Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Virginia Tech Massacre Brings Security Home | Main | 5 New Anti-Spam Techniques: Promising Technologies for Dealing with Spam and Phishing »

P2P Botnets Increasingly Sophisticated

Botnets have been a problem for years but we may be reaching a point where their level of sophistication makes them difficult to contain with existing technologies. Of particular concern is the spread of peer-to-peer botnets which are much more resilient than traditional command and control botnets.

Dr. Jose Nazario of Arbor Networks, quoted in PhysOrg.com:

"P2P networks - are - the biggest challenge we're facing," … [he] said in an interview with eWEEK. "Bad guys know this. - P2P botnets are hard to take down - for the same reasons that media companies have trouble shutting down P2P networks."

From Peer-to-Peer Botnets: Overview and Case Study by Julian B. Grizzard, David Dagon, Vikram Sharma, Chris Nunnery and Brent ByungHoon Kang, we hear:

Peer-to-peer bots are now under widespread development," the authors wrote. "Some peer-to-peer bots have used existing peer-to-peer protocols while others have developed custom protocols. We predict that peer-to-peer botnets will mature to a level in which they might become more widespread than traditional decentralized C&C architectures.

What this means, among other things, is that we’ll new kinds of tools to detect and contain these. For example, more emphasis on network traffic analysis, rather than just scan client devices, will be needed. This is due to two problems. First, botnet writers are getting better at using rootkits to hide their malware, and second, even when we can detect botnet footprints, naive users are not running updated anti-virus programs that might detect them.

I’ve been a proponent of improving user training and awareness about security but that isn’t enough and it can’t happen fast enough.

For more on recent trends in botnets, see the HotBots conference proceedings at http://www.usenix.org/events/hotbots07/tech/.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/279

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net