavour.

This process is complicated by the fact that ownership of compromised systems often changes hands very quickly in the digital underground, he explained:

It is important to focus on the criminal operators themselves - it's the only way to shut down the botnet. However, it doesn't pay to delay in taking down the operators. Given the trend in buying/selling/renting and horse-trading (eg trading botnet victims in one country with a botnet operator that has botnet victims in another) access to the victim hosts can change hands rapidly. As part of the handover of victims or sections of the botnet, the new operator installs their own (new) botnet agent.

Building and running botnets is a highly competitive business. If one operator goes down, it creates new opportunities for the other botnet operators. It's not as if the victims have suddenly become secure in the interim.

®

Agentless Backup is Not a Myth

Anonymous Coward

Bawts

I have turned a good 30 million + boxes into "bots" over the past 12 years (netbios kid) and it's easy as pie ;-) Eventually I did of course get caught and I am still awaiting some court cases over the matter.

If you infect 1 million PC's and lose contact, which does happen, you go and infect another 1 million PC's and through organising the hosts you soon notice that many are THE SAME idiots getting infected over and over.

By disabling ANY botnet all you are doing is temp stopping access whilst the botnet owner spends a week reinfecting the same bunch as they infected before.

The ONLY way to stop people like me, is to prosecute. This brings the realities of what you are doing home, fast. There is always a route, botnet admins are lazy and do not always proxy into everything and even when they do they often use the same proxies over and over, meaning if you monitor the proxy then you can find the source.

My advice is to never do takedowns but to monitor the nets until a way is found of identifying the owner. If more owners are prosecuted the realities soon drive home that a jail sentence is VERY possible and we would soon see a sharp drop in infections which will see a corresponding drop in SPAM. Bad news for AV and Anti-spam companies but good news for the average internet user.

2
0

What he said

Exactly - the crims (by definition) look for most reward for least effort. There is such a glut of Win installations out there, and a glut of naive/uneducated/carefree users sat in front of them that writing malware for it is easy money.

If we had a glut of penguin installations with a glut of naive/uneducated/carefree users sat in front of them you'd have the same problem, only with better net APIs.

Win can easily be made much more resilient to attacks. Users can be taught to pick a random browser that ain't IE and use that. Routers (and ISPs) can block known low-value/high risk net addrs/subnets. None of this is default though and therein lies the issue.

To be fair it's ppl like el Reg readers that should take it upon themselves to teach ma/pa, the kiddies etc :

1. If you need to install software right-click, Run as...

2. Don't use IE

3. Don't download tat from the web

4. Ignore emails asking for any info at all.

Teach 3 ppl, get them to pass it on...

1
0

Linux isn't the answer

If the majority of computers in the world run linux, the majority of botnets would be written to run on linux.

2
1

More from The Register

 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?
 breaking news
'BadNews is malware' says outfit that found it
Google says code harmless but Lookout says code base is evolving
Panda-peddlers cuffed for chess gambling gambit
More porridge on the menu for Chinese coders after second offence