Raising a Botnet in Captivity

The place for technology related posts.

Moderator: Moderators

Post Reply
User avatar
Sabre
DCAWD Founding Member
Posts: 21432
Joined: Wed Aug 11, 2004 8:00 pm
Location: Springfield, VA
Contact:

Raising a Botnet in Captivity

Post by Sabre »

Tech Review article
To catch a criminal, sometimes you have to think like one.

So researchers on the trail of cybercrooks that use armies of infected computers, known as botnets, to send out spam e-mail or to attack websites are building botnets of their own. Fortunately, the new approach is being tested using a high-powered computing cluster that is safely isolated from the Internet.

"We set up what we thought would be the closest to a botnet in the wild," says Pierre-Marc Bureau, a researcher with computer security firm ESET, part of the project led by a team at Ecole Polytechnique de Montreal with collaborators at Nancy University, France, and Carlton University, Canada. "To our knowledge, this is the first such realistic experiment," he says.

Over 3,000 copies of Windows XP were installed on a cluster of 98 servers at Ecole Polytechnique. Each virtual computer system was wrapped in software that linked it up to the others as if it were an individual computer connected to the Internet or a local network. Every system was also infected with the Waledac worm, a piece of now well understood and largely vanquished software that at the start of 2010 was estimated by Microsoft to control hundreds of thousands of computers and to send out 1.5 billion spam messages a day.

The team mimicked the control structure needed to take charge of a Waledac botnet, in which a central command-and-control server sends orders to a handful of bots that then spread those instructions to other machines.
8)
Sabre (Julian)
Image
92.5% Stock 04 STI
Good choice putting $4,000 rims on your 1990 Honda Civic. That's like Betty White going out and getting her tits done.
thermatico
Yugo owner
Posts: 281
Joined: Mon Oct 11, 2010 8:23 pm

Re: Raising a Botnet in Captivity

Post by thermatico »

I wish I could say I was impressed, but I'm not. All too often projects like this get more press than their actually worth. They're still studying just one worm and how it works, which will probably have very little in common with how the next big botnet works

On the bright side, given the University setting, these guys are probably training quite a few guys to be good a front line malware analysis.
User avatar
complacent
DCAWD Founding Member
Posts: 11651
Joined: Sun Aug 29, 2004 8:00 pm
Location: near the rockies. very.
Contact:

Re: Raising a Botnet in Captivity

Post by complacent »

thermatico wrote:I wish I could say I was impressed, but I'm not. All too often projects like this get more press than their actually worth. They're still studying just one worm and how it works, which will probably have very little in common with how the next big botnet works

On the bright side, given the University setting, these guys are probably training quite a few guys to be good a front line malware analysis.

I couldn't agree more. Great training, tons of potential in the future. :pics:
colin

a tank, a yammie, a spaceship
i <3 teh 00ntz
User avatar
Raven
Mr. Underpowered or something
Posts: 1221
Joined: Thu Feb 18, 2010 12:46 pm
Location: Manasty

Re: Raising a Botnet in Captivity

Post by Raven »

Image
All my cars have drum brakes and are sub 200 hp, what am I doing with my life?
2013 Mazda 2
1994 Chevy S10 pickup
1985 Chevy Caprice (no fuel system)
steed77
I'm a n000b
Posts: 30
Joined: Mon Dec 06, 2010 2:30 pm
Location: NoVa

Re: Raising a Botnet in Captivity

Post by steed77 »

Raven wrote:Image

ok that made me LOL
03 SVT Lighting 488hp/560tq
05 Evo 8 505hp/411tq
05 4.8is X5
09 versa
User avatar
Sabre
DCAWD Founding Member
Posts: 21432
Joined: Wed Aug 11, 2004 8:00 pm
Location: Springfield, VA
Contact:

Re: Raising a Botnet in Captivity

Post by Sabre »

thermatico wrote:I wish I could say I was impressed, but I'm not. All too often projects like this get more press than their actually worth. They're still studying just one worm and how it works, which will probably have very little in common with how the next big botnet works

On the bright side, given the University setting, these guys are probably training quite a few guys to be good a front line malware analysis.
Hopefully they can replicate the tech for other worms/virii/botnets. As you said, at least it's getting some new minds on the problem :)
Sabre (Julian)
Image
92.5% Stock 04 STI
Good choice putting $4,000 rims on your 1990 Honda Civic. That's like Betty White going out and getting her tits done.
Post Reply