To catch a criminal, sometimes you have to think like one.
So researchers on the trail of cybercrooks that use armies of infected computers, known as botnets, to send out spam e-mail or to attack websites are building botnets of their own. Fortunately, the new approach is being tested using a high-powered computing cluster that is safely isolated from the Internet.
"We set up what we thought would be the closest to a botnet in the wild," says Pierre-Marc Bureau, a researcher with computer security firm ESET, part of the project led by a team at Ecole Polytechnique de Montreal with collaborators at Nancy University, France, and Carlton University, Canada. "To our knowledge, this is the first such realistic experiment," he says.
Over 3,000 copies of Windows XP were installed on a cluster of 98 servers at Ecole Polytechnique. Each virtual computer system was wrapped in software that linked it up to the others as if it were an individual computer connected to the Internet or a local network. Every system was also infected with the Waledac worm, a piece of now well understood and largely vanquished software that at the start of 2010 was estimated by Microsoft to control hundreds of thousands of computers and to send out 1.5 billion spam messages a day.
The team mimicked the control structure needed to take charge of a Waledac botnet, in which a central command-and-control server sends orders to a handful of bots that then spread those instructions to other machines.
Raising a Botnet in Captivity
Moderator: Moderators
- Sabre
 - DCAWD Founding Member
 - Posts: 21432
 - Joined: Wed Aug 11, 2004 8:00 pm
 - Location: Springfield, VA
 - Contact:
 
Raising a Botnet in Captivity
Tech Review article

			
			
									
						
							Sabre (Julian)

92.5% Stock 04 STI
Good choice putting $4,000 rims on your 1990 Honda Civic. That's like Betty White going out and getting her tits done.
			
						
92.5% Stock 04 STI
Good choice putting $4,000 rims on your 1990 Honda Civic. That's like Betty White going out and getting her tits done.
- 
				thermatico
 - Yugo owner
 - Posts: 281
 - Joined: Mon Oct 11, 2010 8:23 pm
 
Re: Raising a Botnet in Captivity
I wish I could say I was impressed, but I'm not. All too often projects like this get more press than their actually worth. They're still studying just one worm and how it works, which will probably have very little in common with how the next big botnet works
On the bright side, given the University setting, these guys are probably training quite a few guys to be good a front line malware analysis.
			
			
									
						
										
						On the bright side, given the University setting, these guys are probably training quite a few guys to be good a front line malware analysis.
- complacent
 - DCAWD Founding Member
 - Posts: 11651
 - Joined: Sun Aug 29, 2004 8:00 pm
 - Location: near the rockies. very.
 - Contact:
 
Re: Raising a Botnet in Captivity
thermatico wrote:I wish I could say I was impressed, but I'm not. All too often projects like this get more press than their actually worth. They're still studying just one worm and how it works, which will probably have very little in common with how the next big botnet works
On the bright side, given the University setting, these guys are probably training quite a few guys to be good a front line malware analysis.
I couldn't agree more. Great training, tons of potential in the future.
colin
a tank, a yammie, a spaceship
i <3 teh 00ntz
			
						a tank, a yammie, a spaceship
i <3 teh 00ntz
- Raven
 - Mr. Underpowered or something
 - Posts: 1221
 - Joined: Thu Feb 18, 2010 12:46 pm
 - Location: Manasty
 
Re: Raising a Botnet in Captivity

All my cars have drum brakes and are sub 200 hp, what am I doing with my life?
2013 Mazda 2
1994 Chevy S10 pickup
1985 Chevy Caprice (no fuel system)
			
						2013 Mazda 2
1994 Chevy S10 pickup
1985 Chevy Caprice (no fuel system)
- 
				steed77
 - I'm a n000b
 - Posts: 30
 - Joined: Mon Dec 06, 2010 2:30 pm
 - Location: NoVa
 
Re: Raising a Botnet in Captivity
Raven wrote:
ok that made me LOL
03 SVT Lighting 488hp/560tq
05 Evo 8 505hp/411tq
05 4.8is X5
09 versa
			
						05 Evo 8 505hp/411tq
05 4.8is X5
09 versa
- Sabre
 - DCAWD Founding Member
 - Posts: 21432
 - Joined: Wed Aug 11, 2004 8:00 pm
 - Location: Springfield, VA
 - Contact:
 
Re: Raising a Botnet in Captivity
Hopefully they can replicate the tech for other worms/virii/botnets. As you said, at least it's getting some new minds on the problemthermatico wrote:I wish I could say I was impressed, but I'm not. All too often projects like this get more press than their actually worth. They're still studying just one worm and how it works, which will probably have very little in common with how the next big botnet works
On the bright side, given the University setting, these guys are probably training quite a few guys to be good a front line malware analysis.
Sabre (Julian)

92.5% Stock 04 STI
Good choice putting $4,000 rims on your 1990 Honda Civic. That's like Betty White going out and getting her tits done.
			
						
92.5% Stock 04 STI
Good choice putting $4,000 rims on your 1990 Honda Civic. That's like Betty White going out and getting her tits done.